Home > Ask the Security Experts > Expert Archive: Information Security Threats Questions & Answers > What tools can a hacker use to crack a laptop password?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What tools can a hacker use to crack a laptop password?

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 15 May 2008
What are some of the tools a hacker can use to crack the password on a laptop? Or is it simply trial and error?

>
EXPERT RESPONSE
If the laptop password described is merely the operating system password, an attacker with physical access to the machine could simply boot it from a Linux CD, mount the NTFS partition on the hard drive if it is a Windows machine, and change the administrator password to some value the attacker knows (possibly even blank). Peter Nordahl released a CD ISO image that performs this attack quite well against Windows NT/2000/2003/XP/Vista. Users can download Peter Nordahl's tool for free. Once the attacker has changed the admin password, he or she can then boot the system to Windows and log on with admin credentials. If the sensitive user files are in clear text, the attacker can seize them.

Even if they are encrypted on the machine using Windows Encrypted File System (EFS), the attacker can still log on to the machine with administrator access. As long as the EFS-protected files are encrypted by a user other than the default administrator, the attacker can use admin privileges to dump the machine's local SAM database. He could then crack the user's password for the account that encrypted the file, relying on a free password cracking tool such as Cain or John the Ripper, and use this password to gain access to the files, with EFS transparently un-encrypting the files for the user.

Yet there are stronger methods available beyond EFS, like whole-disk encryption technologies that encrypt everything, including the operating system booted via a special secure boot loader. Attackers are not above using simple trial and error, which is a possibility that should not be discounted. For instance, a malicious hacker could create a hardware device that interfaces with the USB port of a stolen laptop, trying thousands of passwords per hour, possibly eventually guessing one successfully.

But, in February 2008, another useful attack vector called a "cold-boot" was discussed widely. It was based on some fascinating research from Ed Felton's team at Princeton University. In this so-called cold-boot attack, the bad guy takes a hibernating machine and disconnects power. As we all know, RAM is volatile, but it's not volatile enough so that secrets (including passwords and crypto keys) stored in memory vanish instantly; in fact, they remain for several minutes and potentially longer if the memory is cooled. After removing power, the attacker can boot the system to an external device, such as a CD or USB token, and dump RAM, storing the results on the USB drive or sending it across the network. The attacker can then scour the memory image looking for the data structures that store the secret needed to decrypt the laptop. With this secret, the attacker can either copy the entire encrypted partitions or reboot the machine and have the built-in software decrypt it. There's even free software appearing now that helps automate part of this attack, particularly the boot process and dumping of memory.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Password Cracking
ID and password authentication: Keeping data safe with management and policies
IBM USB banking device stops keyloggers, malware
Bluetooth 2.1 is easy to crack
Screencast: An introduction to the Open Source Security Testing Methodology Manual (OSSTMM)
Ophcrack: Password cracking made easy
Is encryption only as good as an organization's password management and access control policies?
What are the risks associated with RIM's line of PDAs?
Security360: Identity management market
How to prevent hackers from accessing your router security password
Complex password compliance requirements made simple

Password Management
ID and password authentication: Keeping data safe with management and policies
New Sun product illustrates identity management trend
Sun launches open source OpenSSO for identity management
Shared Identity Providers Could Soothe Password Chaos
How does the Group Policy Object interact with the 'Password Never Expires' flag?
What are the benefits of identity managed as a service?
What are best practices for remote management of medical imaging devices?
What kinds of new 'picture password' technologies are available for mobile devices?
Trends in enterprise identity and access management
Is it illegal for anyone in an enterprise to ask an employee for his or her password?

Expert Archive: Information Security Threats
Are there antivirus suites that pick up more than just run-of-the-mill viruses?
Are social networking sites an easy target for malicious hackers?
What are the dangers of cross-site request forgery attacks (CSRF)?
Should social engineering tests be included in penetration testing?
Best practices for using restriction policy whitelists
What kind of data is compromised during a Google hack?
Defining mobile device security concerns
What are the risks associated with RIM's line of PDAs?
What security measures can be taken to stop crimeware kits?
What software development best practices can prevent input validation attacks?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cracker  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
salt  (SearchSecurity.com)
session replay  (SearchSecurity.com)
shadow password file  (SearchSecurity.com)
war dialer  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts