Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 41 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Physical Security
Windows sever 2008 security expert needed URGENTLY. 911. Help please.
EH-Net
May 20, 2013, 10:43:27 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Physical Security
(Moderator:
don
) >
Windows sever 2008 security expert needed URGENTLY. 911. Help please.
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Windows sever 2008 security expert needed URGENTLY. 911. Help please. (Read 18660 times)
0 Members and 1 Guest are viewing this topic.
webman1
Newbie
Offline
Posts: 6
Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
on:
September 06, 2009, 02:22:40 PM »
I really hope I've come to the right place. I referred a client to ZT Systems to buy a server for tehir practice. It needed to be shipped and in the door by yesterday 9-5-09 so the It guy could set it up as an application sever that has to be completed by Tuesday, the day after labor day so the vendor for the 3rd party application can setup the server for their app. Thiis a 10k sever for 100 users so I'm assuming you know just how important this could be. Anyway, the sever arrived and when we finally opened last night the OS was installed with a admin account setup but no password has been supplied? I know there are plenty of ways to bypass the login screen and setup a new password in most cases but here is where THE GOOD IS SEPERATED FROM THE BEST in terms of security knowledge. The server is running Windows Server 2008 64 bit, Raid controllers Lsi, so most small apps that will allow you to bypass the login screen don't work when your using Raid controllers and 64 bit version.
Can anyone tell me if there's a way to bypass the 2008 login screen to get to our admin password with this type of hardware setup? It's going to end up a lawsuit if we don't find a way to resolve this. Just in case you're wondering. yes we have tried to contact them in every way possible but have had no luck. So now I am hoping someone has the knowledge to help. Please advise if you can.
Brad
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #1 on:
September 06, 2009, 02:52:33 PM »
Initial thoughts:
1. Plan better. Saturday delivery on a holiday weekend for a mission critical system due on the first day back from that holiday? Add in the fact that on ZT Systems site, it clearly states, "Call (888) 984-8899 Servers: Call 201-559-1064 Monday through Friday, 9-6PM EST." Also, don't let those doctors dictate what happens on an IT project.
2. If it's a new box and you can't even log on for the first time (and therefore no data is yet on it), then simply re-install the OS and set your own password.
3. Read
this thread
.
Hope this helps,
Don
PS - How did you find us?
Logged
CISSP, MCSE, CSTA, Security+ SME
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #2 on:
September 06, 2009, 02:54:13 PM »
Brad,
Don beat me to it with some better links, but my original post was going to be:
There are several ways to bypass authentication if you've got physical access to the box. Recently
KonBoot
is getting a lot of good press, and I've had plenty of success with it in practice.
Hope this helps.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Ketchup
Hero Member
Offline
Posts: 1021
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #3 on:
September 06, 2009, 03:29:17 PM »
Before you get too crazy, have you tried default passwords, like "password" or the name of the company that sold it to you? Typically though, Windows 2008 Server is installed so that the minisetup is forced. At the end of the minisetup, Windows 2008 Server forces to reset the password.
Logged
~~~~~~~~~~~~~~
Ketchup
webman1
Newbie
Offline
Posts: 6
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #4 on:
September 06, 2009, 03:59:02 PM »
Thank you all for your help. I understand the logistical issues but the events that were set in place and then handed off to me is something that everyone on this forum has experienced at least once in their career.lol. If you've never had a project where everything went wrong and was beyond explanation, after you've got many years of experience under your belt, you've been lucky. So I'll spare you the drama.
Thanks for the KonBoot link. We've tried a few apps like this but the server being 64 bit and Raid has made all our attempts fruitless. And yes we've tried just about every default or logistical password you can think of. The password convention really does a good job in complicating simple default guesses.
I'm going to pass on Kon-Boot to him and report back. Thanks a lot everyone.
Brad
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #5 on:
September 06, 2009, 04:14:53 PM »
Let us know how you get on with Kon-Boot. In my experience it works fine with hardware Raid controllers, but fails with software Raid implementations. I'd be interested to know if this is true beyond the limited amount of hardware I have been able to test.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
webman1
Newbie
Offline
Posts: 6
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #6 on:
September 06, 2009, 04:35:59 PM »
Sounds good and I will. Here's what we had them build. So that's what it will be tested against.
