Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation |
|---|---|
| Date: | Mon, 29 Nov 2004 10:40:11 -0600 |
This model breaks down, of course, in the home market, where people want unfettered access to their computer.
That's because it is (more than) pretty stupid to let users install software at all. The job of system administrators is to "manage" the systems they are responsible for. With Windows systems that requires that "ordinary users" (i.e. everyone whose job is not officially "system administrator") _MUST NOT_ be allowed to install new software. Sadly, extraordinarily few Windows system admins actually have enough nouse to realize this, and most of the few who do cannot get enough management muscle to back such a "draconian" policy.
Paul Schmehl (pauls@utdallas.edu) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] Privilege escalation flaw in the AClient Service for Windows (Version 5.6.181)., Reed Arvin |
|---|---|
| Next by Date: | [Full-Disclosure] [SECURITY] [DSA 601-1] New libgd1 packages fix arbitrary code execution, debian-security-announce |
| Previous by Thread: | Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation, Nick FitzGerald |
| Next by Thread: | RE: [Full-Disclosure] MS Windows Screensaver Privilege Escalation, Kovács László |
| Indexes: | [Date] [Thread] [Top] [All Lists] |