Is WinXP (and Win2000) screen saver password safe?

From: Ian Watt (icewalker_at_hotpop.com)
Date: 03/31/04


Date: 31 Mar 2004 00:23:42 -0800

Hi

I posted some time ago a question concerning WinXP/Win2000 screen
saver security (http://groups.google.com/groups?dq=&hl=en&lr=&ie=UTF-8&oe=UTF-8&threadm=4067ce15%240%24267%24802e34e2%40news.novaxess.net&prev=/groups%3Fhl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26group%3Dalt.security.scramdisk)

The situation is that I have disk encryption software (Safeboot Solo)
that asks for the password _before_ Windows is started. So my password
should be quite safe from password sniffers etc. BUT my concern is
that if I activate the screen saver, is it possible for someone to
access Windows for example bypassing screen saver password (there
seems to be software doing just that with Win95), or accessing the
file system via network (even if I use firewall & drives are not
shared) or whatever.

I.e. are there known vulnerabilities making it possible to access my
computer's filesystem without the need to boot, if the computer is
locked with Windows screen saver?

IW



Relevant Pages

  • Re: [opensuse] Who said Linux doesnot get Virus infections
    ... you can execute a screen saver if you test it. ... They're under the general "viruses" tag. ... A Linux system being used to protect Windows ...
    (SuSE)
  • Re: Monitor Choice
    ... They also have poor voltage control - a blank screen saver displays as dark ... I find all flavours of Windows default to no higher than 75Hz, ... and thus get stuck with both flickery displays and needless power ... More a case of win defaults than monitors though. ...
    (uk.comp.homebuilt)
  • Re: Screen Saver Settings Lost
    ... 2004 Windows MVP "Winny" Award ... >Troubleshooting Screen Saver Issues in XP ... >2004 Windows MVP "Winny" Award ...
    (microsoft.public.windowsxp.general)
  • Re: Wait...it only partially worked!
    ... Right click the Desktop, select Properties, Screen Saver and uncheck On ... MS-MVP Windows XP/ Windows Smart Display ... "Kathy" wrote in message ... > booting the system...I can now boot the system just fine ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Windows mobile 5.0 screen saver
    ... for the thin client shell that a Windows CE OEM *can* add to their device. ... only a *very* small percentage of Windows CE ... > Sorry for the local msdn link: Here goes the online link: ... there is no standard screen saver API. ...
    (microsoft.public.dotnet.framework.compactframework)