{"id":23193,"date":"2008-03-06T10:00:00","date_gmt":"2008-03-06T10:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/2008\/03\/06\/how-do-i-log-on-using-a-dial-up-connection-on-windows-vista\/"},"modified":"2008-03-06T10:00:00","modified_gmt":"2008-03-06T10:00:00","slug":"how-do-i-log-on-using-a-dial-up-connection-on-windows-vista","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20080306-00\/?p=23193","title":{"rendered":"How do I log on using a dial-up connection on Windows Vista?"},"content":{"rendered":"<p>Mike Stephens from the <a href=\"http:\/\/blogs.technet.com\/grouppolicy\/\">Group Policy Team Blog<\/a> explains <a href=\"http:\/\/blogs.technet.com\/grouppolicy\/archive\/2007\/07\/30\/where-is-logon-using-dial-up-connections-in-windows-vista.aspx\"> how to get &#8220;Log on using dial-up connections&#8221; working on Windows Vista<\/a>.\n But I&#8217;m posting to respond to a comment on that page, since that falls under the category of &#8220;When people ask for security holes as features.&#8221;<\/p>\n<blockquote class=\"q\"><p> The only problem is all users need to have access to an account with local admin privileges [in order to set this up]. <\/p><\/blockquote>\n<p> The implied request is that non-administrative users be allowed to  create dial-up connections that can be used for logging on. This request falls into the category of <a href=\"http:\/\/blogs.msdn.com\/oldnewthing\/archive\/tags\/When+people+ask+for+security+holes+as+features\/default.aspx\"> <i>When people ask for security holes as features<\/i><\/a>; in this case, it&#8217;s a <a href=\"http:\/\/blogs.msdn.com\/oldnewthing\/archive\/2006\/08\/25\/723428.aspx\"> repudiation security vulnerability<\/a>. Here&#8217;s how.\n A non-administrative user creates a dial-up networking connectoid and marks it as available for use during logon. For the phone number, the non-administrative user uses a voting number for a television reality show, one that charges $2 per call. (If you are more mercenary, you can arrange to set up a phone number that charges $50\/minute and agree to split the profits.) The non-administrative user then logs off and waits.\n When the show starts, the non-administrative user then goes up to the computer and <i>instead of logging on normally<\/i>, goes to the dial-up connection button and selects the dial-up connectoid. The non-administrative user then proceeds to make dozens of failed logon attempts with that connectoid, under bogus user names like <i><a href=\"http:\/\/www.msnbc.msn.com\/id\/18014242\/\">Sanjaya<\/a>Rocks<\/i> or <i><a href=\"http:\/\/www.williamhung.net\/\">WilliamHung<\/a>4Ever<\/i>. Each failed logon attempt casts a vote for the contestant, and (here&#8217;s the important part) <i>since nobody is actually logged on, you can&#8217;t prove who made the calls<\/i>.\n Some time later, the non-administrative user logs on and deletes the dial-up networking connectoid, to clean up afterward.<\/p>\n<p> The next month, the system administrator gets the phone bill and sees $100 worth of calls to the television show. The system administrator goes to the audit logs to see who made those calls, only to find that they were made by <i>nobody<\/i>. Even if the system administrator finds the logs for the non-administrative user having created and subsequently deleted the offending dial-up networking connectoid, that&#8217;s just circumstantial evidence. &#8220;I created those for fun, as a joke. I never actually used them. It must&#8217;ve been just somebody walking past the machine who saw that they could use it to vote for Sanjaya.&#8221; <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mike Stephens from the Group Policy Team Blog explains how to get &#8220;Log on using dial-up connections&#8221; working on Windows Vista. But I&#8217;m posting to respond to a comment on that page, since that falls under the category of &#8220;When people ask for security holes as features.&#8221; The only problem is all users need to [&hellip;]<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[104,141],"class_list":["post-23193","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-tipssupport","tag-when-people-ask-for-security-holes-as-features"],"acf":[],"blog_post_summary":"<p>Mike Stephens from the Group Policy Team Blog explains how to get &#8220;Log on using dial-up connections&#8221; working on Windows Vista. But I&#8217;m posting to respond to a comment on that page, since that falls under the category of &#8220;When people ask for security holes as features.&#8221; The only problem is all users need to [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/23193","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=23193"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/23193\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=23193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=23193"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=23193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}