Forum     

Go Back   Digit Technology Discussion Forum > Community > Tutorials
Register FAQ Calendar Mark Forums Read

Tutorials This section offers tutorials and How to's on just about anything related to computers and IT. Note: All tutorials are courtesy the posters and not verified by Digit


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 08-11-2007, 02:06 PM   #1 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Arrow Windows XP: the security holes


Microsoft Windows XP has been the most successful of the Windows Range of Operating Systems by Microsoft.
When I got my very first Computer assemble I had no knowledge about operating system, so the computer shopee guy installed Windows XP sp-2 on to my machine.
Since then this little piece of clicks and tricks has fascinated me a lot.

When I got internet connection on my system 3 years back, XP turned out to be a nightmare. I always had an updated AVG but still due to all my downloads I had enough virus’s which forced me to Reinstall the whole OS once in 2 weeks and that was when I started looking on the security features Provided by Windows XP.


Moving inside the box:


There are 2 security holes I found in Windows XP sp-2:

1) REPARING: When repairing the Windows XP, if we press Ctrl+F10 then the DOS prompt is popped up and you have the access (not administrator privilege) to the box.
2) RECOVERY CONSOLE: I’ve used a lot of third party software to protect my system but the best way I found was to physically block access to my PC…lol…


I started googling around for getting administrator access to XP box without a third party program but it turned out to be either very time consuming or not working for sp-2 and so I started looking for the answer on my own, when I ended up with a Windows 2000 bootable cd from a friend.


The game:


Most of you might have used the recovery console of Windows XP which asks the Administrators Password before letting you use itself, but what if we boot a XP sp-2 machine with Windows 2000 cd and start the recovery console present in it???

VOLA!!!! THE PASSWORD IS NOT REQUIRED
This is the most irritating fact the the machine with with XP’s latest service pack can easily be fooled.


The Steps:

a) Restart the system and pop in Windows 2000 bootable CD. (Check if the CD\DVD drive is set to primary boot over HDD in the bios system)
b) On the blue screen press R or F10 (f 9 worked fine on my lappy…) and the Press C to enter the recovery console.
c) Select the XP parathion from the menu and that’s it!


The access and stuff possible:


a) File and Folder: The XP recovery console does not allows even the Administrator to access all the drives but when using Windows 2000 recovery console the access is made easy and to all the drives.
b) Copy-ing: The XP recovery console does not allows coping of files and folders to a removal media (only floppy at this instance) but by editing the registry it is possible but when using Windows 2000 recovery console, coping files and folders is not a big task, its simple and no “Access Denied” error is given. This feature also allows you to make new file and folder and change its attribute also.
c) The Net User: The XP recovery console does not provides the “net user username password” command but when using Windows 2000 recovery console this command worked successful for me on a friends FAT-32 XP partition

Conclusion:

I tested this security hole (recovery console) on my brothers HP Laptop provide by the reliance company for his office work which has a lot of security features but in that case also I could get access to 60% of the resource and even had the power to format a parathion.
The method i described above is using Windows 2000 recovery console but using any Linux Distro will also allow you to have access to a lot of Resources. I would recommend Geexbox Distro for the same purpose.
After this finding of mine I strongly conclude that Windows XP is not a very secure operating system.
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 08-11-2007, 02:30 PM   #2 (permalink)
Dreamweaver
 
Gigacore's Avatar
 
Join Date: Aug 2006
Location: Bangalore
Posts: 3,904
Default Re: Windows XP: the security holes

Nice tut! Keeeeeeeeeeeep Going >>>>>>>>>
__________________
Today's noobs are tomorrow's geeks. Don't make fun of them.. encourage them. - Gigacore

Follow me on twitter.com/gigacore
Gigacore is offline  
Old 08-11-2007, 02:31 PM   #3 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Windows XP: the security holes

thx giga...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 08-11-2007, 04:00 PM   #4 (permalink)
Wire muncher!
 
infra_red_dude's Avatar
 
Join Date: Nov 2003
Posts: 6,164
Default Re: Windows XP: the security holes

This is a serious issue! Abhishek, IMO you should remove the procedure to gain access and only post about the security hole.
__________________
"The true measure of a man is how he treats someone who can do him absolutely no good."

http://phoenix-ani.blogspot.com
infra_red_dude is offline  
Old 08-11-2007, 04:12 PM   #5 (permalink)
God of Mistakes...
 