INTEL Quad Core Server
XEON E5440(QuadCore) 2.83G 12M 1333 BX80574E5440P
SM X7DVL-E 5000V 24GFB-D 6xSATA V/R5/2GbL RTL MBD-X7DVL-E-O
12GB 667MHZ ECC REG
Seagate 146GB SAS 15K ST3146356SS
Seagate 600GB 15K 3.5" 6G/SAS ST3600057SS
SuperMicro 650W X7/PD 8SAS/SATA BLK 4U/TOWER
SuperMicro 4 U RACK MOUNT KITS
SONY 20X DVD+/-RW
LSI 3GB 4PORT SAS/SATA ROC RAID SAS
LSI Logic LSIiBBU06 RAID Controller Battery
Microsoft Windows Server 2008 Standard with 100 user licence
3 YEAR PARTS AND LABOR WARRANTY
I'll let you know how it goes ro see how it measures up.
Brad
Logged
webman1
Newbie
Offline
Posts: 6
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #7 on:
September 06, 2009, 05:15:04 PM »
The It guy that has the server at home said that Kon-boot sais it's for 32 bit only but he's going to give it a try anyway and hope somehow it works on a 64 bit server. Just in case it doesn't work does anyone know of any other solutions?
Thanks,
Brad
Logged
webman1
Newbie
Offline
Posts: 6
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #8 on:
September 06, 2009, 05:43:53 PM »
Well....Back to square 1. Kon-Boot didn't work, it just hung up on boot. The issue is that it's 64 bit. Thanks though. If anyone else has any other idea I'm open.
Thanks,
Brad
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #9 on:
September 06, 2009, 06:07:46 PM »
Brad,
According to this:
http://home.eunet.no/pnordahl/ntpasswd/walkthrough.html
Peter Nordahl's password reset disc works with Vista x64. Server 2008 is fairly similar. I think that it's worth a try.
If that doesn't work, maybe you will have some luck with the Firewire DMA hack. I have had quite a few issues with this hack on Vista, but I have gotten one or two machines to work.
http://blog.security4all.be/2008/03/unlock-windows-pc-without-password.html
«
Last Edit: September 06, 2009, 06:12:41 PM by Ketchup
»
Logged
~~~~~~~~~~~~~~
Ketchup
chrisj
Hero Member
Offline
Posts: 1163
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #10 on:
September 06, 2009, 07:50:05 PM »
Two things we've done in the past at work (xp and S2003), was use Trinity Rescue Kit (trk), and Knoppix 5.1. TRK might be easier, I've had it work on 64 bit and 32 bit systems.
TRK's user guide says how to use it to reset admin password. There are guides out there (google is good) on how to use a Linux Live CD to reset a window admin password.
Logged
OSWP, Sec+
webman1
Newbie
Offline
Posts: 6
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #11 on:
September 06, 2009, 09:00:20 PM »
Ketchup is the man. Your last tip worked perfect. We were literally thirty minutes from having to wipe the server, reinstall the OS, Find and install all the drivers (yeah we didn't get those either yet,) and then do all the customizations that we paid them to do already. Next would have been a pretty bad phone conference. So you really helped us.
In the future if you get your server with the admin account setup and the password isn't available on a holiday weekend, and you're on a intense dealine, use Ketchup's advice:
"Brad,
According to this:
http://home.eunet.no/pnordahl/ntpasswd/walkthrough.html
Peter Nordahl's password reset disc works with Vista x64. Server 2008 is fairly similar. I think that it's worth a try."
That's when you're running Windows server 2008, and a 64 bit system. Thanks again man.
Brad
T
«
Last Edit: September 06, 2009, 09:02:21 PM by webman1
»
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #12 on:
September 06, 2009, 09:57:04 PM »
Brad, I am glad it worked. I hate reinstalling OS on servers. It's a complete pain finding all the drivers and retuning all the settings.
Logged
~~~~~~~~~~~~~~
Ketchup
jimbob
Guest
Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please.
«
Reply #13 on:
September 07, 2009, 01:09:46 AM »
Now might be a good time to check for any additional user accounts or 'value addes' software installed by the vendor.
Jimbob
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.