hidden hit counter
Welcome to WindowsForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Security issue??

 
   Windows XP (Home) -> Security Admin RSS
Next:  Huge security issue??????  
Author Message
Brad Pears1

External


Since: Apr 06, 2004
Posts: 24



(Msg. 1) Posted: Tue Sep 06, 2005 5:00 pm
Post subject: Security issue??
Archived from groups: microsoft>public>windowsxp>security_admin (more info?)

I was recently advised of an issue where a user with a local "restricted"
account on an XP Pro machine, somehow managed to grant himself
administrative rights...

Now, unless he knew the local admin password, or the password of one of the
other admins for the machine, is there any easy way that a 14 year old kid
could have done this??? (other than hacking the password etc...)

Thanks,

Brad

 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Malke

External


Since: May 06, 2005
Posts: 697



(Msg. 2) Posted: Tue Sep 06, 2005 5:00 pm
Post subject: Re: Security issue?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Brad Pears wrote:

> I was recently advised of an issue where a user with a local
> "restricted" account on an XP Pro machine, somehow managed to grant
> himself administrative rights...
>
> Now, unless he knew the local admin password, or the password of one
> of the other admins for the machine, is there any easy way that a 14
> year old kid could have done this??? (other than hacking the password
> etc...)
>

"Hacking the password" as you put it is completely brain-dead easy for
someone with physical access to the machine. Any smart tech-savvy
14-year old could do it. I suggest you have a talk with the kid.

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Sparda




Joined: Jun 27, 2005
Posts: 2062



(Msg. 3) Posted: Tue Sep 06, 2005 5:31 pm
Post subject: Re: Security issue?? [Login to view extended thread Info.]

Well, he could have used a clever service (that runs as system which has compleate control) to run cmd, which would give him compleate access to every thing and could run the user management thing and then give him self admin rights, not exacly hard.
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Sparda




Joined: Jun 27, 2005
Posts: 2062



(Msg. 4) Posted: Tue Sep 06, 2005 5:38 pm
Post subject: Re: Security issue?? [Login to view extended thread Info.]

You ask how he could run a program via a service? well, he could have found a service exe that he can change stuff, and replace the exe. If this is not the case, it can be a bit more tricky, he would have had to find a way to run a program as system with out going though a service.
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Brad Pears1

External


Since: Apr 06, 2004
Posts: 24



(Msg. 5) Posted: Wed Sep 07, 2005 10:28 am
Post subject: Re: Re: Security issue?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Could you give me an actual example of how this could have been done , using
an actual running service?? I'm just not sure how he could have run
"command" from within the service in order to run the managment console to
give himself admin rights...

My guess is he must have hacked the password but you never know...

"Sparda" wrote in message

> "Sparda" wrote:
> > Well, he could have used a clever service (that runs as system
> > which has compleate control) to run cmd, which would give him
> > compleate access to every thing and could run the user
> > management thing and then give him self admin rights, not
> > exacly hard.
>
> You ask how he could run a program via a service? well, he could have
> found a service exe that he can change stuff, and replace the exe. If
> this is not the case, it can be a bit more tricky, he would have had
> to find a way to run a program as system with out going though a
> service.
>
> Posted Via Usenet.com Premium Usenet Newsgroup Services
> ----------------------------------------------------------
> ** SPEED ** RETENTION ** COMPLETION ** ANONYMITY **
> ----------------------------------------------------------
> http://www.usenet.com
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Malke

External


Since: May 06, 2005
Posts: 697



(Msg. 6) Posted: Wed Sep 07, 2005 10:28 am
Post subject: Re: Re: Security issue?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Brad Pears wrote:

> Could you give me an actual example of how this could have been done ,
> using an actual running service?? I'm just not sure how he could have
> run "command" from within the service in order to run the managment
> console to give himself admin rights...
>
> My guess is he must have hacked the password but you never know...

Why bother to mess around with services or anything that elaborate?
Simply boot with NTpasswd and change the Administrator password to a
blank. Then log in and do whatever you want. Takes less than 5 minutes.

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
CReWdog

External


Since: Sep 07, 2005
Posts: 1



(Msg. 7) Posted: Wed Sep 07, 2005 1:49 pm
Post subject: Re: Security issue?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Sparda wrote:
> *"Sparda" wrote:
> > Well, he could have used a clever service (that runs as system
> > which has compleate control) to run cmd, which would give him
> > compleate access to every thing and could run the user
> > management thing and then give him self admin rights, not
> > exacly hard.
>
> You ask how he could run a program via a service? well, he could
> have
> found a service exe that he can change stuff, and replace the exe.
> If
> this is not the case, it can be a bit more tricky, he would have had
> to find a way to run a program as system with out going though a
> service.
>
> Posted Via webservertalk.com Premium Usenet Newsgroup Services
> ----------------------------------------------------------
> ** SPEED ** RETENTION ** COMPLETION ** ANONYMITY **
> ----------------------------------------------------------
> http://www.webservertalk.com *


Hi.
Dead easy, all he has to do is obtain a copy of the "system" & "sam"
files in the winnt/system32/config folder using a win98 boot disc & a
programme to copy the 2 files. He can then either extract the password
hashes & brute force them to get the password (takes a LONG time if a
strong password is used) or (much quicker) post the hashes onto a
certain site that has already decoded ALL possible hash combinations
(they use something called rainbow tables) then they compare your
hashes with the ones contained in the tables & tell you what the
corresponding password is).
OR... he could have logged into the admin account in safe mode.... you
DID put a password on it, didn't you??? (This account has no password
unless you set one.

Regards

CReWdog.



