Hotkeys in XP and Security Countermeasures

  

Hot Keyholes and Security Measures in XP

Hotkeys are a key used to launch a program or use a function of a program. A set of keys, one of which can include F1, F2 function keys, or some special keys.

1. Hotkeys

Hotkeys are a key and a set of keys used to start a program or use a function of a program. One key can include functions F1 and F2. The keys can also be some special keys, such as the keys on the DELL keyboard, such as “internet”, “mail”, etc., which are not commonly used on keyboards. The most common ones are some combination keys, the hotkeys most familiar to people who use QQ. It is a combination of “ctrl+~”” to open and quickly view the sent information.

There are also many hotkeys that can be used to open programs. These hotkeys can be set by themselves. After setting, they can be used to open various programs. You can determine the rules for each program's settings, so that it can be effective. Use the hotkey function, for example, according to the first letter of the program, so after setting, you can easily open the notebook with “ctrl+Alt+N”, open Word with “ctrl+Alt+W” For those who are particularly dependent on a tool, such a way to open a program is very convenient and therefore widely used.

2, winxp "self-deregistration" function

When we are in the office, we often need to leave temporarily, and put the computer on the desk, which means the information is If you have a password, you can't move your computer. This ensures security.

In winxp, it provides a feature that we call "self-logout" (that is, automatic logout), which is similar to the screen saver and has a section on your computer. When the time is at rest, it will automatically log out, but this "logout" is a fake logout, all your background programs are still running, there is almost no difference before the logout, which leaves a hidden danger .

Vulnerability Description

The hotkey function is a service provided by the system (specifically, open the program, use the program's hotkey), and the service has not been executed during the startup process until the login interface. This feature is only enabled when you log in as a user. After execution, the user can use the hotkeys of the user's own settings (including some default hotkeys).

Suppose a user (he has the identity of an administrator and logs in as an administrator) has something to leave for a while, thinking that he will be back soon, but then he was forced to return immediately, and his computer was Exposed to the case of no protection, then winxp (the operating system of the computer mentioned here refers to winxp, and the operating system does not set the screen saver and the corresponding password) is very smart to automatically implement "ldquo; Self-deregistration & rdquo;.

If this kind of cancellation is really written off, then this security measure is obviously very good, but as mentioned before, this kind of cancellation is fake, although others can't enter your desktop, I can't see what's on your computer, but they can also use the hotkey because the hotkey service hasn't stopped.

At this time, a hostile and experienced person can use these hot keys to do something. The easiest thing is to open N big programs to destroy your machine, you can open and use a program. In particular, some network-related sensitive programs (and services) ……

In fact, this computer is half controlled by him, as long as he has enough imagination … …

Security Countermeasures

In fact, we have to admit that the above vulnerability is being used to really make destructive things. The probability is very small. It needs a lot of "what if" is established, but as A loophole, it is actually there, not afraid of 10,000, just in case, just like "CDautorun", as far as we know, it has not really been used to cause damage, but this kind of destructive security The possibilities are real, so in many public places (such as Internet cafes), this feature is turned off.

Copyright © Windows knowledge All Rights Reserved