4 ms·
This bug only applied to grub authentication, which isn't a widely used feature. And you could achieve the same result with boot from disk/USB if that is enable
by biggestdecision 8y ago
This bug only applied to grub authentication, which isn't a widely used feature. And you could achieve the same result with boot from disk/USB if that is enabled.
The vuln doesn't give you access to the actual accounts on the computer.
- seanp2k2 8y agoLet's not forget https://www.cvedetails.com/cve/CVE-2013-1050/ https://www.cvedetails.com/cve/CVE-2013-1050/ and https://www.cvedetails.com/cve/CVE-2015-7496/ https://www.cvedetails.com/cve/CVE-2015-7496/ and https://www.cvedetails.com/cve/CVE-2017-8900/ https://www.cvedetails.com/cve/CVE-2017-8900/ (to a lesser extent). Check out https://www.cvedetails.com/vulnerability-list.php?vendor_id=0&product_id=0&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=1&opfileinc=0&opginf=0&cvssscoremin=7&cvssscoremax=0&year=2018&month=0&cweid=0&order=3&trc=194&sha=05aa8f8c1263cd6dfb415503c9c247a410d9fb3a https://www.cvedetails.com/vulnerability-list.php?vendor_id=... for more fun.
- samstave 8y agohttp://i.imgur.com/rG0p0b2.gif http://i.imgur.com/rG0p0b2.gif
- stiGGG 8y agoOh dear, I remember something similar was possible on iOS lockscreen multiple times. What version of Windows was that?
- samstave 8y ago95. 98 had an even better one... just hitting cancel on some login boxes would let you in.
- cheerlessbog 8y agoI believe that was by design: the dialog was an opportunity to authenticate with the domain. If you just wanted local access you could hit cancel. Remember Win9x was not a secure OS itself.
- eitland 8y agoPretty sure I've seen a similar trick on XP or later as well. (I learned it from someone I didn't meet until long after I last saw a 95/98/2000 machine.)
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- raverbashing 8y agoBut the Windows 95 login was just for logging into the network, not the computer I think that if you hit Cancel there it would work just as well. You wouldn't get it logged into the domain though
- rusk 8y agoYes - from what I recall there was not even a pretense of security. Everything was just unencrypted FAT (VFAT rather than FAT32) and if you logged in as one user all other user's data was clearly visible - it was just a means to have your own user workspace and customisations applied. Windows 95 and everything up to (not including) XP was a toy OS for home users ... If you wanted "grown up" features you had to go for NT.
- semi-extrinsic 8y agoThis was the worst one for me: https://www.cvedetails.com/cve/CVE-2017-12712/ https://www.cvedetails.com/cve/CVE-2017-12712/
- dmitriid 8y agoI remember an article somewhere about these kinds of bugs. A lot of medical hardware/software combos are/can be compromised. And here comes the problem: do you disclose the vulnerabilities since it means potentially killing people? How long do you wait before manufacturers acknowledge and fix the problem (and they often don't)? So yeah, these types of vulnerabilities are very very scary.
- jodrellblank 8y agonot forgetting https://www.jwz.org/blog/2015/04/i-told-you-so-again/ https://www.jwz.org/blog/2015/04/i-told-you-so-again/
- AJRF 8y ago!WARNING! - This now redirects to an image of a hairy testicle. I think the site owner noticed the traffic and put in a redirect.
- obituary_latte 8y agoHeh just saw/posted the same. I think you’re right - jwz being a little trolly.
- eMSF 8y agoIt's been that way for years (i.e. visitors from HN get redirected).
- AJRF 8y agoAh you are right, should have experimented with that.
- obituary_latte 8y agowtf. Clicking your link brought me to http://i.imgur.com/rG0p0b2.gif http://i.imgur.com/rG0p0b2.gif somehow. jwz doing a referrer troll?? Anyone else see this?
- sebcat 8y agoProbably Referer check, copy-pasting the URL works.