RSS All Posts

RSS PowerShell Posts

Tags

2142 Active Directory Administrativia Announcements Battlefield Blogging Cricket Deployment Deployment4 Get-PSUGUK Group Policy HowTo Linux MDT MDT 2010 Microsoft Deployment Toolkit MSDN Music Permissions Personal PowerGui Power Lines PowerShell PowerShell Groups PowerShell Support PowerShell Tools PowerShell V2 Presentations PSUGAU Quick Tips Scripting SDDL Security Tech Talk Ubuntu User Groups Virtualisation VMware Infrastructure Client WAIK Weekly Poll Windows 7 Windows Automation Installation Kit Windows Server 2003 Windows Server 2008 XML

Archives

Meta


« | Main | »

Windows 2008 Hacked?

By Adam Bell | February 11, 2008

Dean, has put up a post explaining an architectural defect in the way Windows Server 2008 handles the Accessibility Options prior to login.

As Microsoft’s 3rd Law of security states, if you have physical access, then it’s not your box anymore. And this is just another good reason why physical security is one layer in your security policy. You do have a multi-layered security policy don’t you?

Really, this comes down to, why MS:

1. Give an anonymous console user the ability to kick of a SYSTEM level process. DOH!
2. Not having the GINA validate what it is launching.
3. Having this as the default and not an option. DOH! Again!
4. SYSTEM Full Control over the Active Directory – Priceless!

Windows Server 2008 is moving in the right direction, they are reducing attack surfaces out-of-the-box and producing a more secure, leaner OS, which is great. I guess they missed this one ….

The post is well worth a read, cheers Dean :)

Topics: Security, Windows Server 2008 | No Comments »

Comments