Mac OS X Lion Login Passwords Extracted With Ease
securityweek.com
securityweek.com
Edit: the WinLockPwn tool has been available since 2008, you can just plug one computer into another and dump the RAM. You can then use "signatures" to search for passwords for various systems, including Windows. http://web.archive.org/web/20090402130220/http://storm.net.n...
I like this part:
I'm also pleased to note... the guy who did it by plugging a Cardbus Firewire card into a laptop that didn't have firewire, waiting for it to auto install it (while at the locked screen!) then winlockpwning it. That's awesome. :)
So, even if your laptop doesn't currently have firewire, you're still not safe.
Time to whip out the epoxy, I reckon.
[1]: http://www.hermann-uwe.de/blog/physical-memory-attacks-via-f...
Not really. Note that LightPeak/Thunderbolt has the exact same issue. I believe it can be mitigated by the right IOMMU implementation (if the OS takes advantage of the feature).
Kon-Boot is an prototype piece of software which allows to change contents of a linux kernel (and now Windows kernel also!!!) on the fly (while booting). In the current compilation state it allows to log into a linux system as 'root' user without typing the correct password or to elevate privileges from current user to root. For Windows systems it allows to enter any password protected profile without any knowledge of the password. It was acctually started as silly project of mine, which was born from my never-ending memory problems :) Secondly it was mainly created for Ubuntu, later i have made few add-ons to cover some other linux distributions. Finally, please consider this is my first linux project so far :) Entire Kon-Boot was written in pure x86 assembly, using old grandpa-geezer TASM 4.0.
It's a little hard to believe this as there's really no need to have the password kept in memory; it could be the exploit requires the device to be plugged in while you're typing your password--which is more believable and also less interesting.
These seems like big holes.
Do you really think there are security experts who don't bother with screensaver passwords or whole disk encryption?
I'm no encryption expert, but it seems like you would need to store decryption keys (or in this case, the login password) in plaintext so they could be used by the OS.
An explanation from an expert would be appreciated.
FireWire asks for it, but in recent years CPUs have started implementing IOMMUs, which should be useable to "lie" to devices and sandbox DMA'd memory, preventing full memory access to even low level busses (such as FireWire or Thunderbolt)
This is a well known and common lockdown procedure for security focused Mac admins, especially as it also prevents booting off of alternate media.
Hm, isn't automatic login now disabled by default in the installation process of Lion? The last install I did seemed to have it disabled by default although there was a toggle to switch it on if I so chose.