Garbage's Avatar
 
Join Date: Dec 2005
Location: Pune, Maharashtra
Posts: 1,923
Default Re: Windows XP: the security holes

Quote:
Originally Posted by infra_red_dude
This is a serious issue! Abhishek, IMO you should remove the procedure to gain access and only post about the security hole.
WHY ??? Afterall it's a loophole in Operating System. M$ should be knowing that.

Open Source community also improved itself this way.. by discussing loopholes and coming with solutions. M$ should also get his chance !!

BTW, Very gr8 find Abhishek !!
Keep it up !!!
__________________
Registered Linux User #468778
----------------------------------
http://twitter.com/_Garbage_
Garbage is offline  
Old 08-11-2007, 04:14 PM   #6 (permalink)
Wire muncher!
 
infra_red_dude's Avatar
 
Join Date: Nov 2003
Posts: 6,164
Default Re: Windows XP: the security holes

I'm asking the author to keep the info about the loophole but remove the procedure of breaking into the system. Thats it
__________________
"The true measure of a man is how he treats someone who can do him absolutely no good."

http://phoenix-ani.blogspot.com
infra_red_dude is offline  
Old 08-11-2007, 04:17 PM   #7 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Windows XP: the security holes

thx guys....and INFRA_RED_DUDE...i think shirish_nagar is right...

@shirish_nagar: hey ur a mem at igniteds too...chears bro...me too...strange_abhi der...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 08-11-2007, 04:28 PM   #8 (permalink)
God of Mistakes...
 
Garbage's Avatar
 
Join Date: Dec 2005
Location: Pune, Maharashtra
Posts: 1,923
Default Re: Windows XP: the security holes

Quote:
Originally Posted by Abhishek Dwivedi
thx guys....and INFRA_RED_DUDE...i think shirish_nagar is right...

@shirish_nagar: hey ur a mem at igniteds too...chears bro...me too...strange_abhi der...
yeh... I'm a die hard fan of IG. In fact Mr. Anup Girdhar and Vineet Kumar (Founders of National Anti-Hacking Group) are my friends !!

@ Aniruddha,
Can u please tell me why u want NOT to disclose the procedure ??
__________________
Registered Linux User #468778
----------------------------------
http://twitter.com/_Garbage_
Garbage is offline  
Old 08-11-2007, 04:42 PM   #9 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Talking Re: Windows XP: the security holes

Quote:
Originally Posted by shirish_nagar
yeh... I'm a die hard fan of IG. In fact Mr. Anup Girdhar and Vineet Kumar (Founders of National Anti-Hacking Group) are my friends !!

@ Aniruddha,
Can u please tell me why u want NOT to disclose the procedure ??

cool man...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 08-11-2007, 04:58 PM   #10 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,447
Default Re: Windows XP: the security holes

You can report it to Microsoft, only thing is they might ask if you have licenses for your XP and Windows 2000
As for Linux, I think any should do. From my linux partitions I can access system32\config too. Ophcrack uses slax to access windows partitions.
NucleusKore is offline  
Old 08-11-2007, 05:19 PM   #11 (permalink)
Alpha Geek
 
choudang's Avatar
 
Join Date: Sep 2005
Location: Guwahati
Posts: 812
Default Re: Windows XP: the security holes

XP is not secure in FAT-32 file system. Even admin password can be changed thru recovery [shift+F10].

Time ago, i was successful in installing staffs in Win2000 without having a power user or adminstrator rights. Do not use the system folder for installation, use diff drive and it will get installed.

The bottom line is that Microsoft is having lots of security holes, even they are using Genuine Validation method, which can be over passed (already done in IE7 and WMP 11 with an small java script)
__________________
For every action, there is an equal and opposite criticism.
choudang is offline  
Old 08-11-2007, 07:30 PM   #12 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Windows XP: the security holes

@Nucleuskore: a frnd informed me dat MC already knows dis sumhow...so its useless reporting.

