Cracking passwords in Windows 7, Child's play


Recommended Posts

Agreed. Every technology has its own weaknesses but why not use BitLocker which is readily available on your machine? I guess if one is not happy with the available encrypting methods, they can always lock their laptop in a bank vault.

Yeah, but Microsoft left a backdoor in bitlocker too. Easy to bypass and unencrypt data, even if the PC is off.

Overall Linux distributions have a less complex design that is easier to understand. It doesn't have anything to do with security. Windows is simply more complex, convoluted and hard to understand.

:blink:

Err wha? Linux is simple and easy? I'm not sure what distro you have been running, but I think you're quite a bit mistaken. Maybe you are thinking about the *nix derived (via BSD) Mac OS X stuff?

I know Linux has gotten a LOT better over the last 10 years and I now have family I've convinced to run it as their primary OS in many cases, but I would't say it is easier than Windows at all. Of course, comparing the two on ease of use in many areas can be like comparing apples and oranges, but I don't think many people find the command line easy. Us geeks maybe, but not the majority of society.

How can they access your data with your computer turned off?

You didn't get the memo? BitLocker forces the HDD to print all of its contents in braille on the bottom. So easy even a blind man can steal the data! (sarcasim)

Err wha? Linux is simple and easy? I'm not sure what distro you have been running, but I think you're quite a bit mistaken. Maybe you are thinking about the *nix derived (via BSD) Mac OS X stuff?

No, I am not saying that Linux is "simple and easy" to use (although that all depends on what you mean by Linux), I am saying that it has a less complex design where it is easier to understand how things work and fit together. Windows is reasonably user friendly on the surface, but once you start digging a little it is arguably the most complex operating system on the market. I would say that it is both the most difficult to understand and the most difficult to develop for. I didn't think this was a controversial statement.

This is just libelous unless you're being sarcastic or can actually provide concrete evidence.

See: http://cryptome.org/ (This link probably won't be around for long). There's a PDF there with information.

I reset peoples password all the time. They bring them too my office and don't tell me what the windows password is. So I just wip out the boot cd and blank it out. Then tell then when i'm done that they have to go in and reset the password.

See: http://cryptome.org/ (This link probably won't be around for long). There's a PDF there with information.

I read that 107 page power point :wacko: and it doesn't seem easy and those "backdoors" don't seem to help unless you can get the pin from someone. From what I understand you need the pin so you can access the drive to get the password, or use a hardware attack on the TPM to get access. And the only person who knows the pin is the person who's computer it is, or it;s on the usb drive for booting

I'll see if I Can find the other FTK article too :)

Or you can just recognize the fact that Microsoft is a serious company and does not leave backdoors in Windows. Unless you have the key, you cannot decrypt BitLocker. This is on page 1 of any forensic guide.

I am not sure if you quite understand the devastating consequences any backdoors would have for Microsoft.

Hmm... I was under the impression that the discussion of circumventing security is against forum rules.

Nope. Posting articles relating to exact methods that can be used to circumvent it is.

Can Linux be hacked if the hacker had physical access?

Possibly. I wouldnt think its any harder than Windows, so long as you have the right tools and knowledge, however, the questions you should ask is actually this:

Can a machine be hacked locally regardless of the OS installed on it?

The answer would usually be yes. Unless the person is clever enough to place a BIOS and HDD password on the machine along with only having the primary HDD as the only boot device, they will likely not be able to hack it, or at least not easily.

Or you can just recognize the fact that Microsoft is a serious company and does not leave backdoors in Windows. Unless you have the key, you cannot decrypt BitLocker. This is on page 1 of any forensic guide.

I am not sure if you quite understand the devastating consequences any backdoors would have for Microsoft.

Ah, but they do, quite often, either intentionally or un-intentionally... It has hasent had any devistating consiquences on them yet and they usually patch it quickly when they are found. The only consiquence it does have, is that the Linux community of hardcore users, will use it to "further prove Linux security is far better" etc etc.

Seriously hdood, try calming down on the rudeness. It wont win you many friends. A simple, i think you are wrong because of x, y and z, would have been enough, rather than saying, "or you can just recognise". It makes you sound awfully self opinionated and stuck up.

Possibly. I wouldnt think its any harder than Windows, so long as you have the right tools and knowledge

More often than not you don't even need any tools. You can simply boot to a root console and change the password, giving you full access. Does this mean that Linux is insecure? No, it just means like you say that all bets are off when someone has physical access to the machine.

Ah, but they do, quite often, either intentionally

Since I don't think you actually believe this, I will come right out and call it a lie.

or un-intentionally...

A backdoor is something that is intentionally added to allow security measures to be bypassed. There is no such thing as an "unintentional" backdoor. That is called a bug or a design flaw/limitation, and is a separate issue. Now, you could argue that they added backdoors concealed as bugs, but I think there is a separate section of the forum dedicated to conspiracy theories.

It has hasent had any devistating consiquences

It hasn't because they do not exist.

Seriously hdood, try calming down on the rudeness. It wont win you many friends. A simple, i think you are wrong because of x, y and z, would have been enough, rather than saying, "or you can just recognise".

It's an extremely serious accusation (in fact, one of the most serious you can make), and when someone makes a claim of this magnitude, the onus is on them to prove it. No one else even have to explain why they "think" it's wrong. You can't sit there and claim that something that is even sold as a security product to foreign governments has backdoors without having the evidence. If you have this, you should be able to produce it virtually from memory. Saying that "you think you read it somewhere" doesn't cut it.

For all you who think encryption cannot be evaded, check this out:

1024-bit RSA encryption cracked by carefully starving CPU of electricity

University of Michigan claims they can break the encryption simply by tweaking a device's power supply. By fluctuating the voltage to the CPU such that it generated a single hardware error per clock cycle, they found that they could cause the computer to flip single bits of the private key at a time, allowing them to slowly piece together the password.

Source: http://www.engadget.com/2010/03/09/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-ele/

Hmm... I was under the impression that the discussion of circumventing security is against forum rules.

Giving (or linking to) detailed instructions on how to crack a secure system would be against the rules. I gather that the purpose of this thread is to inform people that the Windows account passwords are not a secure system (never were and still aren't) and that they should not rely on it for security. Several people have posted more secure methods of protecting their data. The purpose of this thread would seem to be how to enhance security rather than how to defeat it and thus it is not against the rules.

More often than not you don't even need any tools. You can simply boot to a root console and change the password, giving you full access. Does this mean that Linux is insecure? No, it just means like you say that all bets are off when someone has physical access to the machine.

Quite. Because its simple to boot to a root and change a password, when you dont already have the root password to begin with :rolleyes:

Since I don't think you actually believe this, I will come right out and call it a lie.

I wouldnt have said it if i hadnt been sure. Dont assume anything and dont tell me what i do and dont think\believe.

A backdoor is something that is intentionally added to allow security measures to be bypassed. There is no such thing as an "unintentional" backdoor. That is called a bug or a design flaw/limitation, and is a separate issue. Now, you could argue that they added backdoors concealed as bugs, but I think there is a separate section of the forum dedicated to conspiracy theories.

I was aiming toward both of what you are saying. Both intentional "bugs" and un-intentional...

I reffer to Windows and\or Office 2007 "phoning home". I believe at first there where undocumented methods of gaining access to someones machine by re-routing the call to a remote server, so that the attacker could launch there attack\gain access to the machine.

It hasn't because they do not exist.

See my above quoted post... it clearely does\has.

It's an extremely serious accusation (in fact, one of the most serious you can make), and when someone makes a claim of this magnitude, the onus is on them to prove it. No one else even have to explain why they "think" it's wrong. You can't sit there and claim that something that is even sold as a security product to foreign governments has backdoors without having the evidence. If you have this, you should be able to produce it virtually from memory. Saying that "you think you read it somewhere" doesn't cut it.

Yes yes and blah blah evidence and blah blah you provide it and blah blah.

