WinXP Priviledge Escalation Problem

Yohhan

Senior member
May 17, 2002
263
0
0
Is it fairly easy for a limited user to escalate their privileges to administrator on WinXP home? I'm having a problem with a user who seems to be able to gain administrative rights fairly easily, even though he should be setup with just a limited account.
 

Alex

Diamond Member
Oct 26, 1999
6,995
0
0
from within a guest account on wxp you cant really do much at all. my roomate last year had xp home and a guest account for me but i just figured out his password and kept changing my priviledges etc just to mess around with him he never figured it out and i insisted that i managed to do that by "hacking the mainframe"

so yeah i dont think its really possible to do anything apart from surf the web from within a guest account and definitely not change settings so this guy knows your password or something... my 2cents
 

MrChad

Lifer
Aug 22, 2001
13,507
3
81
Guest account != Limited account.

I don't know how he could escalate his privileges without knowing your administrator password. You do have password protection on all of your admin accounts, right?
 

Yohhan

Senior member
May 17, 2002
263
0
0
I have a password on the administrator account.

Both mine, and the "hidden" administrator account that boots up in safe mode.

So guest mode is more restrictive than a limited account?
 

Alex

Diamond Member
Oct 26, 1999
6,995
0
0
Originally posted by: Yohhan
I have a password on the administrator account.

Both mine, and the "hidden" administrator account that boots up in safe mode.

So guest mode is more restrictive than a limited account?

yeah a guest account is like when you use a public terminal somewhere you can pretty much just run whats in the start menu and surf the internet...
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
If he doesnt know the password to any of the accounts that have administrative privilages than you have a serious issue. It could be that the system is missing critical updates (there have been a number of volunerabilities that allow for privilage elevation) or it could be that your system has been comprimised and he is aware of it (i.e. trojan/back door).

Whatever the case you know the system has been comprimised, it's going to be next to impossible to ever consider this system "clean". At the very least I would suggest a very thourough audit of the software and configuration and to change the passwords for all your accounts that have any level of privilages on the system.

I would also make your knowledge of the situation clear to him as well as making sure he knows that this kind of behavior is absolutly not acceptable (assuming it is something he did). If this is a personally owned system I wouldnt allow him to use it any more; if this is an institution I would suggest formal diseplenary action.

I take security breaches very seriously, if this were one of my systems his job would now be on the line.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |