Infosecurity magazine posted an article
that supposedly shows how you can execute some commands to start windows xp up without a password. The article presents this as a "juicy" hack;
the short tutorial shows how, with the judicious use of the XP run command and tripping an executable, it is possible to start up Windows XP without requiring a
They also make a feeble attempt at classifying the feat;
Infosecurityisn't really sure either, but the breathtakingly
simple security bypass appears to have been coded as a backdoor to
Windows XP for administrators who have lost their password.
Lets clarify a few things;
- You need a valid login to do this
- Your user will need privileges to do this
- It will prompt you for the username and password to automatically log you on with the next time it starts up.
- It defaults to the current user so in this case they are running the control as the user Administrator.
Two minutes of research would have let the author of the article present it in the proper light. Tweaking a setting to automate the login screen so you don't have to see it. It is not a security bypass. I expect better from security specific magazines.