Showing posts with label crack admin password. Show all posts
Showing posts with label crack admin password. Show all posts

Sunday, September 5, 2010

A Strong Password Isn't The Strongest Security

Make your password strong, with a unique jumble of letters, numbers and punctuation marks. But memorize it, never write it down. And, oh yes, change it every few months. These instructions are supposed to protect us. But they don’t!

Some computer security experts are advancing the heretical thought that passwords might not need to be “strong,” or changed constantly. They say onerous requirements for passwords have given us a false sense of protection against potential attacks. In fact, they say, we aren’t paying enough attention to more potent threats.


Here’s one threat to keep you awake at night: Keylogging software, which is deposited on a PC by a virus, records all keystrokes — including the strongest passwords you can concoct — and then sends it surreptitiously to a remote location.

“Keeping a keylogger off your machine is about a trillion times more important than the strength of any one of your passwords,” says Cormac Herley, a principal researcher at Microsoft Research who specializes in security-related topics. He said antivirus software could detect and block many kinds of keyloggers, but “there’s no guarantee that it gets everything.”

After investigating password requirements in a variety of settings, Mr. Herley is critical not of users but of system administrators who aren’t paying enough attention to the inconvenience of making people comply with arcane rules. “It is not users who need to be better educated on the risks of various attacks, but the security community,” he said at a meeting of security professionals, the New Security Paradigms Workshop, at Queen’s College in Oxford, England. “Security advice simply offers a bad cost-benefit tradeoff to users.”

One might guess that heavily trafficked Web sites — especially those that provide access to users’ financial information — would have requirements for strong passwords. But it turns out that password policies of many such sites are among the most relaxed. These sites don’t publicly discuss security breaches, but Mr. Herley said it “isn’t plausible” that these sites would use such policies if their users weren’t adequately protected from attacks by those who do not know the password.

Mr. Herley, working with Dinei FlorĂȘncio, also at Microsoft Research, looked at the password policies of 75 Web sites. At the Symposium on Usable Privacy and Security, held in July in Redmond, Wash., they reported that the sites that allowed relatively weak passwords were busy commercial destinations, including PayPal, Amazon.com and Fidelity Investments. The sites that insisted on very complex passwords were mostly government and university sites. What accounts for the difference? They suggest that “when the voices that advocate for usability are absent or weak, security measures become needlessly restrictive.”

Donald A. Norman, a co-founder of the Nielsen Norman Group, a design consulting firm in Fremont, Calif., makes a similar case. In “When Security Gets in the Way,” an essay published last year, he noted the password rules of Northwestern University, where he then taught. It was a daunting list of 15 requirements. He said unreasonable rules can end up rendering a system less secure: users end up writing down passwords and storing them in places that can be readily discovered.

“These requirements keep out the good guys without deterring the bad guys,” he said.

Northwestern has reduced its password requirements to eight, but they still constitute a challenging maze. For example, the password can’t have more than four sequential characters from the previous seven passwords, and a new password is required every 120 days.

By contrast, Amazon has only one requirement: that the password be at least six characters. That’s it. And hold on to it as long as you like.

A short password wouldn’t work well if an attacker could try every possible combination in quick succession. But as Mr. Herley and Mr. FlorĂȘncio note, commercial sites can block “brute-force attacks” by locking an account after a given number of failed log-in attempts. “If an account is locked for 24 hours after three unsuccessful attempts,” they write, “a six-digit PIN can withstand 100 years of sustained attack.”

Roger A. Safian, a senior data security analyst at Northwestern, says that unlike Amazon, the university is unfortunately vulnerable to brute-force attacks in that it doesn’t lock out accounts after failed log-ins. The reason, he says, is that anyone could use a lockout policy to try logging in to a victim’s account, “knowing that you won’t succeed, but also knowing that the victim won’t be able to use the account, either.” (Such thoughts may occur to a student facing an unwelcome exam, who could block a professor from preparations.)

Very short passwords, taken directly from the dictionary, would be permitted in a password system that Mr. Herley and Stuart Schechter at Microsoft Research developed with Michael Mitzenmacher at Harvard.

At the Usenix Workshop on Hot Topics in Security conference, held last month in Washington, the three suggested that Web sites with tens or hundreds of millions of users, could let users choose any password they liked — as long as only a tiny percentage selected the same one. That would render a list of most often used passwords useless: by limiting a single password to, say, 100 users among 10 million, the odds of an attacker getting lucky on one attempt per account are astronomically long, Mr. Herley explained in a conversation last month.

Mr. Herley said the proposed system hadn’t been tested and that users might become frustrated in trying to select a password that was no longer available. But he said he believed an anything-is-permitted password system would be welcomed by users sick of being told, “Eat your broccoli; a strong password is good for security.”

Tuesday, June 15, 2010

Security experts release tool to hack Android phones!

Two security experts said on Friday they released a tool for attacking smartphones that use Google Inc's Android operating system to persuade manufacturers to fix a bug that lets hackers read a victim's email and text messages.

"It wasn't difficult to build," said Nicholas Percoco, head of Spider Labs, who along with a colleague, released the tool at the Defcon hacker's conference in Las Vegas on Friday.

Percoco said it took about two weeks to build the malicious software that could allow criminals to steal precious information from Android smartphones.

"There are people who are much more motivated to do these things than we are," he added.