--
CReWdog
------------------------------------------------------------------------
Posted via http://www.mcse.ms
------------------------------------------------------------------------
View this thread: http://www.mcse.ms/message1836564.html
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Sparda




Joined: Jun 27, 2005
Posts: 2062



(Msg. 8) Posted: Wed Sep 07, 2005 7:34 pm
Post subject: Re: Re: Security issue?? [Login to view extended thread Info.]

Well, the example that stuck in my mind was that at my High school, Nortan antivirus couldnt update because it couldnt write to the hard drive, so the school admins in all there wisedome allowed every one to write to that folder, in cluding the noroton system monitor. So as you do, it wrote a wee vb program thats soul pupose was to run cmd... as system, so replacing the system monitor with my vb program... you see where im going with this.
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Brad Pears1

External


Since: Apr 06, 2004
Posts: 24



(Msg. 9) Posted: Fri Sep 09, 2005 10:27 am
Post subject: Re: Re: Security issue?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Never heard of booting with NTpasswd - is that some sort of utility ?? I
know you can boot to the recovery console etc.. but you need admin password
for that...

Please elaborate!

Thanks,

Brad

"Malke" wrote in message

> Brad Pears wrote:
>
>> Could you give me an actual example of how this could have been done ,
>> using an actual running service?? I'm just not sure how he could have
>> run "command" from within the service in order to run the managment
>> console to give himself admin rights...
>>
>> My guess is he must have hacked the password but you never know...
>
> Why bother to mess around with services or anything that elaborate?
> Simply boot with NTpasswd and change the Administrator password to a
> blank. Then log in and do whatever you want. Takes less than 5 minutes.
>
> Malke
> --
> Elephant Boy Computers
> www.elephantboycomputers.com
> "Don't Panic!"
> MS-MVP Windows - Shell/User
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Torgeir Bakken 1

External


Since: Mar 22, 2004
Posts: 748



(Msg. 10) Posted: Fri Sep 09, 2005 11:15 am
Post subject: Re: Security issue?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Brad Pears wrote:

> Never heard of booting with NTpasswd - is that some sort of utility ?? I
> know you can boot to the recovery console etc.. but you need admin password
> for that...
>
> Please elaborate!
>
Hi,

http://home.eunet.no/~pnordahl/ntpasswd/



--
torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of
the 1328 page Scripting Guide:
http://www.microsoft.com/technet/scriptcenter/default.mspx
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Brad Pears1

External


Since: Apr 06, 2004
Posts: 24



(Msg. 11) Posted: Fri Sep 09, 2005 11:44 am
Post subject: Re: Security issue?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Yes, I did put a password on the admin account. I have heard of what you
mentioned there regarding sending your files to a website and they'll tell
you what the password is... I tried that once before for a machine I could
not figure out the admin password on, had to run a utility that copied the
two files to floppy (likely the ones you mentioned) , then posted those two
files to the website and about a day later, I had the password. It worked
quite well actually!!!

Thanks for the input...

"CReWdog" wrote in message

>
> Sparda wrote:
>> *"Sparda" wrote:
>> > Well, he could have used a clever service (that runs as system
>> > which has compleate control) to run cmd, which would give him
>> > compleate access to every thing and could run the user
>> > management thing and then give him self admin rights, not
>> > exacly hard.
>>
>> You ask how he could run a program via a service? well, he could
>> have
>> found a service exe that he can change stuff, and replace the exe.
>> If
>> this is not the case, it can be a bit more tricky, he would have had
>> to find a way to run a program as system with out going though a
>> service.
>>
>> Posted Via webservertalk.com Premium Usenet Newsgroup Services
>> ----------------------------------------------------------
>> ** SPEED ** RETENTION ** COMPLETION ** ANONYMITY **
>> ----------------------------------------------------------
>> http://www.webservertalk.com *
>
>
> Hi.
> Dead easy, all he has to do is obtain a copy of the "system" & "sam"
> files in the winnt/system32/config folder using a win98 boot disc & a
> programme to copy the 2 files. He can then either extract the password
> hashes & brute force them to get the password (takes a LONG time if a
> strong password is used) or (much quicker) post the hashes onto a
> certain site that has already decoded ALL possible hash combinations
> (they use something called rainbow tables) then they compare your
> hashes with the ones contained in the tables & tell you what the
> corresponding password is).
> OR... he could have logged into the admin account in safe mode.... you
> DID put a password on it, didn't you??? (This account has no password
> unless you set one.
>
> Regards
>
> CReWdog.
>
>
>
> --
> CReWdog
> ------------------------------------------------------------------------
> Posted via http://www.mcse.ms
> ------------------------------------------------------------------------
> View this thread: http://www.mcse.ms/message1836564.html
>
 >> Stay informed about: Security issue?? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
security issue - dear all by mistake i remove all permission to open an fplder ,,, till my permessions as administrator, now i can't open the folder ,,, and get access denide message ,,, plz advice me ,, how to open the folder again ,, i work under domain environmen...

Is this a security issue? -

Windows XP update - Jpeg security issue - Hi, I want to protect my PC against this new security issue with Jpeg files. I have XP home, I don't wish to install Service Pack 2 as it changes the operating system significantly. How can I protect my PC against this potential security breach? When...

XP User Profile Security Issue - We have migrated hundreds of XP desktops from Novell to MS ADS. When it comes to 3 desktops which share C drive to each other, user B on Computer B can access to user A's user profile. Same as user A when he can get access to user B 's My..

Log On Issue - I hope I have the right forum for this, I recently shut down my computer (XP Pro) I remember seeing an error box indicating something about "hidden windows not responding" The computer shut down, and when I tried to log on a day later, the...
   Windows XP (Home) -> Security Admin All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
  Windows XP
 Win 2000/NT/98/ME
 Windows Vista!


[ Contact us | Terms of Service/Privacy Policy ]