How to get into an admin account on a Windows computer
m.imgur.com
m.imgur.com
Actually, someone linked to something like it in the comments: https://i.imgur.com/n9Th4q5.jpg
I can't imagine how difficult it must be to secure a login system with so much added surface due to accessibility and dumb users.
Bottom line is, if you let people have physical access to the machine, they can always own it.
The disk contents are fully encrypted, and Windows will only boot when the system is in an untampered state (via TPM unlock). A student would have to compromise Windows in a way that escalates their privileges. From there they could turn BitLocker off if they liked. This is far from impossible, but we also use AppLocker to prevent students from running any software that has not be explicitly approved--so they would have to compromise some software which is already installed. I won't delude myself and say it's impossible to compromise all of this, but for my goal of keeping 13-18 year-olds from resetting the local admin password it is quite sufficient.
TPM chips generally provide the following: 1. An encrypted store that can only be accessed by an authorized portion of code ( such as booting an encrypted drive ). Checks are done to ensure the code being run is signed. 2. Secure RNG ( random number generation ) 3. Various other public/private key stuff
Typically you can enable/disable TPM from the BIOS. ( whether it is a physically removeable TPM chip or not )
Obviously removing/destroying the TPM chip will cause a loss of data, but that is irrelevant if you don't care about that data and are willing to reinstall the OS.
It isn't hard to install a clean OS on a wiped drive. Even supposing somehow you couldn't reset the BIOS to shut off the TPM and force a normal clean drive boot process, I was speculating if removing/destroying the TPM would revert to booting normally.
Note there was a lot of anger when TPMs were initially introduced, because they could effectively be used to force a system to only ever boot a signed OS. ( removing the ability to run Linux ) This is my curiosity; if on normal systems this can be forced or not.
How would one complete an image level backup of an encrypted hard drive without admin rights?
Honestly software security is the optimal solution. It solves a whole host of threat models (alternative boot media, repair tool, HDD removal, stolen machines, HDD warranty data leaks, lost laptops, etc). All physical security does with that in place is stop someone stealing your internal components, but it is expensive to do well and relatively easy to defeat with just a screwdriver or paperclip (and "unlimited" time).
If full-disk encryption isn't used, there's really not much the underlying OS can do to prevent this.
This exploit does actually open possibilities where there were few/none before. Also I imagine it's easier for some people to execute.
Here's one of the pages that lists some of them: http://www.uktsupport.co.uk/reference/biosp.htm
I'm glad they've made this harder, as most thieves are deterred by the technical aspects of breaking in to wipe a computer.
I don't understand why more labs don't use dumb terminals to hook back into a VM that gets blown out the airlock after each and every use.
[1] http://answers.microsoft.com/en-us/windows/forum/windows_7-s...
Here's a 'guide' from 2012 http://carnal0wnage.attackresearch.com/2012/04/privilege-esc...
And here's a 'fix' from microsoft: https://social.technet.microsoft.com/Forums/windows/en-US/a3...
If you can alter one system file then you can alter all system files. So even if this got "fixed," then another program would be replaced, a service, or the login screen itself.
The only actual fix is to protect the Windows installation itself, this can be accomplished through full disk encryption (e.g. Bitlocker) in combination with uEFI secure boot.
To be honest I roll my eyes when people post "exploits" like this. It just shows that people have no core understanding of computer security from the ground on up.
As an aside this exact exploit would work perfectly on a Linux (e.g. Ubunutu) system that didn't implement full disk encryption.
Performing this modification DOES NOT require rebooting the computer into startup repair if you have admin access (which is typical after you get hacked). There is a process that watches system32 for modifications and resets them, but if you script it and change the files fast enough it won't notice.
The utility of this trick is really insane. Would you realize that a hacker had backdoor access to your computer via RDP if the only thing that was modified was cmd.exe and sethc.exe swapping places?
That makes any password work for login, but only once, and it's undetectable after a reboot.
http://piotrbania.com/all/kon-boot/index2.html is the free version, which can be installed with http://www.pendrivelinux.com/yumi-multiboot-usb-creator/. That only works on 32-bit systems and up to Windows 7.
If you want the paid version, you can either buy it from http://www.piotrbania.com/all/kon-boot/, or get it from http://kickass.so/kon-boot-v2-4-remedy-for-lost-password-mum... or your usual source.
I'm pretty sure everyone interested on here is able to find the "usual sources".
Ahould the tools locksmith's use also be considered illegal and therefore you can steal them?
Of course not. There are many valid usecases for tools like this. Especially for people working as sysadmins.
I was quite surprised to find that the command shell ran with admin privs from before the login process, since I was unable to elevate in any other way (including by trying system restore back before joining, or trying to get into safe mode).
But the interesting part of this post is the trick to do the file renaming without having to boot from any external media. This bypasses any security preventing the use of external media. Even if a user has access only to the keyboard, mouse, and power button (or can cut the power by pulling the cable), he can use this trick to do the file renaming and gain local admin access.
