Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 13th, 2011, 09:29 AM
moontan's Avatar
moontan moontan is offline
Massive Poster
 
Join Date: Sep 2010
Location: Québec
Posts: 3,180
Default Password for Admin account

i started using a standard account to increase security.

i used to use an Admin account without a password, being the sole user of this machine.

my question is:
is there any benefit security-wise of using an admin password when i run an app inside a standard account that needs a password?
or can i just run without a password?
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal |

Last edited by moontan : March 13th, 2011 at 09:37 AM.
  #2  
Old March 13th, 2011, 03:07 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Password for Admin account

In early XP days, I can remember vaguely a vulnability (dont know whether it was theoretical or exploitable) based on poor firewall, guest account and network shares, where a change of user to admin implicated that the intruder owned the machine. At least I can remember an advice to allways add a password for the admin, based on this story.
  #3  
Old March 13th, 2011, 03:12 PM
Brocke's Avatar
Brocke Brocke is offline
Updates Team
 
Join Date: Mar 2008
Location: USA,IA
Posts: 1,644
Default Re: Password for Admin account

well really password are weak in windows. Windows puts the password to all CAPS when being verified. unless that changed.
  #4  
Old March 13th, 2011, 05:34 PM
moontan's Avatar
moontan moontan is offline
Massive Poster
 
Join Date: Sep 2010
Location: Québec
Posts: 3,180
Default Re: Password for Admin account

tnx for taking the time to answer folks!

i have removed the admin password for the time being and unless someone can bring conclusive evidences as to why it should be on it will stay off.
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal |
  #5  
Old March 13th, 2011, 11:15 PM
safeguy's Avatar
safeguy safeguy is offline
Frequent Poster
 
Join Date: Jun 2010
Posts: 916
Default Re: Password for Admin account

I like to think of it as a simple way to avoid rogue people (with not much PC knowledge) tampering with your Windows settings.
__________________
Uncertainty is the only certainty there is, and knowing how to live with insecurity is the only security...
  #6  
Old March 14th, 2011, 09:18 AM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 641
Default Re: Password for Admin account

Sry double post
  #7  
Old March 14th, 2011, 09:22 AM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 641
Default Re: Password for Admin account

I've once been bypassed by an admin on my workplace ( I chalenge him to do it)
Even though I use password on log in
he is able to make a new admin account to access my laptop.

Can someone teach me how he did that?
Or at least tell how to stop that? (Without setting up bios password)

Since he still kept it as a secret from me ;p
  #8  
Old March 14th, 2011, 10:49 AM
Sadeghi85 Sadeghi85 is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 697
Default Re: Password for Admin account

Quote:
Originally Posted by blasev


Can someone teach me how he did that?

There are lots of software to do that.

Quote:
Originally Posted by blasev
Or at least tell how to stop that? (Without setting up bios password)

full disk encryption


EDIT:

Quote:
Originally Posted by blasev
(Without setting up bios password)

bios password on most computers can be bypassed, there are lots of software to do that too.

Last edited by Sadeghi85 : March 14th, 2011 at 10:55 AM.
  #9  
Old March 14th, 2011, 01:13 PM
Greg S Greg S is offline
Very Frequent Poster
 
Join Date: Mar 2009
Location: A l a b a m a
Posts: 1,039
Default Re: Password for Admin account

Quote:
Originally Posted by moontan
tnx for taking the time to answer folks!

i have removed the admin password for the time being and unless someone can bring conclusive evidences as to why it should be on it will stay off.
I see in your sig that you use UAC. What do you do in the standard account when presented with the UAC alert? Just click OK. I've always had a password and have mine set to provide credentials which includes entering the password so I have no knowledge of how it works without a password.
  #10  
Old March 14th, 2011, 01:20 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,565
Default Re: Password for Admin account

Quote:
Originally Posted by Greg S
I see in your sig that you use UAC. What do you do in the standard account when presented with the UAC alert? Just click OK. I've always had a password and have mine set to provide credentials which includes entering the password so I have no knowledge of how it works without a password.

You'd still get the same exact alert from UAC, the only exception being you'd have no password to enter; no username would be required either.

I believe the major concern would be whether or not you're part of a network, and if other machines may get compromised at some point; other concern would be other people at home/at work (if they could get their hands at your laptop/desktop).

Am I missing some other scenario?

Oh yeah, computer shops! Some folks enjoying seeing the photos, etc., specially if the client is a sexy lady. I don't think they would bother booting with some Linux live CD, would they? lol
  #11  
Old March 14th, 2011, 01:29 PM
Greg S Greg S is offline
Very Frequent Poster
 
Join Date: Mar 2009
Location: A l a b a m a
Posts: 1,039
Default Re: Password for Admin account

Quote:
Originally Posted by m00nbl00d
You'd still get the same exact alert from UAC, the only exception being you'd have no password to enter; no username would be required either.

I believe the major concern would be whether or not you're part of a network, and if other machines may get compromised at some point; other concern would be other people at home/at work (if they could get their hands at your laptop/desktop).
Network as in four Win 7 laptops in the house being able to see and use files from each other or use one printer for all? Presently on mine, I've disabled all the things that allow them or me to communicate with each other. They can do it with each other but I can't.
Quote:
Originally Posted by m00nbl00d
Oh yeah, computer shops! Some folks enjoying seeing the photos, etc., specially if the client is a sexy lady. I don't think they would bother booting with some Linux live CD, would they? lol
Uh, probably, lol
  #12  
Old March 14th, 2011, 01:34 PM
moontan's Avatar
moontan moontan is offline
Massive Poster
 
Join Date: Sep 2010
Location: Québec
Posts: 3,180
Default Re: Password for Admin account

Quote:
Originally Posted by Greg S
I see in your sig that you use UAC. What do you do in the standard account when presented with the UAC alert? Just click OK. I've always had a password and have mine set to provide credentials which includes entering the password so I have no knowledge of how it works without a password.

it works the same, i just click OK.

i'm not on a network and i'm the only one using this computer.

of course, if that is not the case you'd want to use a password...
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal |
  #13  
Old March 14th, 2011, 07:13 PM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 641
Default Re: Password for Admin account

Quote:
Originally Posted by Sadeghi85
There are lots of software to do that.
full disk encryption
EDIT:
bios password on most computers can be bypassed, there are lots of software to do that too.

Wow, my laptop is weak
  #14  
Old March 14th, 2011, 08:43 PM
bollity bollity is offline
Regular Poster
 
Join Date: May 2009
Posts: 156
Default Re: Password for Admin account

there is a security whole in windows called " hidden sharing". most users don't know anything about this whole.
hidden sharing will allow other network pc to see your files on the harddisk even if you don't make any sharing. so a password for any account including the administrator account is necessary.

go to control panel -- administrative tools--computer management ---shared folders --- shares and you will see what i mean.C$ D$ E$ ... etc, all are hidden sharing.

you can get rid of hidden sharing by editing registry. google " disable hidden sharing"

this is for 32 bit xp and win 7 :
add this value to this registry key
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters]

Value Name:AutoShareWks
Data Type: REG_DWORD (DWORD Value)
Value Data: (0 = disable shares, 1 = enable)

then restart and now there is no hidden shares.

http://www.petri.co.il/disable_admin...ive_shares.htm
  #15  
Old March 15th, 2011, 05:40 AM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 641
Default Re: Password for Admin account

Thx for the info
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:32 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums