Identix BioLogon GINA Authentication Bypass Vulnerability
BID:4101
Info
Identix BioLogon GINA Authentication Bypass Vulnerability
| Bugtraq ID: | 4101 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0268 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 12 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This issue was reported to BugTraq on February 12th, 2002 by "Paul A Roberts" <[email protected]>. |
| Vulnerable: |
Identix BioLogon 3.0 |
| Not Vulnerable: | |
Discussion
Identix BioLogon GINA Authentication Bypass Vulnerability
Identix BioLogon is a software utility which provides support for biometric security measures (fingerprint readers, smartcards, etc.) on Microsoft Windows operating systems. Part of its design is to help restrict unauthorized users from physically accessing the host.
It is possible for a physical attacker to bypass the GINA (Graphical Identification and Authentication) interface. This may be accomplished if the attacker presses CTRL-ALT-DEL to access the GINA interface, and then selects the "More" option. Events may be selected and the attacker may initiate browsing. On Windows XP systems, the attacker selects the "Configure / Sounds" option after "More" to select events. Browsing grants system-level access to the host.
Identix BioLogon is a software utility which provides support for biometric security measures (fingerprint readers, smartcards, etc.) on Microsoft Windows operating systems. Part of its design is to help restrict unauthorized users from physically accessing the host.
It is possible for a physical attacker to bypass the GINA (Graphical Identification and Authentication) interface. This may be accomplished if the attacker presses CTRL-ALT-DEL to access the GINA interface, and then selects the "More" option. Events may be selected and the attacker may initiate browsing. On Windows XP systems, the attacker selects the "Configure / Sounds" option after "More" to select events. Browsing grants system-level access to the host.
Exploit / POC
Identix BioLogon GINA Authentication Bypass Vulnerability
There is no exploit code required.
There is no exploit code required.