Re: Vulnerability in IBM Windows XP: default hidden Administrator account allows local Administrator access

Shawn McMahon <[email protected]> Sat, 18 Sep 2004 10:07:17 -0400
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <20040918140717.GB14272__33447.9415826083$1095567322$gmane$org@eiv.com>
On Fri, Sep 17, 2004 at 03:08:34PM -0500, Michael Wilson, Contractor said:
> 
> It is most likely the Vendor Install Customization that has caused this
> issue, as true enough, most vendor installs force you to pick an
> administrator password before using the system.  If the account is hidden,
> then it is definitely IBM's doing as I have never seen a Windows install
> where the administrator account could not be seen under the accounts tab.

Averatec laptop installs of XP Home have it hidden; you have to boot in
Safe Mode to add a password.

The documentation that specifies this is a Microsoft product, so I
suspect it's the same with other installs of Home, but I have only left
the packaged install of XP Home on one machine ever, so I am not at all
sure of this.


-- 
Shawn McMahon      | Let's set the record straight. There is no argument
EIV Consulting     | over the choice between peace and war, but there is
UNIX and Linux	   | only one guaranteed way you can have peace - and you
http://www.eiv.com | can have it in the next second - surrender. - Reagan
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.0 (GNU/Linux)

iD8DBQFBTEEVEcl9bQ0RMt0RAh+oAKDidmEZiBtB2e653lzzBaFahqgmXQCg75CN
fdAZNt5OyVMiM0THa3P6q8Q=
=pthJ
-----END PGP SIGNATURE-----