@warrior: XP isn't safe in NTFS, i cud change ma pass thru dis trick in NTFS patation...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 09-11-2007, 11:32 AM   #13 (permalink)
Wire muncher!
 
infra_red_dude's Avatar
 
Join Date: Nov 2003
Posts: 6,164
Default Re: Windows XP: the security holes

@shirish
For safety reasons of corz! Until Abhishek posted, I didn't know that it could be done. Now anybody can read this post and try to hack into precious data (i'm talking about office environment, a lot of people visit this forum which includes huge no. of unregistered users all over the world).
__________________
"The true measure of a man is how he treats someone who can do him absolutely no good."

http://phoenix-ani.blogspot.com
infra_red_dude is offline  
Old 09-11-2007, 01:50 PM   #14 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Windows XP: the security holes

@INFRA_RED_DUDE: yar i've not given ne kinda step by step tut...i've just xplained it up and dats it...if da mods think its harmfull..den dey can remove it...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 09-11-2007, 02:48 PM   #15 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Default Re: Windows XP: the security holes

It is the responsibility of windows users to "protect" their machines "physically",even in office circles.I dont think @abhishek's writing harms.he shared his knowledge.that it.btw,congos for the article
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Old 09-11-2007, 03:20 PM   #16 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Windows XP: the security holes

thx prakash.....and ur right....physical security is da best at da moment...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 18-06-2008, 01:40 AM   #17 (permalink)
Right Off the Assembly Line
 
tech24's Avatar
 
Join Date: Jun 2008
Posts: 5
Thumbs up Re: Windows XP: the security holes

well their site is back now... they were down for a long and i just came across with their site yesterday night... when i saw their new interface then i thought some other one might have started that awesome community again but when i went through the member names, then i saw that they were the same admins, members etc etc.... actually one of my frnd told me abt their return back news so i just googled them and got them again

edited the post again... just forgot to add their name... i was talking about igniteds community... i think u people will be very happy to hear about this news after a long time hehehee

Last edited by tech24; 18-06-2008 at 01:43 AM. Reason: forgot to mention about whom i was talking
tech24 is offline  
Old 20-06-2008, 05:43 PM   #18 (permalink)
Fast 'N' Furious
 
topgear's Avatar
 
Join Date: Jul 2006
Location: Geek's Heaven
Posts: 11,169
Default Re: Windows XP: the security holes

Good one.....Page Saved
__________________
ToPsPeEeD = FaSt BuT StEaDy

AMD Radeon HD 6850 OverClocked to 1 Ghz !!!

Blog : http://topgeartopspeed.wordpress.com/
----------------------------------------------------
Never buy viewsonic products : http://tinyurl.com/ykwx4oa
topgear is offline  
Old 20-06-2008, 05:50 PM   #19 (permalink)
God of Mistakes...
 
Garbage's Avatar
 
Join Date: Dec 2005
Location: Pune, Maharashtra
Posts: 1,923
Default Re: Windows XP: the security holes

Quote:
Originally Posted by tech24 View Post
well their site is back now... they were down for a long and i just came across with their site yesterday night... when i saw their new interface then i thought some other one might have started that awesome community again but when i went through the member names, then i saw that they were the same admins, members etc etc.... actually one of my frnd told me abt their return back news so i just googled them and got them again

edited the post again... just forgot to add their name... i was talking about igniteds community... i think u people will be very happy to hear about this news after a long time hehehee
Hey, thanks bro for the news... Let me check the site !!
__________________
Registered Linux User #468778
----------------------------------
http://twitter.com/_Garbage_
Garbage is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Apple megapatch plugs 45 security holes Ankur Mittal Technology News 29 23-03-2007 12:52 PM
Apple plugs four security holes techtronic Technology News 1 16-02-2007 08:54 PM
Many, many, many security holes in the Microsoft Frontpage wolvrine Tutorials 1 17-09-2005 11:46 PM
Three new Windows security holes come at a bad time imprince Software Q&A 8 28-12-2004 12:05 AM

 
Latest Threads
- by Who
- by Krow
- by clmlbx
- by Tech&ME
- by icebags

Advertisement




All times are GMT +5.5. The time now is 09:08 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2