Tom's Hardware > Forum > Windows XP > Security Admin > XP Exploit issue!
Word :    Username :           
 

How do i prevent someone from doing this?

How to get System privileges in Windows XP using a limited account

-Open a command prompt,

-Then type at ##:## /interactive "cmd.exe" (##:## is time 24hrs. eg 5:30pm=17:30)

-When it gets to the time you specified, a new command prompt should open,

-So open the task manager (press CTRL+ALT+DEL or type taskmgr in command prompt) and end the "explorer.exe" process (Everything on the desktop will disappear, but the command prompt will stay),

-Then type explorer.exe (A new desktop should appear).

-And you now have System privileges.

Any thoughts on how to prevent someone from doing this?? Disabling the command prompt wont work neither will disabling the task manager. you can enable both from the registry.

Sponsored Links
Register or log in to remove.

From Windows Help:

"By default only a Local Administrator can issue an AT command"

Great exploit, dude!

The answer is, if you don't trust your users then don't make them Administrators. Pretty simple stuff really.

Reply to ijack

thats the problem they dont have to be a administrator to get on the admin account. they just need access to the command prompt

Reply to Glut

And the authority to run the "at" command - which an ordinary user doesn't have.

Reply to ijack
Tom's Hardware > Forum > Windows XP > Security Admin > XP Exploit issue!
Go to:

There are 705 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them