Seriously mate. You are so original. You even contradict yourself within a couple of words of your stuck up posts. Lets see shall we:

You say in one post - "It hasnt because it doesnt exist" <-- note the lack of proof in this claim. Also notice how you expect people to take your word as god, as though you know EVERYTHING far more than most of the truely technical people on here, such as Budman.

Now, within your very same post you say this - "when someone makes a claim of this magnitude, the onus is on them to prove it" <-- That is a direct contradiction of your sentence only a few lines above.

Now, im not saying that i have supplied proof on everything i have ever said, as no-one ever could. However, if you are going to bang on at people about providing "proof" when ever you are challenged, then make sure you are going to or even do provide proof when you challenge someone... Or is it a case that you are more superior to everyone else and dont need to prove... ANYTHING!? :rofl: :rolleyes:

Quite. Because its simple to boot to a root and change a password, when you dont already have the root password to begin with :rolleyes:

Yes it is.

I reffer to Windows and\or Office 2007 "phoning home". I believe at first there where undocumented methods of gaining access to someones machine by re-routing the call to a remote server, so that the attacker could launch there attack\gain access to the machine.

That would be a remote vulnerability, not a backdoor.

See my above quoted post... it clearely does\has.

It does not. All you appear to be saying is that Windows has had its share of remote vulnerabilities over the years. While true, these are not backdoors. A backdoor is a piece of code intentionally placed there to allow someone to circumvent security. This is extremely serious, so I'd like you to document it so I can forward the information to the proper authorities in my country so that a criminal investigation can be launched. If any local branches of Microsoft are involved, this might even constitute acts of treason. This is not a joke, I really will do this.

Also notice how you expect people to take your word as god

"My word?" You mean my claim that Windows contains no backdoors? I'd so it's a pretty damn well substantiated claim, considering there is absolutely zero evidence of it, despite the fact that Windows has been widely audited, is the biggest target of attacks, and that its source code is available to tens of thousands of people.

as though you know EVERYTHING far more than most of the truely technical people on here, such as Budman.

I have no idea who Budman is or what I claim to know that he doesn't. Maybe I know more than him about something, maybe I don't. I don't see any posts by him so I am not sure what you are referring to.

Now, within your very same post you say this - "when someone makes a claim of this magnitude, the onus is on them to prove it" <-- That is a direct contradiction of your sentence only a few lines above.

Stop trying to twist this around. Please provide your evidence that Windows contains backdoors. I do not have to disprove this, you have to prove it.

However, if you are going to bang on at people about providing "proof" when ever you are challenged, then make sure you are going to or even do provide proof when you challenge someone...

If there is something specific you want me to document, then say so, otherwise you are simply trying to weasel out of having to provide evidence for your accusation. Even if you think I'm an idiot and a hypocrite, you can show that you're better than me by doing this.

Quite. Because its simple to boot to a root and change a password, when you dont already have the root password to begin with :rolleyes:

What are you trying to say here? That you can not boot to a root console if you don't have the root password? This is not true, its called single usermode - and can be booted into quite easy depending on the OS and if they support it or not.

It could be as simple halting your boot loader (lilo,grub,etc) and then entering this command

linux single

Just do a google for recover root password or single user mode, etc. Its quite easy to, as stated quite often without any tools.

Does not matter what OS -- if you have physical access to the machine, you can pretty much throw out any OS level username or passwords. Be it you can boot something like single user mode, or boot some tool to reset the password.. Or for that matter just boot some other OS and mount the file system and gain access to what files you want.

So unless your hardware has limitation to prevent boot from other sources, or your HDD is encrypted, etc.. If you have physical access to the computer you can pretty much throw out security all together.. Even if the machine will not boot - I could just pull the drive and access it.. Passwords set on the HDD can be bypassed.

example of hdd and bios recovery methods/services

http://www.pwcrack.com/harddisk.shtml

http://www.biospasswordrecovery.com/

http://www.notebookpasswords.com/

etc.. etc.. Now are all of these sites legit?? Not sure have never had need to test them.. But it seems unlikely that none of them work.. There was a thread a while back talking about HDD passwords set and that they could not be removed.. I don't recall the companies posted in that thread -- but just google you will find lots of them that can either just reset the password so you can use the disk, or quite often recover it so that you gain access to the data.

