Subject: Re: "BSD Authentication"
To: Dave Sainty <dave@dtsp.co.nz>
From: Ted Lemon <mellon@hoffman.vix.com>
List: current-users
Date: 11/24/1998 11:12:18
> Heh, I can't think of an easier way to grab a sites root password. :)
>
> Come to think of it, NT does just this.... How funny...
Actually, NT has a solution for this. You know how it tells you to
type CTL-ALT-DEL to log in? It turns out that there's a reason for
this bogosity - CTL-ALT-DEL is a sequence that user processes are
prevented from trapping. It will _always_ get you to a real login
screen. If NT lets you type in the superuser password to get out of
the screen saver, that's a bug, but they do have a secure way for the
administrator to reclaim control of the console.
_MelloN_