TUCoPS :: Security App Flaws :: win5102.htm

Identix BioLogon can be bypassed
14th Feb 2002 [SBWID-5102]

	Identix BioLogon 3


	Paul A Roberts says :


	At an XP or NT login the operator presses CTRL-ALT-DEL. The GINA  option
	\"More\" can then be selected.  For  XP,  Configure  /  Sounds  is  then
	selected. An event can then be selected and \"Browse\"  initiated.  Once
	Browse is initiated System level explorer access is granted.  Files  can
	be copied to removable media or files can  be  imported  from  removable
	media to local locations such as  startup  folders.  Properties  can  be
	altered and files removed or added. NT 4  behaves  much  the  same  with
	minor menu differences.



