<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>What&#039;s My Pass? &#187; Linux</title>
	<atom:link href="http://www.whatsmypass.com/tag/linux/feed" rel="self" type="application/rss+xml" />
	<link>http://www.whatsmypass.com</link>
	<description>Password Recovery for Windows, Mac, Linux, browsers, email, instant messengers, BIOS</description>
	<lastBuildDate>Tue, 24 Jan 2012 16:08:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Password Exploitation Class Videos</title>
		<link>http://www.whatsmypass.com/password-exploitation-class-videos</link>
		<comments>http://www.whatsmypass.com/password-exploitation-class-videos#comments</comments>
		<pubDate>Tue, 31 Aug 2010 02:47:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Matthew Shoemaker Memorial Fund]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Wireless profile passwords]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/password-exploitation-class-videos</guid>
		<description><![CDATA[The Password Exploitation Class was put on as a charity event for the Matthew Shoemaker Memorial Fund . The speakers were Dakykilla, Purehate_ and Irongeek. Lots of password finding and crack topics were covered. Hashcat, OCLHashcat, Cain, SAMDump2, Nir&#8217;s Password Recovery Tools, Password Renew, Backtrack 4 R1, UBCD4Win and much more. Part 1: Topics include: [...]]]></description>
			<content:encoded><![CDATA[<p>The Password Exploitation Class was put on as a charity event for the <a href="http://www.shoecon.org">Matthew Shoemaker Memorial Fund </a>. The speakers were Dakykilla, <a href="http://www.question-defense.com">Purehate_</a> and <a href="http://www.irongeek.com/">Irongeek</a>.</p>
<p>Lots of password finding and crack topics were covered. Hashcat, OCLHashcat, Cain, SAMDump2, Nir&#8217;s Password Recovery Tools, Password Renew, Backtrack 4 R1, UBCD4Win and much more.<br />
<span id="more-1018"></span></p>
<p>Part 1: Topics include: Why exploit local passwords?, Scenario:Imaged Systems, Grabbing local passwords, Hash Examples, Great Resources, Platforms Used: Ubuntu, Backtrack, UBCD4Win, Windows Profile, Windows System Trifecta, Anti-Virus Pains, Getting an account/changing an account password, hash insertion, Sala&#8217;s Password Renew, Keyloggers, Boot CD demos, SAMDump2, Browser Passwords, IE, Firefox Etc., PSPV, PasswordFox, IE Passview, ChromePass, RDP and VNC password grabbing, Instant Messaging, Stupid Web Apps rant, AOA: Any Old Asterisks (stuff hidden by Asterisks), Network Shares stored passwords, Outlook PST password cracking and hash collision example, Wireless profile passwords, WirelessKeyView, Sniffing them off the wire with Wireshard and Cain.<br />
<a href="http://www.archive.org/download/PasswordExploitationClass/passwordclass1.avi">Download Class 1</a></p>
<p>Part 2: The best single video out there for showing Hashcat and OCLHashcat. Lots of info about using Hashcat/OCLHashcat, its advantages, and the power of a video card to boost cracking speed.<br />
<a href="http://www.archive.org/download/PasswordExploitationClass/passwordclass2.avi">Download Class 2</a></p>
<p>Part 3: Windows LM and NTLM hash cracking, Time Memory Tradeoffs, SAM Cracking Prevention, Linux/Unix passwd and shadow files, Parts of a *nix hash, Windows Cached Domain Credentials, Problems with Windows 7, Cracking Creds Countered, Finding where Unknown Apps store passwords, System Process Monitoring, RegFromApp, ProcessActivityView, Procmon (Process Monitor), finding the hash type, Other Weird Vectors, Inverse Bruteforce, Look in the logs for passwords, upcoming events.<br />
<a href="http://www.archive.org/download/PasswordExploitationClass/passwordclass3.avi">Download Class 3</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/password-exploitation-class-videos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.archive.org/download/PasswordExploitationClass/passwordclass2.avi" length="245204672" type="video/x-msvideo" />
<enclosure url="http://www.archive.org/download/PasswordExploitationClass/passwordclass1.avi" length="340141508" type="video/x-msvideo" />
<enclosure url="http://www.archive.org/download/PasswordExploitationClass/passwordclass3.avi" length="200843330" type="video/x-msvideo" />
		</item>
		<item>
		<title>Kon Boot 1.1</title>
		<link>http://www.whatsmypass.com/kon-boot-1-1</link>
		<comments>http://www.whatsmypass.com/kon-boot-1-1#comments</comments>
		<pubDate>Mon, 10 May 2010 09:08:13 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[kon-boot]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[USD]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=935</guid>
