Full Disclosure mailing list archives

Re: Odd Behavior - Windows Messenger Service


From: Jay Sulzberger <jays () panix com>
Date: Wed, 16 Jul 2003 19:59:32 -0400 (EDT)



On Wed, 16 Jul 2003, Blue Boar wrote:

morning_wood wrote:

imho it is iresponsible default behaivor for a workstation OS to allow
remote resources / services / enumeration
before any interactive user or administrative login.

That's what services do.  If you don't want it to do that, run it as a
regular app.  What do you suggest they do with the login service?

                                      BB

Step 1: Protect it from possible spoofs by not running uncontrolled
channels at startup.

oo--JS.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: