EH-Net
May 21, 2013, 10:28:55 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Bypassing Safeboot Security System 4.2  (Read 27202 times)
0 Members and 1 Guest are viewing this topic.
lsullivan64
Newbie
*
Offline Offline

Posts: 6


View Profile
« on: November 20, 2009, 04:54:34 PM »

Hi,

I have been brought in by a company that has let go about 22 employees.  Each had a lap top which is protected by Safeboot Security System 4.2.  I have the log in for the Safeboot, but not the log in for the user on the computers.  I need to crack the passwords for the user accounts on the computers, actually I can erase it.  Has anone ever dealt with this?

Thanks
Logged
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #1 on: November 28, 2009, 11:42:50 PM »

I need to crack the passwords for the user accounts on the computers, actually I can erase it.

What are you looking to do? That sentence doesn't make sense to me?
Logged

twitter.com/timmedin | http://blog.securitywhole.com
lsullivan64
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #2 on: December 02, 2009, 09:37:36 AM »

I have the  computers.  I have the user and Password for Safeboot.  I don't have the windows User and password.  I can either break the password or I can erase it. 

I need to get past safeboot.  When i boot the computer I put in the safeboot user/pass and get to the windows log in.  Is there a way i can run a tool to remove the password?

Any ideas would be apreciated.
Logged
unsupported
Sr. Member
****
Offline Offline

Posts: 318


Unofficial Newbie Moderator


View Profile
« Reply #3 on: December 02, 2009, 01:09:15 PM »

IMHO, this does not sound kosher.  If you have the password for Safeboot, the company should also be able to provide you with the local administrator user name and password.

What is your end goal with the systems beyond getting user names and passwords?
Logged

-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #4 on: December 02, 2009, 02:38:21 PM »

if you have a domain controller, you can change the passwords on the DC and when the boxes connect to the network, you should be able to get into the systems after.
Logged

OSWP, Sec+
lsullivan64
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #5 on: December 02, 2009, 03:28:43 PM »

Hi,
I don't have the domain controler.  Because of some "Not Kosher" activities by people in the IT department I have been brought in. I have nothing to do with the company other than the "Higher Ups" hired me. 

The end goal is the company wants to look at the computers to try to see who was involved in the activites that were bad.  If you want more inf I can let you know.  Put at hotmail dot com after my user name and I can provide.
Thanks
Logged
3PIL0GU3
Newbie
*
Offline Offline

Posts: 38


View Profile
« Reply #6 on: December 02, 2009, 05:34:34 PM »

If your tring to find bad activities wouldi it be more worthwhile taking an incident response/forensics approach to this problem
Logged

----------------------------
CEH
lsullivan64
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #7 on: December 02, 2009, 06:16:45 PM »

The bad activity is already known. It is more trying to find out who is actually involved. There will be no legal action.   
Logged
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #8 on: December 03, 2009, 09:22:33 PM »

Try Kon-Boot
Logged

twitter.com/timmedin | http://blog.securitywhole.com
lsullivan64
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #9 on: December 04, 2009, 07:02:52 AM »

I looked at kon Boot.  Not sure it could help.  The trick is having to boot up and log into Safeboot then get past the windows password.  I don't see hoe kon boot can let me do that.
Logged
unsupported
Sr. Member
****
Offline Offline

Posts: 318


Unofficial Newbie Moderator


View Profile
« Reply #10 on: December 04, 2009, 08:20:52 AM »

Couldn't you do the quick and dirty method of running a repair and wiping out the SAM database?  Is that even possible with newer MS OS?

Just a thought.  But I still think this is a little fishy. Smiley
Logged

-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
lsullivan64
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #11 on: December 04, 2009, 08:29:53 AM »

My understanding is that if you wipe any passwords without dealing with the disc encryption you will only have a brick left. 
Logged
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #12 on: December 04, 2009, 03:12:55 PM »

I don't know if Kon-Boot would work but it might. I would suggest trying it. All it does is load its code then calls the normal boot loader.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
mulberry
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #13 on: December 06, 2009, 04:01:16 AM »


I'm pretty sure FTK 3 claims to deal with safeboot ( presumably when psswd is supplied ) but then again FTK 2 was going to break eggs with a big stick !

But I don't really get why the win admin login is a barrier IMHO I think you maybe want to re consider the methodology ? Even maybe a logical image ?

Mulberry
Logged
mulberry
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #14 on: December 09, 2009, 04:10:12 AM »

Sorry - I take back my last paragraph - I do now get it. Wink
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.078 seconds with 19 queries.