		<description><![CDATA[We reviewed Kon Boot 1.0 last year HERE which was a great breakthrough program that allowed you to boot into a Windows machine and bypass the logon screen without entering a password. To accomplish this, Kon Boot hooks the bios on the fly subverting the Windows kernel authentication temporarily and allowing you access. Since this [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://img718.imageshack.us/img718/1199/konboot11.png" alt="Kon Boot 1.1" /><br />
We reviewed Kon Boot 1.0 last year <a href="http://www.whatsmypass.com/bypass-windows-logon-password">HERE</a> which was a great breakthrough program that allowed you to boot into a Windows machine and bypass the logon screen without entering a password. To accomplish this, Kon Boot hooks the bios on the fly subverting the Windows kernel authentication temporarily and allowing you access. Since this is a temporary process the computer is back to normal when you reboot. This allowed you to access the computer without having to take the time to reset the password or crack it, and it left the computer untouched. Now, a year later, Kon Boot v1.1 has been released with new features, such as booting from floppy,CD, or usb, privilege escalation support which allows you to gain SYSTEM privileges from ANY account on the system. For example, you can boot from Kon Boot and log in as Guest and run &#8216;Net User&#8217; command to add a new user,reset admin passwords etc as SYSTEM </p>
<p>It also has a bunch of new bug fixes/updates.</p>
<ol>
<li>- Added 64-bit environment support</li>
<li>- Added USB support tools (grldr, klmemusb)</li>
<li>- Added debugging code to make it easier to track down various compatibility problems</li>
<li>- Fixed bug in Windows 7 support failures</li>
<li>- Removed Linux support</li>
<li>- Many performance improvements to source code</li>
<li>- Improved BIOS support by reducing code size significantly</li>
</ol>
<p>Unfortunately it is no longer free. But for a meager price of $15.99 for a personal license, it gives you free updates and support for a period of 6 months. You can still use it without restrictions after that period.<br />
They also offer a commercial license, for $75.99 with 1 year of support and updates, allowing you to use on business environment.<br />
To purchase Kon Boot v1. 1,visit their website <a href="http://www.kryptoslogic.com/?area=2&#038;item=2">http://www.kryptoslogic.com</a></p>
<p>We are also giving away 10 personal licenses this week to some lucky readers!!! More details to come!!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/kon-boot-1-1/feed</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Password Cracking Guide</title>
		<link>http://www.whatsmypass.com/password-cracking-guide</link>
		<comments>http://www.whatsmypass.com/password-cracking-guide#comments</comments>
		<pubDate>Wed, 24 Mar 2010 15:06:24 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[Password Info]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Cracking Office]]></category>
		<category><![CDATA[GPU]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Novell NetWare]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[WEP]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/password-cracking-guide</guid>
		<description><![CDATA[This pdf document is for people who want to learn to the how and why of password cracking. There is a lot of information being presented and you should READ IT ALL BEFORE you attempted doing anything documented here. Here is the table of contents 1 LM vs. NTLM 2 Syskey 3 Cracking Windows Passwords [...]]]></description>
			<content:encoded><![CDATA[<p>This pdf document is for people who want to learn to the how and why of password cracking. There is a lot of information being presented and you should READ IT ALL BEFORE you attempted doing anything documented here.<span id="more-912"></span><br />
Here is the table of contents</p>
<pre>1 LM vs. NTLM
2 Syskey
3 Cracking Windows Passwords
   3.1 Extracting the hashes from the Windows SAM
      3.1.1 Using BackTrack Tools
         3.1.1.1 Using bkhive and samdump v1.1.1 (BT2 and BT3)
         3.1.1.2 Using samdump2 v2.0.1 (BT4)
         3.1.1.3 Cached Credentials
      3.1.2 Using Windows Tools
         3.1.2.1 Using fgdump
         3.1.2.2 Using gsecdump
         3.1.2.3 Using pwdump7
         3.1.2.4 Cached Credentials
   3.2 Extracting the hashes from the Windows SAM remotely
      3.2.1 Using BackTrack Tools
