Win XP "self-logout" function

  

Hotkey is a key and a set of keys used to start a program or use a function of a program. One key can include F1, F2 function keys, or Are some special keys.

1. Hotkeys

Hotkeys are a key and a set of keys used to start a program or use a function of a program. One key can include functions F1 and F2. The keys can also be some special keys, such as "internet" on the DELL keyboard, "mail" and other keys that are not on the general keyboard. The most common ones are some combination keys. The hotkeys that people who use QQ are most familiar with are " The ctrl+~" key combination is used to quickly view the sent information.

There are also many hotkeys that can be used to open programs. These hotkeys can be set by themselves. After setting, they can be used to open various programs. You can determine the rules for each program's settings, so that it can be effective. Use the hotkey function, for example, according to the first letter of the program, so after setting, you can easily open the notebook with "ctrl+Alt+N" and open Word with "ctrl+Alt+W". For those who are particularly dependent on a tool, such a way to open a program is convenient and therefore widely used.

2, winxp "self-deregistration" function

When we are in the office, we often need to leave temporarily, and put the computer on the desk, which means that the information is peeked or Lost even more serious consequences, so with a screen saver, if you set a password, then in general, others will not be able to move your computer. This ensures security.

In winxp, it provides a feature that we call "self-logout" (that is, automatic logout), which has the same effect as a screen saver, and has been on your computer for a while. It automatically logs out after the quiescent state, but this "logout" is a fake logout, all your background programs are still running, there is almost no difference before the logout, which leaves a hidden danger.

Vulnerability Description

The hotkey function is a service provided by the system (specifically, open the program, use the program's hotkey), and the service has not been executed during the startup process until the login interface. This feature is only enabled when you log in as a user. After execution, the user can use the hotkeys of the user's own settings (including some default hotkeys).

Suppose a user (he has the identity of an administrator and logs in as an administrator) has something to leave for a while, thinking that he will be back soon, but then he was forced to return immediately, and his computer was Exposed to the case of no protection, then winxp (the operating system of the computer mentioned here refers to winxp, and the operating system does not set the screen saver and the corresponding password) is very smart to automatically implement the "self Logout."

If this kind of cancellation is really written off, then this security measure is obviously very good, but as mentioned before, this kind of cancellation is fake, although others can't enter your desktop, I can't see what's on your computer, but they can also use the hotkey because the hotkey service hasn't stopped.

At this time, a hostile and experienced person can use these hot keys to do something. The easiest thing is to open N big programs to destroy your machine, you can open and use a program. In particular, some sensitive programs (and services) related to the network...

In fact, this computer is half controlled by him, as long as he has enough imagination...

Security Countermeasures < Br>

In fact, we have to admit that the above vulnerability is being used to make really destructive things. The probability is very small. It requires a lot of "hypothesis", but as a loophole, it is Really exist, not afraid of 10,000, just in case, just like "CDautorun", as far as we know, it has not been used to cause damage, but the possibility of this breach of security is really there. So in many public places (such as Internet cafes), this feature is turned off.

Copyright © Windows knowledge All Rights Reserved