Help : Win95 securuty hole (one more)

Michel Applaincourt Michel.Applaincourt at umh.ac.be
Wed Feb 25 09:02:16 GMT 1998


Hi all, 

ma again. I know I should drop 95 and get all my stations on Linux, but
that's not the opinion of my boss so...

I am trying (if possible) to secure Win95 computers with connexions to
samba, deported profiles, policy, accounting of what is done and by who,
...
Ok all of that works and yesterday I discovered a hole i didn't knew.
I knew that when in a session, you get start menu from task bar when you
press CTRL+ESC.
What I didn't knew is that, when out of a session, if you pree CTRL+ESC,
you get task manager. That tool permits you to shutdown computer, but also
(thanks to Bill Gates) to run an application.
I tried to execute 'explorer' and guess what : I get a session, while
computer was still asking me to identify : I get task bar and desktop of
the last person who locked. I did not tried, but i guess if I wanted, I
could run regedit. 
And I can't even know who do that, cause the user did not log on so did
not identify...

Ok, you could say users have to know to do that but THAT'S the users i
don't want to touch the configuration of win95 who show me that trick.

Has anyone an idea to prevent this : for example trap keys when CTRL+ESC
is pressed so they can't access task manager, or remove run an app from
task manager, something like this...

I HATE MICROSOFT!!!!!

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Michel  APPLAINCOURT     | E-mail : michel.applaincourt at umh.ac.be
 Computer Sciences Assistant | Phone  : 32 65 373498 
 Universite de Mons-Hainaut  | Fax    : 32 65 373318
                         
                          [Sad...But True]
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-




More information about the samba mailing list