         3.2.1.1 ettercap
      3.2.2 Using Windows Tools
         3.2.2.1 Using fgdump
   3.3 Cracking Windows Passwords
      3.3.1 Using BackTrack Tools
         3.3.1.1 John the Ripper BT3 and BT4
            3.3.1.1.1 Cracking the LM hash
            3.3.1.1.2 Cracking the NTLM hash
            3.3.1.1.3 Cracking the NTLM using the cracked LM hash
            3.3.1.1.4 Cracking cached credentials
         3.3.1.2 John the Ripper - current
            3.3.1.2.1 Get and Compile
            3.3.1.2.2 Cracking the LM hash
            3.3.1.2.3 Cracking the LM hash using known letter(s) in known location(s) (knownforce)
            3.3.1.2.4 Cracking the NTLM hash
            3.3.1.2.5 Cracking the NTLM hash using the cracked LM hash (dumbforce)
            3.3.1.2.6 Cracking cached credentials
         3.3.1.3 Using MDCrack
            3.3.1.3.1 Cracking the LM hash
            3.3.1.3.2 Cracking the NTLM hash
            3.3.1.3.3 Cracking the NTLM hash using the cracked LM hash
         3.3.1.4 Using Ophcrack
            3.3.1.4.1 Cracking the LM hash
            3.3.1.4.2 Cracking the NTLM hash
            3.3.1.4.3 Cracking the NTLM hash using the cracked LM hash
      3.3.2 Using Windows Tools
         3.3.2.1 John the Ripper
            3.3.2.1.1 Cracking the LM hash
            3.3.2.1.2 Cracking the NTLM hash
            3.3.2.1.3 Cracking the NTLM hash using the cracked LM hash
            3.3.2.1.4 Cracking cached credentials
         3.3.2.2 Using MDCrack
            3.3.2.2.1 Cracking the LM hash
            3.3.2.2.2 Cracking the NTLM hash
            3.3.2.2.3 Cracking the NTLM hash using the cracked LM hash
         3.3.2.3 Using Ophcrack
            3.3.2.3.1 Cracking the LM hash
            3.3.2.3.2 Cracking the NTLM hash
            3.3.2.3.3 Cracking the NTLM hash using the cracked LM hash
         3.3.2.4 Using Cain and Abel
      3.3.3 Using a Live CD
         3.3.3.1 Ophcrack
4. Changing Windows Passwords
   4.1 Changing Local User Passwords
      4.1.1 Using BackTrack Tools
         4.1.1.1 chntpw
      4.1.2 Using a Live CD
         4.1.2.1 chntpw
         4.1.2.2 System Rescue CD
   4.2 Changing Active Directory Passwords
5 plain-text.info
6 Cracking Novell NetWare Passwords
7 Cracking Linux/Unix Passwords
8 Cracking networking equipment passwords
   8.1 Using BackTrack tools
      8.1.1 Using Hydra
      8.1.2 Using Xhydra
      8.1.3 Using Medusa
      8.1.4 Using John the Ripper to crack a Cisco hash
   8.2 Using Windows tools
      8.2.1 Using Brutus
9 Cracking Applications
   9.1 Cracking Oracle 11g (sha1)
   9.2 Cracking Oracle passwords over the wire
   9.3 Cracking Office passwords
   9.4 Cracking tar passwords
   9.5 Cracking zip passwords
   9.6 Cracking pdf passwords
10 Wordlists aka Dictionary attack
   10.1 Using John the Ripper to generate a wordlist
   10.2 Configuring John the Ripper to use a wordlist
   10.3 Using crunch to generate a wordlist
   10.4 Generate a wordlist from a textfile or website
   10.5 Using premade wordlists
   10.6 Other wordlist generators
   10.7 Manipulating your wordlist
11 Rainbow Tables
   11.1 What are they?
   11.2 Generating your own
      11.2.1 rcrack - obsolete but works
      11.2.2 rcracki
      11.2.3 rcracki - boinc client
      11.2.4 Generating a rainbow table
   11.3 WEP cracking
   11.4 WPA-PSK
      11.4.1 airolib
      11.4.2 pyrit
12 Distributed Password cracking
   12.1 john
   12.2 medussa (not a typo this is not medusa)
13 using a GPU
   13.1 cuda - nvidia
   13.2 stream - ati</pre>
<p><a href="http://tools.question-defense.com/Cracking_Passwords_Guide.pdf">Cracking_Passwords_Guide.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/password-cracking-guide/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hashcat v0.30</title>
		<link>http://www.whatsmypass.com/hashcat-v0-30</link>
		<comments>http://www.whatsmypass.com/hashcat-v0-30#comments</comments>
		<pubDate>Mon, 28 Dec 2009 04:19:47 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[Files]]></category>
		<category><![CDATA[Force Attack]]></category>
		<category><![CDATA[Gentoo]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=837</guid>
		<description><![CDATA[A new multi-platform password cracking tool hashcat was just released publicly. Tested on XP, Win7, Gentoo, Debian The main features of hashcat are: * It is free. * Native binaries for Linux and Windows. * Multi-threaded. * Supports the following hashes: * MD5 * md5($pass.$salt) * md5($salt.$pass) * md5(md5($pass)) * md5(md5(md5($pass))) * md5(md5($pass).$salt) * md5(md5($salt).$pass) [...]]]></description>
