Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 LOCK SMITH SOFTWARE, break the administration code..

views
     
TSsamuraislash
post Apr 29 2006, 07:11 PM, updated 20y ago

Getting Started
**
Junior Member
277 posts

Joined: Nov 2005
From: shah alam - cyberjaya



need help.. is there any other software that i can use to block the lock smith... seem it look like a very powerful tool to change the administrator password..
asellus
post Apr 29 2006, 07:58 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(samuraislash @ Apr 29 2006, 07:11 PM)
need help.. is there any other software that i can use to block the lock smith... seem it look like a very powerful tool to change the administrator password..
*
Is that software the same as the one at http://home.eunet.no/~pnordahl/ntpasswd/ ?

If yes, then remove all your floppy disk drives and also your optical disc drives. And also disable your USB ports too.

What kind of machine do you have anyway?
WaCKy-Angel
post Apr 29 2006, 08:02 PM

PeACe~~
*********
All Stars
21,961 posts

Joined: Dec 2004
From: KL



If u can block it...ppl can hack it...

Change password everyday?
Use steel box to lock the CPU?
strace
post Apr 29 2006, 08:22 PM

Ayy
*****
Senior Member
700 posts

Joined: Aug 2005
QUOTE(asellus @ Apr 29 2006, 07:58 PM)
Is that software the same as the one at http://home.eunet.no/~pnordahl/ntpasswd/ ?

If yes, then remove all your floppy disk drives and also your optical disc drives. And also disable your USB ports too.

What kind of machine do you have anyway?
*
and stop people from uploading the files to the internet?
silllver
post Apr 29 2006, 08:30 PM

Regular
******
Senior Member
1,298 posts

Joined: Jan 2003
-----==deleted-----

This post has been edited by silllver: Apr 29 2006, 10:50 PM
asellus
post Apr 29 2006, 08:35 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(strace @ Apr 29 2006, 08:22 PM)
and stop people from uploading the files to the internet?
*
If that locksmith software is the same as the one in the URL, physical security is important.
TSsamuraislash
post Apr 29 2006, 09:39 PM

Getting Started
**
Junior Member
277 posts

Joined: Nov 2005
From: shah alam - cyberjaya



QUOTE(asellus @ Apr 29 2006, 09:35 PM)
If that locksmith software is the same as the one in the URL, physical security is important.
*
so that mean i need to lock all the HP computer in my office..? darn in here got about 100 ++ PC man... how bout usb drive..? can it be used to crack the admin password for those who is clever enought to mess with admin password...
trix
post Apr 29 2006, 10:28 PM

Enthusiast
*****
Senior Member
848 posts

Joined: Feb 2005
From: everywhere, yet nowhere.



set the bios to only boot from hd
if they desperate enough open up the casing to reset cmos, if kantoi you can accuse them with trying to steal company's stuff.

edit: and password the bios also

This post has been edited by trix: Apr 29 2006, 10:38 PM
asellus
post Apr 29 2006, 10:39 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(samuraislash @ Apr 29 2006, 09:39 PM)
so that mean i need to lock all the HP computer in my office..? darn in here got about 100 ++ PC man... how bout usb drive..? can it be used to crack the admin password for those who is clever enought to mess with admin password...
*
If your computer can boot from USB drives, then yes that ntpasswd can be used to reset admin account.

You can reduce the risk by making sure:-

1. People can't access BIOS so that they can't boot from floppy, CD-ROM or USB ports.
2. Make sure that each and every single computer in the network to have their Adminsitrator account to have unique passwords. And change them regularly. Like everyday for example. With random passwords.
3. Make it hard for people to install software like Norton Ghost or Acronis TruImage so that they can't make an image of a workstation to their USB HDD drives that can be taken to their home so that they can crack the admin password.
4. Make it hard for people to open the case of the workstation without authorization. Suggest to your manager/superior that harsh actions be done to people who does.
5. Make sure that things like scheduled tasks, services and other doesn't use domain administrator accounts. If needed to be, use local administrator priviledge first.
6. Go scream at Microsoft for leaving a hole that big. And upgrade to Vista ASAP, hoping that Microsoft doesn't screw up again. Or maybe Linux.
TSsamuraislash
post Apr 29 2006, 10:40 PM

Getting Started
**
Junior Member
277 posts

Joined: Nov 2005
From: shah alam - cyberjaya



QUOTE(trix @ Apr 29 2006, 11:28 PM)
set the bios to only boot from hd
if they desperate enough open up the casing to reset cmos, if kantoi you can accuse them with trying to steal company's stuff.

edit: and password the bios also
*
but they still can press F9 to change the boot option.

WaCKy-Angel
post Apr 29 2006, 10:41 PM

PeACe~~
*********
All Stars
21,961 posts

Joined: Dec 2004
From: KL



QUOTE(samuraislash @ Apr 29 2006, 09:39 PM)
so that mean i need to lock all the HP computer in my office..? darn in here got about 100 ++ PC man... how bout usb drive..? can it be used to crack the admin password for those who is clever enought to mess with admin password...
*
What kind of company are u in?
Why are u so worried about admin password?
Futhermore for 100 pc?
What information so high security?

FYI....i cracked all my ex company's pc...and my current company's pc...ehehe
strace
post Apr 29 2006, 11:03 PM

Ayy
*****
Senior Member
700 posts

Joined: Aug 2005
Run Keberos authentication server then secure your LAN from network sniffers.
TSsamuraislash
post Apr 30 2006, 02:20 AM

Getting Started
**
Junior Member
277 posts

Joined: Nov 2005
From: shah alam - cyberjaya



QUOTE(WaCKy-Angel @ Apr 29 2006, 11:41 PM)
What kind of company are u in?
Why are u so worried about admin password?
Futhermore for 100 pc?
What information so high security?

FYI....i cracked all my ex company's pc...and my current company's pc...ehehe
*
i'm working in the private sector.. doing R&D which all the data is very valuable.. just worried about IP.
trix
post Apr 30 2006, 10:36 PM

Enthusiast
*****
Senior Member
848 posts

Joined: Feb 2005
From: everywhere, yet nowhere.



how about creating a logon script that dumps the nt hash for admin's password and then compare it against the original hash.
auto logoff if it's different.

 

Change to:
| Lo-Fi Version
0.0148sec    0.22    5 queries    GZIP Disabled
Time is now: 27th November 2025 - 12:58 AM