PDA

View Full Version : Logon Authentication Security Breach


Dave McMahon
December 18th 03, 06:37 PM
Stumbled on an issue where I can access an XP Pro system
by typing in a password leaving user ID blank. The
password was/is associated with the original admin
profile established during the initial OS installation.
The administrator profile folder continues to exist under
docs & settings even though the original admin user was
deleted from within the Users applet (control panel)
after creating two new replacement administrator accounts
with non-descript names and different passwords. The
original "administrator" user profile does not appear in
the users applet in control panel, essentially making it
an invisible point of access (unless you happen to notice
the user folders existence in docs & settings. Has anyone
seen this before?

additional info:

NTFS partitions
client is Domain member
all users domain logon
2 new admin accounts are local machine only
original admin account in question was/is local machine
only

Google