A ThinkPad supervisor password crack
xiphmont.livejournal.com
xiphmont.livejournal.com
IBM/Lenovo also says the only way to "recover" from a lost password is a new motherboard. Meanwhile eveyone else has figured it out. Great example of security theater.
Note that this password only allows access to BIOS and being able to boot; if the HDD also has a password and/or is encrypted, this doesn't really affect security of data.
My motivation here is the same as most people buying old Thinkpads off eBay-- getting past the SVP on machines with a dead CMOS battery. I don't give a fig about any data on the hard drive :-)
There was this eSettings.exe which let you change some BIOS Settings from Windows, including the password. Of course it first asked for the old password and showed a prompt, denying the request if it was wrong.
I fired up good old OllyDbg and traced the prompt in the ASM code. I changed only one bit IIRC (jne to je, or similar), saved the .exe and tried my luck.
It let me through the prompt and I entered the new password. Amazingly the BIOS gladly accepted it!
I didn't bother to find out what functions it exactly called to set the new password to write a small tool, because I already had one. ;)
I wonder if this still works... If not with an Acer, maybe with some other make?
I've never seen a BIOS that actually had anything but application-level password check for the calls from OS mode to rewrite the BIOS passwords or settings. No idea whether you can leverage TPMs or some of the enterprise trusting features to change that, though.
But I've always been a bit confused as to why they've never fixed (or at least tried to fix) this issue.
I don't think it's a serious enough security feature to be worth trying to defend against physical access.
With the architecture used, they're never going to be too robust to physical access. Overall EEPROM reset button on motherboard would be best, and just admit there's no really security against physical access here.
No, I don't know a trick for new machines, and am unlikely to look for one. Modern Thinkpads aren't machines I'm very interested in.
I have a t420 that has the supervisor password enabled. The only thing it prevented me from doing was enabling virtualization on the cpu, but docker has mostly replaced vagrant for me so I haven't minded.
sigh Please, Please, provide reasons along with your arguments. Simply stating something doesn't help, especially when there is contradicting information floating around.
PROT is not the WP pin. They're different. Go read the spec sheets.
The original hack as discovered was PROT to GND, not SCL to SDA. My only speculation was as to why the hack as reposted changed over time.
The more interesting aspect, verified by testing, is that it does work.
In my own testing, SCL to SDA will not work on the T2X, T3X, T4X, T60, X2X, X3X, X4X, or X60. It does work on the T61/X61 and T400/500.
PROT to GND works on all of the above. I also tested it on an X230 (works), but I didn't check SCL to SDA on that machine.
That being said, it's likely the firmware's failsafe-mechanism kicking in when it cannot access the memory chip that stores the password (because access to the chip is hindered).
Yet utilizing the "WP" (write protect) pin on the memory chip ought to do nothing in my opinion - unless the firmware tries to store something to the memory at boot time (which is entirely possible). On the other hand, forcing clock or data pins to ground - in effect disallowing any signalling via them - should be a sureproof way to force the firmware to trigger it's failsafe mechanism.
But I was more interested in the end-to-end test, as I expected others reading would also be:
SDL to SDA (the usual instructions given elsewhere) only works on some models.
PROT to GND appears to work on all. In my collection of ~ 30 machines, it works on all the models SCL to SDA does, as well as all the models SCL to SDA does not.
PROT to GND was the original hack as discovered around the time of the T20.
Source: http://cache.nxp.com/documents/data_sheet/PCA24S08.pdf (Section 6.4 Access Protection)