Re: Insufficient Authentication vulnerability in Asus notebook

看板Bugtraq作者時間16年前 (2009/05/15 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/12 (看更多)
Once someone has physical access all bets are off, there's a lot the =20 can do. 1) steal it 2) boot off cd and reset/enable admin acct 3) boot off cd and grab all hashes 4) pour a perfectly good frappucino on the keyboard 5) cover it with smiley face stickers You get the idea. This is non issue. On May 14, 2009, at 6:37 AM, Jeremy Brown <0xjbrown41@gmail.com> wrote: > If you explore further research, you will find that this is not a bug, > this is well known, and its not particular to Asus. > > 2009/5/14 MustLive <mustlive@websecurity.com.ua>: >> Hello SecurityFocus! >> >> I want to warn you about Insufficient Authentication vulnerability =20= >> in Asus >> notebook. >> >> After publication of information about Insufficient Authentication >> vulnerability in Acer notebooks >> (http://www.securityfocus.com/archive/1/503398/30/0/), I decided to >> investigate all notebooks of my friends. Particularly I checked two =20= >> Asus >> notebooks: at one with Windows XP Professional there is no such >> vulnerability, at another with Windows XP Home Edition there is such >> vulnerability. >> >> In Windows XP Home in default administrator's account =20 >> "Administrator" there >> is empty password. And it does not set equal to password of first =20 >> admin, >> when admin account is creating during first start of notebook (as =20 >> it happens >> during installation of Windows XP). So with physical access to =20 >> notebook, >> anybody can enter into the system with administrator's rights. >> >> Vulnerable models of notebooks: Asus =D0=906500R and potentially = other =20 >> models. >> >> I mentioned about these vulnerability at my site >> (http://websecurity.com.ua/3139/). >> >> Now I'm continue to investigate this situation. If you'll find such =20= >> case in >> your notebook or in desktop PC, then inform me on email. >> >> Best wishes & regards, >> MustLive >> Administrator of Websecurity web site >> http://websecurity.com.ua >> >
文章代碼(AID): #1A35o000 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 4 之 12 篇):
文章代碼(AID): #1A35o000 (Bugtraq)