RE: Windows Server 2003 - Not secure from my test but OSX from Mac is secure from the start

From: Depp, Dennis M. (deppdm_at_ornl.gov)
Date: 09/19/03

  • Next message: Jonathan Sanders: "Filtered v. Closed v. Open"
    Date: Fri, 19 Sep 2003 13:03:12 -0400
    To: Jimi Thompson <jimit@myrealbox.com>, Damon McMahon <inst_karma@hotmail.com>, security-basics@securityfocus.com
    
    

    It can be argued very effectively that no machine is "safe" unless it is
    physically secure. This is not a Windows problem, but a computer
    problem in general. With a SUN machine, it is easy to boot from a CD
    and reset the Root password. If I remove the CD drive, it is not
    difficult to add a new CD drive.

    Dennis

    -----Original Message-----
    From: Jimi Thompson [mailto:jimit@myrealbox.com]
    Sent: Thursday, September 18, 2003 11:07 PM
    To: Damon McMahon; security-basics@securityfocus.com
    Subject: Re: Windows Server 2003 - Not secure from my test but OSX from
    Mac is secure from the start

    >><SNIP>
    >
    >There are so many tools out there that can reset the Administrator
    >account with console access to Windows that _no_ Windows machine is
    >safe if it is not physically secure.
    >
    </SNIP>

    A prime example of this can be observed by booting a Windows XP
    machine off a Windows 2000 CD. Windows 2000 "assumes" that the SAM
    is corrupt and allows you to fire up the recovery console to pull off
    just about anything you want including stuff off the encrypted
    partitions.

    Another example of this are the Linux boot floppy utilities that
    actually 1- reset the Admin password to the one of your choice 2-
    allow you to select one or 3 - allow you to dissect and decrypt the
    SAM. This is why so many of the remote management "disk-less floppy"
    utilities make me nervous. Now I can use "password recovery"
    utilities over the wire.

    Just what I needed - SOMETHING ELSE to worry about......

    Thanks,

    Jimi

    ------------------------------------------------------------------------

    ---
    Captus Networks 
    Are you prepared for the next Sobig & Blaster? 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
     - Precisely Define and Implement Network Security 
     - Automatically Control P2P, IM and Spam Traffic 
    FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
    http://www.captusnetworks.com/ads/42.htm
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Captus Networks 
    Are you prepared for the next Sobig & Blaster? 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
     - Precisely Define and Implement Network Security 
     - Automatically Control P2P, IM and Spam Traffic 
    FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
    http://www.captusnetworks.com/ads/42.htm
    ----------------------------------------------------------------------------
    

  • Next message: Jonathan Sanders: "Filtered v. Closed v. Open"

    Relevant Pages

    • Re: Microsoft Says Recovery from Malware Becoming Impossible
      ... and Unix are also subject to this ... The truth is that malware is 99.9 % a Windows problem. ...
      (microsoft.public.security)
    • Re: Microsoft Says Recovery from Malware Becoming Impossible
      ... The truth is that malware is 99.9 % a Windows problem. ... malware (spyware and adware) is 99% a WINDOWS problem: ...
      (microsoft.public.security)
    • RE: Windows Server 2003
      ... I think what he means is, in windows 2000 server and advanced server, it ... > Captus Networks ... > - Automatically Control P2P, ...
      (Security-Basics)
    • xp professional - local administrator password
      ... private intranet use the windows NT. ... Some workstation w/ xp, apeared w/ ... the administrator password changed, anybody now how i can change ... Captus Networks ...
      (Security-Basics)
    • Re: Python Error from Apress book
      ... That's a Windows problem. ... When you execute the script as itself, it doesn't have valid standard handles. ... (you may need to specify the full path to python.exe, or add the directory where Python is installed to your system PATH). ... I use stdout this way all the time, with no problem (python 2.6, Windows XP). ...
      (comp.lang.python)

  • Quantcast