illmob.org

Kon-Boot 3.5 Released

June 28th, 2020 by admin in Uncategorized

Kon-Boot version 3.5 was recently released in early June, with it comes some upgrades for the Windows version, including a new Secure Boot bypass!

  • Secure Boot bypass added (commercial licenses only, PCs (excluding Apple computers))
  • Multiple installer updates and fixes
  • Added support for large USB pendrives (no longer need to meet the 16GB pendrive capacity requirement)
  • Various optimizations

Kon-Boot (aka kon boot, konboot) is a tool that allows accessing target computer without knowing the user’s password. Unlike other solutions Kon-Boot modifies the kernel on the fly and does not reset or modify user’s password and all changes are reverted back to previous state after system restarts. Works on Mac and all current Windows versions, including Window 10 online passwords. We’ve used successfully it in IT and penetration testing engagements for over 10 years now.

Snag a copy from: https://kon-boot.com

Supported Microsoft Windows operating systems
Microsoft Windows XP
Microsoft Windows Vista Home Basic 32Bit/64Bit
Microsoft Windows Vista Home Premium 32Bit/64Bit    
Microsoft Windows Vista Business 32Bit/64Bit    
Microsoft Windows Vista Enterprise 32Bit/64Bit    
Microsoft Windows Server 2003 Standard 32Bit/64Bit    
Microsoft Windows Server 2003 Datacenter 32Bit/64Bit    
Microsoft Windows Server 2003 Enterprise 32Bit/64Bit    
Microsoft Windows Server 2003 Web Edition 32Bit/64Bit    
Microsoft Windows Server 2008 Standard 32Bit/64Bit    
Microsoft Windows Server 2008 Datacenter 32Bit/64Bit    
Microsoft Windows Server 2008 Enterprise 32Bit/64Bit    
Microsoft Windows 7 Home Premium 32Bit/64Bit    
Microsoft Windows 7 Professional 32Bit/64Bit    
Microsoft Windows 7 Ultimate 32Bit/64Bit    
Microsoft Windows 8 and 8.1 all versions (32Bit/64Bit — includes live/online password bypass)
Microsoft Windows 10 all versions (32Bit/64Bit — includes live/online password bypass)
Supported Apple macOS / OS X operating systems
Apple OS X 10.6
Apple OS X 10.7
Apple OS X 10.8
Apple OS X 10.9
Apple OS X 10.10
Apple OS X 10.11
Apple macOS Sierra (10.12)
Apple macOS High Sierra (10.13)
Apple macOS Mojave (10.14)
Apple macOS Cata

Worst passwords of 2019

April 8th, 2020 by admin in Uncategorized

According to SplashData’s The Top 50 Worst Passwords of 2019, tons of people still use “123456” as a password. It ranked second place in 2011 and 2012 and has been number one every year right through 2019. Below is a side by side comparison of the top 25 passwords from 2018 and 2019.

worst passwords 2018 2019

Your xkcd passwords are pwned

December 6th, 2019 by admin in Uncategorized

Unix ninja has a great thorough article about password strengths and standards and why your password probably sucks. Check it out at: https://www.unix-ninja.com/p/your_xkcd_passwords_are_pwned

Kon-Boot

May 27th, 2019 by admin in Uncategorized

Kon-Boot is a tool that allows accessing target computer without knowing the user’s password. Unlike other solutions Kon-Boot does not reset or modify user’s password and all changes are reverted back to previous state after system restart. It has been on the market since 2009 and the free version was downloaded more than 5,000,000 times.

Kon-Boot is currently the only solution worldwide we are aware of that can bypass Windows 10 online passwords! and works with both Microsoft Windows and Apple OSX macOS operating systems. Kon-Boot has been successfully used by military personnel, law enforcement, IT corporations and professionals, forensics experts, private customers.

