Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 49 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Kon-Boot boot Disc Bypass Password.
EH-Net
May 18, 2013, 04:10:52 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Kon-Boot boot Disc Bypass Password.  (Read 53646 times)
0 Members and 1 Guest are viewing this topic.
hackly66
Jr. Member
**
Offline Offline

Posts: 62



View Profile
« on: May 12, 2009, 07:07:14 PM »

Hi everyone-

Last night while learning Snort I headed towards Ask Raymond site, and came across this cool tool called Kon-Boot it’s a live linux boot disc. What this can do is bypass the domain or local administrators account. I tested this on one of my end users with special permission through my co-partner, this boot CD got me through the  account with no interruption no password required. I realized while on line, it locked out the account, but when offline I did not have any issues. Now just to make sure my account being the Local Domain Admin I went ahead and tested myself a few times, and thank God can’t access my account,only as a local administrator it’s possible. This is very scary because it forces you to set a bios password, and encrypt your hard drive. So far I have not tested on Vista or Windows 7, but I’m sure someone out there can give us some feedback, try it on a 64bit OS maybe it might work. Once you reboot back to your system without the Cd everything should be back to normal.

Link to Kon-Boot---- http://www.piotrbania.com/all/kon-boot/


Ask Raymond Site-http://www.raymond.cc/blog/archives/2009/04/29/login-to-windows-administrator-and-linux-root-account-without-knowing-or-changing-current-password/

PS -Please do things ethical this teaches us to warn others about exploits like this one. Wink
 
Logged

A+,Net+,Sec+
Ignatius
Jr. Member
**
Offline Offline

Posts: 91


View Profile
« Reply #1 on: May 13, 2009, 08:43:16 AM »

I've seen threads about this software elsewhere and the posters didn't manage to get anywhere with it.  They were suspicious that it was some kind of hoax (hence the "Kon" in the title) and someone even suspected that it installed a rootkit.

I've not played around with it myself, nor will I until I've seen reputable folks on the fora where it's been discussed have tested it thoroughly and given it the thumbs up.
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #2 on: May 13, 2009, 02:43:33 PM »

I haven't played with this one, but there are many other bootable CDs out there that can get you into a machine without knowing the password. I've used this one in the past and like it:

Offline NT Password & Registry Editor
http://home.eunet.no/pnordahl/ntpasswd/

There is also ERD Commander that was made by Winternals. It has since been bought by Microsoft and is only released to those with Software Assurance contracts. But it has been kept up to date with bootable CDs for both XP and Vista.

There are plenty of others like the Ophcrack CDs, etc. etc. So I don't think this fits into the category of being an exploitable vuln, but it is always something to remember.

This is why sec pros always recommed the extra measures you mention below like power on passwords, full volume encryption, etc. Physical access is always the worst case scenario. OK... maybe not always, but you get what I'm saying.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #3 on: May 13, 2009, 07:58:31 PM »

I have been using Peter Nordahl's disk for the past 8 years or so with about 95% success rate. 

http://home.eunet.no/pnordahl/ntpasswd/

Also firewire DMA hack works pretty well to bypass authentication without having to reboot the machine.  The tool is winlockpwn and is included on the Helix cd.
Logged

~~~~~~~~~~~~~~
Ketchup
hackly66
Jr. Member
**
Offline Offline

Posts: 62



View Profile
« Reply #4 on: May 13, 2009, 08:55:21 PM »

Yes correct guys I'm in with you with the other Boot Disk, but what makes this one a bit differnet is that it keeps the orignal password intact it does not modify your password I ran Sophos free Anti-Rootkit scanner,and did not find any rootkits installed.I would try it on a non productive computer just for you to see how easy this exploit can be. Cool
Logged

A+,Net+,Sec+
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #5 on: June 19, 2009, 07:00:51 AM »

I heard about this the other month on Risky.biz, and finally got around to testing it, doing a small blog, and posting a vid of it working on a Vista box.

Feel free to have a look. http://blog.securityactive.co.uk/2009/06/19/kon-boot-modify-the-kernal-and-walk-right-in-the-front-door/
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.095 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.