Circumvent entering password on a locked machine!

  • Thread starter Thread starter Crappy
  • Start date Start date
C

Crappy

Hi All,

I just stubled onto a way that allows me to see and run anything on my
machine or any other locked machine without entering a password.

The Audi screen saver (www.audi.com) must be used. I suppose you could
create your own which does the same.

Once the screen saver is active, there is a button at the bottom of the
screen called Open Moment.
This allows you to open the audi site in internet explorer.
Once that open (Still no password needed) you can change the location
from audi to C:. I used a site on a server which has an IFRAME with SRC
of C:\
I could see all files and execute anything I wanted. I ran regedit and
changed the value of ScreenSaverIsSecure from 1 to 0. Next time the
poor person thinks that their screen saver is actually secure and you
walk along and do what you want...

Before anyone wants to arrest me, this is what I found, not created :)

FYI:


Cheers,
Crispin
 
Interesting. This is another reason why admins use Group Policy to specify
which screensaver a user can use on their computer as there are a lot of
junk and insecure ones out there. I wonder if they use that screensaver at
Audi?? --- Steve
 
This is pretty well known and has been for some time. It is a function of the
screen saver, not the OS.
 
Back
Top