Home >> Articles >> Article
  Login | Signup  

Articles from the members

Category
  General Knowledge   Career Counselling   Technology
  Power of Creator   Religious   Moral Story
  Medical   Kids   Sports
  Quran & Science   Politics   Poetry
  Funny / Jokes   Video   Golden Old Days - ம‌ல‌ரும் நினைவுக‌ள்
  Others   சுய தொழில்கள்
 
Hack into a Windows PC - no password needed
Posted By:Hajas On 3/5/2008

 

Hack into a Windows PC - no password needed

Asher Moses
March 4, 2008 - 1:28PM

Adam Boileau

Adam Boileau

Security consultant based in New Zealand has released a tool that can unlock Windows computers in seconds without the need for a password.

Adam Boileau first demonstrated the hack, which affects Windows XP computers but has not yet been tested with Windows Vista, at a security conference in Sydney in 2006, but Microsoft has yet to develop a fix.

Interviewed in ITRadio's Risky Business podcast, Boileau said the tool, released to the public today, could "unlock locked Windows machines or login without a password ... merely by plugging in your Firewire cable and running a command".

Boileau, a consultant with Immunity Inc., said he did not release the tool publicly in 2006 because "Microsoft was a little cagey about exactly whether Firewire memory access was a real security issue or not and we didn't want to cause any real trouble".

But now that a couple of years have passed and the issue has not resolved, Boileau decided to release the tool on his website.

To use the tool, hackers must connect a Linux-based computer to a Firewire port on the target machine. The machine is then tricked into allowing the attacking computer to have read and write access to its memory.

With full access to the memory, the tool can then modify Windows' password protection code, which is stored there, and render it ineffective.

Older desktop computers do not come equipped with Firewire ports, which are needed for the hack to work, but many recent models do. Most laptops made in the last few years include Firewire ports.

Paul Ducklin, head of technology for security firm Sophos, said the security hole found by Boileau was not a vulnerability or bug in the traditional sense, because the ability to use the Firewire port to access a computer's memory was actually a feature of Firewire.

"If you have a Firewire port, disable it when you aren't using it," Ducklin said.

"That way, if someone does plug into your port unexpectedly, your side of the Firewire link is dead, so they can't interact with your PC, legitimately or otherwise."

Ducklin also advised people to be careful when giving others physical access to their computer.

"I know people who'd think three times about asking passing strangers to take their photo in front of the Opera House in case they did a runner with the camera, yet who are much more casual with their laptop PC, as long as it's software-locked, even though the hardware alone is worth five times as much as the camera," he said.

Microsoft was unavailable for comment at the time of publication.

This story was found at: http://www.smh.com.au/articles/2008/03/04/1204402423638.html




Technology
Date Title Posted By
7/15/2017 12:21:13 PMஹைப்பர் லூப் என்றால் என்னHajas
6/10/2014 3:57:55 AMமழைநீர் சேகரிப்புHajas
9/10/2013 9:39:19 AMலேப்டாப் வாங்கும்போது கவனிக்க வேண்டியவை ...ganik70
1/14/2013Chennai Bus/Bus Route : சென்னையின் பஸ்ரூட் எளிதில் அறிந்துகொள்ளganik70
1/14/2013Train - டிரைன் செல்லும் பாதையை உடனுக்குடன்அறிந்துகொள்ளganik70
10/2/201210 Hot IT skills for 2013ganik70
5/3/20121 ரூபாயில் இந்தியாவிற்கு பேச – GOOGLE VOICEganik70
1/9/2010குழந்தைகளுக்கான இணைய தளங்கள்!ganik70
8/22/2009உங்கள் எல்லா மின்னஞ்சல் பயன்பாட்டையும் ஜீமைலுக்கு மாற்ற சுலபமான வழிganik70
8/5/2009செல்போனில் இ-மெயில் தகவலைப்பெற...ganik70
6/11/2009அறிமுகமாகிவிட்டது Google Squared - புதிய தேடுபொறிjasmin
5/25/2009Yahoo 'Web Beacons' Spy On And Track Yahoo Usersjasmin
5/14/2009'Smiley' face symbol 'privatised'jasmin
3/31/2009Wi-Fi தொழில்நுட்பம் ஏற்படுத்தியுள்ள அச்சுறுத்தல்கள்!Hajas
3/26/2009செல்போன் கணிதம்ganik70
3/25/2009Internet Browsing - without ComputersHajas
3/19/2009இணைய அரட்டை அடிக்க Digsby - (பலவும் ஒன்றில்)ganik70
3/16/2009ரிலையன்ஸ் Net Connect Broadband +ganik70
3/10/2009தகவல் தொழில்நுட்பத்துறையில் புதியபுரட்சி செய்யப்போகும் "3G" செல்போன் சேவை... !!!ganik70
3/8/2009பழுதடைந்த CD / DVD களை இயக்க, DVD படத்தை வெட்டியெடுக்கganik70
11/15/2008What Chandrayaan-1 aims to accomplishHajas
8/19/200812 early warning signs of IT failureHajas
6/15/2008Tamil Web Keyboardjasmin
4/2/2008Intel rolls out Atom chips at Shanghai tech forumHajas
4/1/2008What's keeping us from Mars? Space rays, say expertsHajas
11/13/2007India hosts world's fourth fastest supercomputerHajas
10/24/2007Microsoft windows invades carsHajas
9/22/2007'Science mystified by the universe'Hajas
8/8/2007The car that won't start if you're drunkHajas
8/5/2007The time to refresh your memory is not far away!Hajas
2/10/2007How to Avoid Hoax Messages?jasmin
1/31/2007Three Back-to-Back Spacewalks Coming Up on StationHajas
12/18/2006Protect your password in cyber cafe and on public computers:Hajas
12/6/2006Spam Doubles, Finding New Ways to Deliver ItselfHajas
12/6/2006General Guidelines for Internet Usersjasmin
6/27/2006Trim Your Windows Startuppeer
6/27/2006Clean Up What a Messy Uninstall Leaves Behindpeer
6/27/2006300GB storage disc (HVD)peer
6/26/2006Killer Photo Accessoriespeer
6/19/2006Hardware Tips: Free Tools Help Keep Your Hardware Hummingpeer
6/19/2006Internet Tips: Bolster Your Defenses Against Net Threatspeer
5/21/2006How Revolvers WorkMohamedris
4/24/2006How Google Grows...and Grows...and Growspeer
9/12/2005Mobile Phones Tips and tricks.Mohamedris
9/10/2005Useful Shortcut:jasmin
8/6/2005COMPUTER TIPSjasmin
8/6/2005How Computer Viruses work?jasmin
8/2/2005How To Build Better Passwordsjasmin
8/2/2005What are viruses, worms, and Trojans?jasmin
8/2/2005Scanning of Imagesjasmin
6/26/2005Useful Shortcuts for Windowsjasmin
5/21/2005Now, a browser that can talk to youjasmin
5/2/2005How Cell Phones WorkMohamedris
6/26/2004Tipu Sultan's contribution to Rocket Technologypeer
4/4/2004தமிழினக் காவலர் பில் கேட்ஸ் - Sujathapeer
4/4/2004யுனிகோடும் தமிழ் இணையமும் - உமர்peer
The view points and opinion solely those of the author or source. nellaiEruvadi.com is not responsible for the posted contents..