Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Media Gone Mad
Tim Mullen, 2003-02-24

Why last week's big Windows security hole is nothing more than technology press hot air.

Comments Mode:
Media Gone Mad 2003-02-24
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Linux_Hawk
I agree completely. 2003-02-24
Anonymous (4 replies)
I agree completely. 2003-02-24
Anonymous
Re: I agree completely. 2003-02-25
Anonymous (2 replies)
Re: I agree completely. 2003-02-25
Anonymous (1 replies)
Re: Re: I agree completely. 2003-02-26
Anonymous
Re: I agree completely. 2003-02-25
Anonymous (2 replies)
Re: I agree completely, or NOT 2003-02-26
Anonymous (2 replies)
Re: I agree completely, or NOT 2003-02-27
Anonymous
Re: I agree completely, or NOT 2003-02-27
Eric Grabowski (eric@mazenet.com) (1 replies)
Re: I agree completely, or NOT 2003-02-27
Anonymous
Re: I agree completely. 2003-02-26
Seb (1 replies)
I think you missed the point. The previous poster was talking about how with him having PHYSICAL access to YOUR server, he can boot up using a linux floppy or cdrom and have complete access to your files. Infact he could even reset the Administrator password on your server to something he wants and reboot back to windows. Thus being able to setup a trojan or whatever he wanted.

The Linux/*nix folks already KNOW this can be done, as we can boot Linux systems from a floppy and circumvent the root password also. Hell lilo lets you do this WITHOUT any aditional help using "linux single" ( for most distros ). So why would "we" make a big deal of being able to do the same thing on Windows?

The comment about stupid artificial security measures was about requiring any sort of password from a recovery console in the 1st place. Since if you have physical access to the box you can do whatever you want with it anyways.

Infact having a password less recovery console IS DESIRABLE in many many cases. ( As the article states ). If you are concerned about physical security you should install the appropriate physical measures. ( BIOS password, case lock, secured/controlled access )

My concern is that it's the Windows Admin Newbies that are shocked and scared of this "bug/security hole" that are spreading this like it's a big deal. Since us *nux admins have known about this for ages.

On a side note MOUNT is not a "*nix" term. It has been used by all sorts of operating systems ( Including MacOS ) far far longer then the existance of Windows. And it has ALWAYS meant mounting( attaching ) a resource either physical ( like a harddrive ) , or virtual ( like a file share ) to a local directory entry ( mount point ). "Maping" is a MS invented word that specifically means mounting a remote share locally.

---



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/144/18425#18425
Re: I agree completely. - thank you 2003-02-28
Anonymous (1 replies)
I agree completely. 2003-02-26
Anonymous
Media Gone Mad 2003-02-24
Anonymous (1 replies)
Media Gone Mad 2003-02-24
Anonymous (1 replies)
Media Gone Mad 2003-02-26
Anonymous
For once I agree with you. 2003-02-24
Anonymous
at least someone sees sense 2003-02-24
ravidew (1 replies)
Media Gone Mad 2003-02-24
Anonymous
Bravo! 2003-02-24
Keydet89@yahoo.com
Media Gone Mad or not? 2003-02-24
Anonymous
Norteamericano Gone Mad 2003-02-25
John Comeau http://risp.org/members/jcomeau (1 replies)
Norteamericano Gone Mad 2003-02-25
Gavin
Media Gone Mad 2003-02-25
Anonymous (4 replies)
Media Gone Mad 2003-02-25
Anonymous (1 replies)
Media Gone Mad 2003-02-26
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Wrong on at least one count 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Media Gone Mad 2003-02-25
Anonymous
WRONG! 2003-02-26
Charles Hill (9 replies)
WRONG! 2003-02-26
Anonymous
WRONG! 2003-02-26
Anonymous
THANK YOU! 2003-02-26
Anonymous
WRONG!....err...not 2003-02-26
Anonymous
WRONG! 2003-02-26
Ralf (1 replies)
WRONG! 2003-02-27
Anonymous
re: WRONG! 2003-02-26
Anonymous
WRONG! 2003-02-26
jonsteph (1 replies)
WRONG! 2003-02-27
Anonymous
WRONG! 2003-02-27
Anonymous
WRONG! 2003-02-28
Anonymous
Media Gone Mad 2003-02-26
Jimmy
Media Gone Mad 2003-02-26
Anonymous
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
TJ Miller jr (23 replies)
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
Anonymous (1 replies)
Actually, fellow, there -is- one. 2003-02-26
Anonymous
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
Daniel Franklin
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
Anonymous (2 replies)
Columnist Gone Mad 2003-02-26
Anonymous (2 replies)
Columnist Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-26
Anonymous
My Experience with The Linux 2003-02-26
Egg Troll (14 replies)
re: My Experience with The Linux 2003-02-26
Stonewolf
My Experience with The Linux 2003-02-26
Anonymous
My Experience with The Linux 2003-02-26
Anonymous
My Experience with The Linux 2003-02-27
Anonymous
Feed the troll 2003-02-27
Anonymous
Re: My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous
Re: My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous (1 replies)
Re: My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous (1 replies)
My Experience with The Linux 2003-02-27
Anonymous (1 replies)
Egg Troll Rules! Anonymous Doesn't. 2003-02-28
Anonymous (1 replies)
As if 2003-03-03
Anonymous
My Experience with The Linux 2003-03-05
blacklight
Linux Boot Floppy 2003-02-26
Anonymous
Joy! 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-26
Anonymous
You don't need a Linux boot floppy 2003-02-27
Aaron Brooks
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-27
icewhit
Media Gone Mad 2003-02-27
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Roberto J Dohnert
Defined media 2003-02-27
bri guy
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-27
Cent
Alert: Major Security Flaws 2003-02-27
Asmo (2 replies)
Alert: Major Security Flaws 2003-02-27
Anonymous
Alert: Major Security Flaws 2003-02-28
Anonymous
This IS a major vulnerability 2003-02-27
obadii@hushmail.com (2 replies)
This IS a major vulnerability 2003-03-02
Anonymous
Media Gone Mad - bye bye *nix 2003-02-27
Anonymous (1 replies)
Media Gone Mad - bye bye *nix 2003-03-02
Anonymous
Media Gone Mad 2003-02-28
Anonymous
Media Gone Mad 2003-02-28
Anonymous
Media Gone Mad 2003-03-02
Anonymous
Media Gone Mad 2003-03-03
Anonymous
STOOPID PEOPLE 2003-03-03
GENIUS GUY (2 replies)
STOOPID PEOPLE 2003-03-04
Anonymous
STOOPID PEOPLE - uhm, yeah. 2003-03-04
Anonymous
It is unfortunate... 2003-03-03
Glenn Schulz (1 replies)
It is unfortunate...that you don't understand 2003-03-04
Anonymous (1 replies)
It is unfortunate...that Glenn learned security from a text book. 2003-03-05
Erik (1 replies)
Reality 2003-03-06
Glenn Schulz (1 replies)
Agreement 2003-03-06
Erik (2 replies)
It has been a pleasure 2003-03-07
Glenn Schulz
Agreement 2003-03-07
FUNNY (2 replies)
MICROSOFT SUCKS! 2003-03-04
[ Discussion Closed ] (1 replies)
MICROSOFT SUCKS! - your a dink. 2003-03-06
Anonymous
Media Gone Mad - Strikeback 2003-03-05
Anonymous
Media Gone Mad - Linux sucks 2003-03-06
Anonymous
what more can I do 2003-03-06
Tigger







 

Privacy Statement
Copyright 2009, SecurityFocus