Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: ... Tiny Personal Firewall ...

... Tiny Personal Firewall ...

From: Andrew Barkley <andrew.barkley_at_usa.net>
Date: Fri Mar 01 04:27:19 2002

Hi ...

Scanning hosts running the Tiny Personal Firewall (2.0.15a) on W2K
workstations that have been locked (ctl + alt + del)

The popup alert/dialogue jumps to the foreground, thus open to accept
permit/deny input from the local console, even when the workstations are
locked (ctl + alt + del). Thus an untrusted individual whom has local access
to individuals workstations can scan a workstation/network, wait for the popup
alert dialogue and enter "permit" on unattended (locked workstations) without
the owners permission/knowledge, No need to first unlock (ctl + alt + del)
...

CHEERS ...
Received on Mar 01 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos