Re: zoinks!@ I knew I didn't like Vaios



ThePsyko wrote:
On 08 Nov 2005 in alt.2600, Mimic <dev@xxxxxxxx> made their contribution
to mankind by stating in
news:w6-dnaMlncM6u-zenZ2dnUVZ8qOdnZ2d@xxxxxxxxx:



ThePsyko wrote:

On 08 Nov 2005 in alt.2600, Mimic <dev@xxxxxxxx> made their
contribution to mankind by stating in
news:u62dnVH7GP0rae3enZ2dnUVZ8tydnZ2d@xxxxxxxxx:




ThePsyko wrote:


C&P from Bugtraq


Sony Vaio laptops require you to create a user account the first
time you start your laptop. If the user you select is not
"Administrator", Sony still goes ahead and creates a user
"Administrator" with a blank password.


This user does not show up in control panel under User Accounts but
if you do start up in safemode the laptop allows you to login as
Administrator.


This gives an attacker an opportunity to gain administrative access
to a computer and access to create add delete or modify user
accounts.


This is basically a backdoor account that is hidden from the user
and compromises the security of all Sony Vaio laptops.

--
Securityforge: For all your security needs
(http://www.securityforge.com) Dbtech: Get the best programmers for
your buisness (http://www.dbtech.org)



... when you get to the GUI login and "dont" see the administrator account, tap ctrl-alt-del twice, which will give you the classic 2k style login, and you can punch into the admin from there, although
Ive found sometimes itll only allow you to in safe mode, sometimes
any mode, guess its down to SP and patches or summink :P




yeah I know... I read that post and didn't think about it being XP.

Never mind :)

/me wanders off muttering something about too many things going on at
once


touch me in my pants and I'll let you off ;/



ummm.. I don't think so!


I meant send biscuit.... :/

--
Mimic

First day it opened I went down there, was doing a few laps and pulled over and the manager comes over to me and says "Oi, mate! No professionals." I said I'm not a professional. He said "Well, you should be with moves like that you could be the best in Britain". I said, "No thanks I'm making shit loads from computers".

[email: ZGF0YWZsZXhAY2FubmFiaXNtYWlsLmNvbQ==]
Help Stop Spam - www.hidemyemail.net

"I have come to realise that, only in death, will I find true perfection."
.



Relevant Pages

  • Re: zoinks!@ I knew I didnt like Vaios
    ... you start your laptop. ... Sony still goes ahead and creates a user "Administrator" with a blank ... This user does not show up in control panel under User Accounts but ... compromises the security of all Sony Vaio laptops. ...
    (alt.2600)
  • Re: Domain changed - locked out
    ... There are few accounts ... >that are created when you install Windows. ... administrator password, ... >> doing this using my home network so the laptop was not ...
    (microsoft.public.win2000.security)
  • Administrator Changes
    ... Hello - On my wife's laptop, I have 2 accounts, mine as the administrator, ... When she receives an email in Outlook in her account, ...
    (microsoft.public.outlook)
  • Changing access to programs by different user accounts
    ... Prior to setting up a laptop as a 'family' unit with 3 different User ... I (administrator) installed programs which allowed access by ... The other 3 User accounts have been assigned 'Limited' accounts. ... 'limiteds' to mess around with. ...
    (microsoft.public.windowsxp.basics)
  • Re: Verification of replication
    ... >>> and even to corruption of the back end data file. ... >> thought was to ask the user for the cases then filter the forms to ... make sure that the users don't log on as an administrator. ... > laptop, and allow it to be administered only when connected to the ...
    (microsoft.public.access.replication)