In a nutshell - if you they have physical access to the equipment.. And they want access to the data, its possible -- unless you actually encrypted the data with say bitlocker or truecrypt, etc. and they do not have access to the KEY.. Most users that use EFS don't follow best practice and leave the key on the machine -- if so then that too can be accessed and your data recovered, etc. But without the KEY your pretty much screwed!!

I don't even want to get into the backdoor nonsense -- IMHO its tinfoil hat conspiracy nutjob talk.. If there was such backdoors in bitlocker and truecrypt, etc.. Then that would be HUGE news and would be all over the net and on CNN, etc. Can you find discussions about it - sure they are all over.. Just like you can find info about how the moon landing was faked, and how we blew up the towers, etc.. And that JFK was hit by the CIA, etc..

The overall point being if they have physical access to your data, your data is not secure unless its "encrypted" with a secure method. As to the threads topic -- yeah it is child play to access a windows machine if you have physical access.. It sure is nothing new, and there have been password crackers available ever since there has been passwords ;) And there has been ways to circumvent security from the beginning..

my 2cents ;)

Edited by BudMan

Yes it is.

Stopped reading there.

What are you trying to say here? That you can not boot to a root console if you don't have the root password? This is not true, its called single usermode - and can be booted into quite easy depending on the OS and if they support it or not.

It could be as simple halting your boot loader (lilo,grub,etc) and then entering this command

linux single

Just do a google for recover root password or single user mode, etc. Its quite easy to, as stated quite often without any tools.

Does not matter what OS -- if you have physical access to the machine, you can pretty much throw out any OS level username or passwords. Be it you can boot something like single user mode, or boot some tool to reset the password.. Or for that matter just boot some other OS and mount the file system and gain access to what files you want.

So unless your hardware has limitation to prevent boot from other sources, or your HDD is encrypted, etc.. If you have physical access to the computer you can pretty much throw out security all together.. Even if the machine will not boot - I could just pull the drive and access it.. Passwords set on the HDD can be bypassed.

example of hdd and bios recovery methods/services

http://www.pwcrack.com/harddisk.shtml

http://www.biospasswordrecovery.com/

http://www.notebookpasswords.com/

etc.. etc.. Now are all of these sites legit?? Not sure have never had need to test them.. But it seems unlikely that none of them work.. There was a thread a while back talking about HDD passwords set and that they could not be removed.. I don't recall the companies posted in that thread -- but just google you will find lots of them that can either just reset the password so you can use the disk, or quite often recover it so that you gain access to the data.

In a nutshell - if you they have physical access to the equipment.. And they want access to the data, its possible -- unless you actually encrypted the data with say bitlocker or truecrypt, etc. and they do not have access to the KEY.. Most users that use EFS don't follow best practice and leave the key on the machine -- if so then that too can be accessed and your data recovered, etc. But without the KEY your pretty much screwed!!

I don't even want to get into the backdoor nonsense -- IMHO its tinfoil hat conspiracy nutjob talk.. If there was such backdoors in bitlocker and truecrypt, etc.. Then that would be HUGE news and would be all over the net and on CNN, etc. Can you find discussions about it - sure they are all over.. Just like you can find info about how the moon landing was faked, and how we blew up the towers, etc.. And that JFK was hit by the CIA, etc..

The overall point being if they have physical access to your data, your data is not secure unless its "encrypted" with a secure method. As to the threads topic -- yeah it is child play to access a windows machine if you have physical access.. It sure is nothing new, and there have been password crackers available ever since there has been passwords ;) And there has been ways to circumvent security from the beginning..

my 2cents ;)

A few, "if this" and so long as this happens etc, but once again, a good, point proven post Budman, unlike some members on Neowin :) (Y)

For all you who think encryption cannot be evaded, check this out:

1024-bit RSA encryption cracked by carefully starving CPU of electricity

University of Michigan claims they can break the encryption simply by tweaking a device's power supply. By fluctuating the voltage to the CPU such that it generated a single hardware error per clock cycle, they found that they could cause the computer to flip single bits of the private key at a time, allowing them to slowly piece together the password.