The latest versions allow you to run PowerShell scripts on Win8/10 machines with UEFI, allowing to automate information gathering quickly for forensic teams. Along with the Sticky Keys escalation feature, which allows user to spawn a console window with system rights before the user is logged in by pressing shift key 5 times, allows for quick access to system resources without worrying about user level access.

Supported operating systems:

Microsoft Windows systems:
   Microsoft Windows XP (from SP2)
   Microsoft Windows Vista Home Basic 32Bit/64Bit
   Microsoft Windows Vista Home Premium 32Bit/64Bit
   Microsoft Windows Vista Business 32Bit/64Bit
   Microsoft Windows Vista Enterprise 32Bit/64Bi
   Microsoft Windows Server 2003 Standard 32Bit/64Bit
   Microsoft Windows Server 2003 Datacenter 32Bit/64Bit
   Microsoft Windows Server 2003 Enterprise 32Bit/64Bit
   Microsoft Windows Server 2003 Web Edition 32Bit/64Bit
   Microsoft Windows Server 2008 Standard 32Bit/64Bit
   Microsoft Windows Server 2008 Datacenter 32Bit/64Bit
   Microsoft Windows Server 2008 Enterprise 32Bit/64Bit
   Microsoft Windows 7 Home Premium 32Bit/64Bit
   Microsoft Windows 7 Professional 32Bit/64Bit
   Microsoft Windows 7 Ultimate 32Bit/64Bit
   Microsoft Windows 8 and 8.1 all versions (32Bit/64Bit)
   Microsoft Windows 10 all versions (32Bit/64Bit)

Apple OSX / macOS systems:
   Apple OSX 10.7
   Apple OSX 10.8
   Apple OSX 10.9
   Apple OSX 10.10
   Apple OSX 10. 11
   Apple macOS Sierra (10.12)
   Apple macOS High Sierra (10.13)
   Apple macoS Mojave (10.14)

Links:
https://kon-boot.com
http://thelead82.com
https://www.piotrbania.com/all/kon-boot/

 

Tutorials: https://kon-boot.com/docs/
Twitter: https://twitter.com/thelead82

Retroactive password policy

April 25th, 2017 by admin in Life, Uncategorized

Sorry your old password isn’t strong enough to change.

source:@PWTooStrong

DPAPIck

October 15th, 2014 by admin in Password Info, Uncategorized

DPAPIck is a forensic tool to deal, in an offline way, with Microsoft Windows® protected data, using the DPAPI (Data Protection API). The tool was updated to support Windows versions all the way to 8.1.

list of recoverable secrets are :

  • EFS certificates
  • MSN Messenger credentials
  • Internet Explorer form passwords
  • Outlook passwords
  • Google Talk credentials
  • Google Chrome form passwords
  • Wireless network keys (WEP key and WPA-PMK)
  • Skype credentials

Src: dpapick.com

Chainbreaker

September 21st, 2014 by admin in Uncategorized

Chainbreaker can extract encrypted user credentials in OS X Keychain and decrypt it using one of the Master Key, user password and SystemKey. More detailed information on this ::here::

src: http://forensic.n0fate.com/?page_id=1180

Bypass iPhone lockscreen with Siri

September 21st, 2014 by admin in Uncategorized

Jose Rodriguez was playing around with an iPhone with iOS 8, and quickly discovered what he saw as a bug: Apple’s voice-activated assistant Siri acting like the worst bouncer ever. In iOS 8, he could activate Siri from the homescreen and she would let him circumvent the lockscreen to post to a person’s Facebook page or look at their notes and call history. No passcode necessary. He posted a demonstration on YouTube.

Kon-Boot 2.4 is out

January 26th, 2014 by admin in Uncategorized

Kon-Boot has updated to version 2.4, which ads the capability to bypass Windows 8/8.1 online account authorization. Definitely worth the price for the time and effort it saves.

Chaos Computer Club breaks Apple TouchID

September 22nd, 2013 by admin in Uncategorized

Using a technique he outlined over 10 years ago, starbug from CCC has broken the biometric lock on the new iPhone.
Source: ccc.de

Next Article »