The tool is a so-called root kit that, once installed, allows its developer to gain total control of Android devices, which are being activated by consumers at a rate of about 160,000 units per day, according to Google.

"We could be doing what we want to do and there is no clue that we are there," Percoco said.

The test attacks were conducted on HTC Corp's Android-based Legend and Desire phones, but he believed it could be conducted on other Android phones.

The tool was released on a DVD given to conference attendees. Percoco was scheduled to discuss it during a talk on Saturday.

Google and HTC did not immediately return calls for comment.

Some 10,000 hackers and security experts are attending the Defcon conference, the world's largest gathering of its type, where computer geeks mix with federal security officials.

Attendees pay $ 140 in cash to attend and are not required to provide their names to attend the conference. Law enforcement posts under cover agents in the audience to spot criminals and government officials recruit workers to fight computer crimes and for the Department of Defense.

Organizers of the conference say presenters release tools such as Percoco's root kit to pressure manufacturers to fix bugs.

Tuesday, May 5, 2009

Why do people write viruses???

Every time when reports of a big new virus or other malware attack hits media, my mind will be out for an answer for the question: Why do people write viruses?

I answer as succinctly as I can, but the question is a deep and complex one. Why do people burglarize homes? Why do people tag buildings with graffiti? Why do they post anonymous hatred on online message boards? Why do they play video games? These questions may sound like they have nothing to do with one another, but you might be surprised how their answers are all related to the topic at hand.

TechRepublic offered an interesting analysis of this issue a month ago but it slipped by me. Fortunately I stumbled upon it this weekend and hope you'll give it a read in order to help shed a little light on a surprisingly complex issue.

So why do people write viruses (and I'll use that term loosely throughout this post as a descriptive for any kind of malware)?

TechRepublic plays it down a bit, but my #1 answer to the question is always the obvious one: For the money. In the old days, a virus designed to erase your hard drive or fill your computer screen with garbage was just a prank (more on that later) but those viruses are quite rare these days. Nowadays, the vast majority of viruses have far more practical ends: They make your PC send spam, they harvest financial information, turn computers into zombies, and extort money out of you directly if you want it deleted. All of these have direct and quantifiable financial goals: Spam is paid for by the message (or the millions of messages) sent. Personal data can be sold on the black market for use in identity theft. It's business, pure and simple -- bad business, to be sure, but all about the cash at the end of the day.

Several of the items on the TechRepublic list get at a secondary reason for virus-writing: They do it because they can. It's the same reason people jump out of planes or drive at insane speeds: It's a thrill, and for a certain subset of programmers, there's a thrill, a laugh, or a power-trip to be had from causing as much damage as possible -- and getting away with it. While most virus writers don't want attention (which can bring serious prison time in the end), a few do, and some underground hackers get off on the notoriety.

Sabotage -- whatever the motivation -- is another common theme in malware creation. Any political issue -- whether it's a presidential election or a Microsoft vs. open source legal spat -- tends to be ground zero for hacker attacks. Denial of service attacks are commonly launched against websites owned by those with opinions unpopular in the hacker community. And that's where your machine comes in: Hackers compromise it with malware to turn it into a DoS zombie.

So, getting the picture? Viruses and other malware are going to be with us forever because they're a digital version of human nature.

Friday, April 10, 2009

Accessing the Computer without an Administrative Password

We all eventually forget one password or the other and such a problem can be so irritating and unpredictable that it can make quite a huge impact. The problem is even more serious when we forget the administrative password to anything, especially our operating system. In most cases the regular user will choose to format the hard disk and then re-install the operating system in order to solve this problem and unfortunately, such an action usually means that some data will be lost along the way. Although it can be impossible at times to access the personal computer if the administrative password was loss, there are some actions you can take in some cases. You will basically need the computer (which really needs to have the possibility to support a bootable CD-ROM) and the Windows CD-ROM.

The first step you will need to take is to modify your personal computer’s BIOS in order to allow booting from the Windows CD-Rom. Next you have to insert the CD in the drive and boot up the PC. Just wait and when the "Press any key to boot from CD" message appears just press any key. Now go through the entire step by step process until you get to the setup screen. This is where you will have the option to repair or install the operating system. You will need to choose repair and Windows Setup will then start a check on your system and start copying files. After this you will notice that the PC will re-boot automatically.

The next step will depend on your operating system. You basically need to open a command prompt after the reboot and resume the setup process. If you have Windows 2000 you have to wait until the part where you see that the OS is registering components and press "Shift + F10". If you have Windows XP you will need to press the same key combination when "Installing devices" appears in the left hand side of your screen. Now we will have a command console open and you can gain access to the Control Panel. In Windows 200 you will need to type "control.exe" and in Windows XP "nusrmgr.cpl". Press the "Enter" key and we now have access to the control panel.

Now just used the tools that are provided in order to reset the password and if you are done just close the control panel by typing "Exit" and then pressing "Enter". Now we will need to allow the repair function to complete as usual. When the operating system starts again you can use the new password in order to log in. There are some circumstances in which you will not be able to access your personal computer but these are rare. If this happens we recommend that you take your hard drive and install it on another computer as slave so that you can save every piece of information you need and then format the entire hard drive. Then you will need to re-install the operating system.
By: Adrian Alexa

Search The Fire Seal

Random Post: I'm feeling lucky!!!