Source: http://www.engadget.com/2010/03/09/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-ele/

The encrypted drive needs to be logged in and active when this "hack" is applied though

Sure there are always a lot of if this or that scenarios when evaluating risks to your data. You need to evaluate the level of the risks, and the costs your willing to pay to mitigate those risk.. Cost being in actual hard $ or in software cost in extra steps required to access data, secure it when done with it, etc.. Be it having to plug in a usb dongle with a key on it, or put in an extra password to unlock a truecrypt volume, etc. etc.. There is always going to be costs involved with security.. Be it in performance of the machine when using an encrypted drive, or extra steps a user has to take to access the data, etc.. And don't forget the added risk your taking when you encrypt of actually locking yourself out of your own data.. There are lots of threads here of users not understanding EFS, not adhering to best practice on securing/backup up the keys - next thing you know they locked themselves out of their own data ;) When in most of these cases the user had no legit reasons to be using EFS in the first place.

You need to understand who/what your protecting your data from before you implement a security option. In many cases a good windows password and setting ntfs permissions correctly will be more than enough to secure your data from other users at your home or business, etc. Sure bypassing windows security is childs play to those that understand it and have local access - but to most users it might as well be 256bit AES encrypted data -- since they don't have a clue on how to bypass it ;)

Stopped reading there.

Why?

A few, "if this" and so long as this happens etc, but once again, a good, point proven post Budman, unlike some members on Neowin :) (Y)

