lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20040120180852.0971697B44@cpo.tn.tudelft.nl>
From: emvs.fd.3FB4D11C at cpo.tn.tudelft.nl (Erik van Straten)
Subject: local SYSTEM on Windows vs. local root on Unix

On Mon, 19 Jan 2004 16:20:58 -0500 KF wrote:

> I am currious to know what you folks think the differences are between 
> obtaining local SYSTEM on a win32 box and obtaining root on a Unix machine.

They are equivalent.

However, there are very many more ways to become SYSTEM on an average
W32 box, than on a Linux box.

Which *IS* an advantage, because if you harden a W32 box, provided
you did a good job, typically morons will have to spend *A* *LOT*
more time to find the holes you overlooked (likely they'll give up
and try Annie's box next door).

With Linux, the first thing they'll do is see if you've patched your
kernel (which I, honestly, have not done on all boxes).

Erik (using both)


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