You can achieve admin on an OS X machine by adding a new one like so:
1. Enter single user mode via cmd + s during startup.
2. Mount the hard drive via /sbin/mount/ -uw /
3. Delete the setupdone check via rm /var/db/.applesetupdone
4. Reboot, and now you are presented with the wizard for adding a new admin account.
Create a batch file with the content:
net localgroup administrators NewUser /add
...then stick this into the 'StartUp' directory for All Users. Break something. Call support. They log in as Administrator, running your batch file in the process.
NewUser would be created with Admin rights. You wouldn't promote your own login, of course.
This exploit you could even pull off on a school lab computer while the teacher is in the room. If he comes over while you're working, inconspicuously power off the machine.
That's like saying, "Car door was open, therefore not theft."
You can't stop a guy who knows what he's doing, but you can stop Josie from the next desk snooping around in HR's file. Also, it causes a breach, which depending on where you live might be needed to show intent.
Also, some people may feel like changing your wallpaper to something inappropriate, but they may not be motivated enough to hack your pc.
most people would open your door if there was no lock on it. Eventhough it's useless.
This is less common NOW, but back in the Android 2.xx days it was the defacto way of getting root.
> Do you really think that startup repair mode is required to swap the position of cmd.exe and sethc.exe?
A Live CD/DVD would work just as well. As would a USB-based OS. You could also (although it would require more work) use network boot to run your own code.
There's no vulnerability, this is unfixable, you just have to secure the system using full disk encryption and secure boot.
The comments about bitlocker and TPM are a good reminder that he who controls the boot sequence controls the computer / phone / car / IoT toaster.
I talked the teacher into canceling all of my detentions in return for showing him how to secure his bootdisks. Man, kids today would just get expelled or go to jail. I'm glad I grew up when I did.
Me and the girl were white honor students, and we were let off with a stern warning, and our "weapons" were handed to our parents. The mexican kid with poor english skills got sent to an alternative school (the kind for disciplinary risk kids).
Does this fix it?
The settings can be changed with bcdedit:
bcdedit /set {default} recoveryenabled No
bcdedit /set {default} bootstatuspolicy ignoreallfailures
Additionally booting from USB/... should be disabled in the BIOS/UEFI options and also access to that should be password secured.Further more because the person has physical access, the computer should be locked away so that the harddrive can't be accessed. Also all cables should be secured so that no sniffer can be plugged in between. This also especially includes the USB ports on the monitor if those are enabled.
To paraphrase another comment from imgur: If the hacker has physical access to the machine, it's now their machine.
Binding sticky keys to CMD is one of the worst ways as it can be detected easily (either via people trying to use Magnifier and getting CMD, hitting shift 5x times, etc), it can be fixed by Windows updates even by accident (and will be fixed via SFC), and could allow other competing "hackers" to access the machine.
I've never seen anyone use this trick in reality and I've certainly never read about "hackers" using it. They typically like to use a tiny single-file VNC server with a hardcoded user/password.
Similarly, on any UNIX OS, you can boot into single-user mode and obtain root access.
These are ancient techniques.
The obligatory response every. single. time this is brought up: Local access? All bets are off. (With certain caveats, of course).
Usually they reference a government document that says that physical destruction of the media is the only correct method to erase TOP SECRET (and above) data, but that is mostly paranoid burocracy.
If you're using a SDD however, you have to deal with firmware wear-leveling, garbage collection and the drive having a lot of GBs hidden from everyone, even the OS. There are some proposed techniques to force an unavailable block back into the available pool and then reading long-deleted data. Afaik, there's little you can do in this scenario, even full disk encryption might not help you with the old data blocks that are still waiting to be zeroed by the GC.
Then again, like you said, FDE is probably the easiest way. TrueCrypt was vulnerable to some on-memory-key attacks, but for data killing its more than enough. There are some projects that have forked TCs code, and there also the old version available thats still fully functional.
https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase
If you have a linux box handy, you can probe your ATA-compatible drives with:
root# hdparm -I /dev/X
look for: Security:
Master password revision code = 65534
supported
enabled
not locked
not frozen
not expired: security count
supported: enhanced erase
Security level high
2min for SECURITY ERASE UNIT. 2min for ENHANCED SECURITY ERASE UNIT.
"Enhanced Security Erase Unit" should get all of the sectors that have been previously used even on a SSD with wear leveling.Of course, you still have to trust that the vendor has correctly implemented it. I have no idea what best practices are in that regard. If anybody here has a better idea, I'd love to hear (Is FIPS certification a good sign? If the drive implements encryption and can therefore do a secure erase by dropping the keys can it be trusted? Can drive vendors generally trusted to not use ECB mode? etc.)
A more reliable way if you're somewhat prepared is to just use a live linux system and NTPasswd. Any distro that can be installed to a flash drive should have it available.
why go through all the trouble? just take the disk out and mount it elsewhere.
that's why one has to encrypt drives.
I then got called away from the computer before I could switch magnifier and cmd back to normal and somebody started using the computer again, with hilarious consequences
(Note: I'm not the IT guy in this company xD)