That posts says I'm right and also implies that the people who believe there are backdoors are crazy and wrong. It's the complete opposite of what you're saying, so why would you thumbs up it? Am I to understand that you're retracting your false accusations?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Nothing kills CMF Phone 2 Pro's successor due to rising memory prices by Hamid Ganji Storage and RAM prices have been rising over the past year, leading to a significant increase in the cost of electronics for customers around the world. Many companies are now revising their plans for upcoming devices due to higher component costs and overall production expenses. CMF is the latest company to cancel the successor to one of its best-selling phones due to rising memory prices. CMF is a sub-brand of Nothing and focuses on making budget smartphones for growing markets. The brand launched the CMF Phone 2 Pro last year with some eye-catching specifications and an affordable price. While many customers may have been waiting for a successor this year, one of the company’s executives has announced that CMF will not release a new smartphone this year. And AI is to blame. As Nothing co-founder Akis Evangelidis announced on X, the company has been working on a successor to the CMF Phone 2 Pro, but with current memory prices, it cannot “build a phone that feels like a genuine step forward at a price that makes sense for CMF.” So, no new CMF phone will be launched this year. Meanwhile, Evangelidis said the company still has several new products in the pipeline, including some in entirely new categories. He added that the Nothing brand will also continue launching new products through 2026. Budget smartphones are among the first victims of the surge in RAM and memory prices, as they have become more expensive to build. The sharp increase in memory costs could also reshape the traditional price ranges associated with budget phones. Apple CEO Tim Cook also recently said that price increases for some of the company’s products are unavoidable because RAM and memory have become significantly more expensive this year. Analysts estimate that the base price of the upcoming iPhone 18 Pro could rise to $1,399 due to current market shortages.
    • Nudge me when they bring back hardware audio acceleration so I can get my EAX 5 back. We've evolved graphics to real-time path tracing, but regressed audio some 15 years back in time with this stupid software audio stack.
    • Ocenaudio 3.19.4 by Razvan Serea  Ocenaudio is a full featured, fast and easy to use audio and music editor. It is the ideal software for people who need to edit and analyze audio files without complications. Ocenaudio also has powerful features that will please more advanced users. To assist ocenaudio development, a powerful toolset of audio editing, analysis and manipulation called Ocen Framework was created. ocenaudio is also based on Qt framework, a well known library for cross-platform development. Cross-platform support ocenaudio is available for all major operating systems: Microsoft Windows, Mac OS X and Linux. Native applications are generated for each platform from a common source, in order to achieve excelent performance and seamless integration with the operating system. All versions of ocenaudio have a uniform set of features and the same graphical interface, so the skills you learn in one platform can be used in the others. VST plugins support Ocenaudio supports VST (Virtual Studio Technology) plugins, giving its users access to numerous effects. Like the native effects, VST effects can use real-time preview to aide configuration. Real-time preview of effects Applying effects such as EQ, gain and filtering is an important part of audio editing. However, it is very tricky to get the desired result by adjusting the controls configuration alone: you must listen the processed audio. To ease the configuration of audio effects, ocenaudio has a real time preview feature: you hear the processed signal while adjusting the controls. The effect configuration window also includes a miniature view of the selected audio signal. You can navigate on this miniature view in the same way as you do on the main interface, selecting parts that interest you and listening to the effect result in real time. Multiselection for delicate editions To speed up complex audio files editing, ocenaudio includes multi-selection. With this amazing tool, you can simultaneously select different portions of an audio file and listen, edit or even apply an effect to them. For example, if you want to normalize only the excerpts of an interview where the interviewee is talking, just select them and apply the effect. Eficient edition of large files With ocenaudio, there is no limit to the length or the quantity of the audio files you can edit. Using an advanced memory management system, the application keeps your files open without wasting any of your computer's memory. Even in files several hours long, common editing operations such as copy, cut or paste happen almost instantly. Fully featured spectrogram Besides offering an incredible waveform view of your audio files, ocenaudio has a powerful and complete spectrogram view. In this view, you can analyze the spectral content of your audio signal with maximum clarity. Advanced users will be surprised to find that the spectrogram settings are applied in real time. The display is updated immediately when altering features such as the number of frequency bands, window type and size and dynamic range of the display. Ocenaudio 3.19.4 changelog: Adds fallback fonts so every language and symbol displays correctly Improves autosave and session recovery stability Improves region navigation and display Fixes a crash when the level meter is used on displays with a scaling greater than 200% Fixes memory corruption when using the silence selection tools Fixes crashes when closing a file while effects are still being processed Fixes a freeze when applying effects to many files at once (macOS) Fixes crashes related to audio devices on Windows Fixes invalid file names when exporting regions whose label is used as the file name Other bug fixes and improvements Download: Ocenaudio 64-bit | Portable | ~40.0 MB (Freeware) Download: Ocenaudio for Linux and Mac OS View: Ocenaudio Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Hasleo Disk Clone 5.8.2.1 by Razvan Serea Hasleo Disk Clone is a free and all-in-one disk cloning software for Windows 11/10/8/7/Vista and Windows Server that can help you migrate Windows OS to another disk, clone one disk to another disk or clone one partition to another location quickly and efficiently. Completely Free Windows Migration and Disk/Partition Cloning Software Migrate Windows from one disk to another without reinstalling Windows, apps. Clone one disk to another and makes the data on 2 disks are exactly the same. Clone a partition to another location without losing any data. Easily adjust the size and location of the destination partition. Convert MBR to GPT or convert GPT to MBR by cloning. Creation of Windows PE emergency disk. Extremely fast cloning speed and multi-language support. Supported OS: Windows Vista/Server 2008 or later, fully compatible with GPT and UEFI. Hasleo Disk Clone 5.8.2.1 changelog: Fixed an issue that caused disk enumeration to fail Fixed an issue where WinPE created under Windows ARM64 26H1 did not work properly Download: Hasleo Disk Clone 5.8.2.1 | 32.3 MB (Freeware) Link: Hasleo Disk Clone Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • This got me thinking, would you rather a self driving car prioritise protecting its passengers or everyone else? I'd choose the one that keeps me and my kids safest. At some point, these cars have to make those choices already, don't they? Wonder if we have a way to find out what way they lean.
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      546
    2. 2
      +Edouard
      187
    3. 3
      Michael Scrip
      78
    4. 4
      PsYcHoKiLLa
      74
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!