			<content:encoded><![CDATA[<p>A new multi-platform password cracking tool hashcat was just released publicly.<br />
Tested on XP, Win7, Gentoo, Debian</p>
<p>The main features of hashcat are:</p>
<p>* It is free.<br />
* Native binaries for Linux and Windows.<br />
* Multi-threaded.<br />
<span id="more-837"></span><br />
* Supports the following hashes:</p>
<p>    * MD5<br />
    * md5($pass.$salt)<br />
    * md5($salt.$pass)<br />
    * md5(md5($pass))<br />
    * md5(md5(md5($pass)))<br />
    * md5(md5($pass).$salt)<br />
    * md5(md5($salt).$pass)<br />
    * md5($salt.md5($pass))<br />
    * md5($salt.$pass.$salt)<br />
    * md5(md5($salt).md5($pass))<br />
    * md5(md5($pass).md5($salt))<br />
    * md5($salt.md5($salt.$pass))<br />
    * md5($salt.md5($pass.$salt))<br />
    * md5($username.0.$pass)<br />
    * md5(strtoupper(md5($pass)))<br />
    * SHA1<br />
    * sha1($pass.$salt)<br />
    * sha1($salt.$pass)<br />
    * sha1(sha1($pass))<br />
    * sha1(sha1(sha1($pass)))<br />
    * MySQL<br />
    * MySQL4.1/MySQL5<br />
    * MD5(WordPress)<br />
    * MD5(phpBB3)<br />
    * MD5(Unix)<br />
    * SHA-1(Base64)<br />
    * SSHA-1(Base64)</p>
<p>* Supports the following attacks:</p>
<p>    * Straight-Words Attack<br />
    * Combination-Words Attack<br />
    * Toggle-Case Attack<br />
    * Brute-Force Attack</p>
<p>* All Attack-Modes except Brute-Force can be extended by Hybrid-Attack rules.<br />
* Hybrid-Attack engine is mostly compatible with JTR / PasswordsPro.<br />
* Possible to resume or limit session.</p>
<p>It also has some special features:</p>
<p>* Automatically recognizes already recovered hashes from outfile at startup.<br />
* Automatically generate random rules for Hybrid-Attack.<br />
* Load hashlist that include more than 3 million hashes of any supported type at once.<br />
* Load saltlist from external file and then use them in a Brute-Force Attack variant.<br />
* Able to work in an distributed environment.</p>
<p>There are some more things you should know:</p>
<p>* You can specify multiple wordlists and also multiple directories of wordlists.<br />
* Number of threads can be configured.<br />
* Threads run on lowest priority.</p>
<p>Get It Here: <a href="http://hashcat.net/hashcat/#downloadlatest">hashcat</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/hashcat-v0-30/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Bypass Windows Logon Password</title>
		<link>http://www.whatsmypass.com/bypass-windows-logon-password</link>
		<comments>http://www.whatsmypass.com/bypass-windows-logon-password#comments</comments>
		<pubDate>Thu, 23 Apr 2009 22:22:29 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[Fedora]]></category>
		<category><![CDATA[Gentoo]]></category>
		<category><![CDATA[i-mate SP3 Cell Phone]]></category>
		<category><![CDATA[kon-boot]]></category>
		<category><![CDATA[konboot]]></category>
		<category><![CDATA[KryptosLogic]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Linux system]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[Microsoft Vista]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[SP2]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[VXI Corporation TalkPro SP1 Headset]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=604</guid>
		<description><![CDATA[Accessing a Windows computer without knowing the password is fairly simple with this free tool called Kon-Boot .There are alternatives like Ophcrack etc, but those rely on grabbing the SAM hashes and cracking those. What sets Kon-Boot apart is that is modifies the kernel on-the-fly while booting (everything is done virtually &#8211; without any interferences [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="size-full wp-image-605 alignnone" title="konboot-300x111" src="http://www.whatsmypass.com/wp-content/uploads/2009/04/konboot-300x111.jpg" alt="" width="300" height="111" /></p>
<p>Accessing a Windows computer without knowing the password is fairly simple with this free tool called Kon-Boot .There are alternatives like Ophcrack etc, but those rely on grabbing the SAM hashes and cracking those. What sets Kon-Boot apart is that is modifies the kernel on-the-fly while booting (everything is done virtually &#8211; without any interferences with physical system changes) and allows you to log into any account without entering a password. All you have to do is insert a boot (cd or floppy) disk burned with Kon-boot software(110kb) in to the computer and boot up.<br />
<span id="more-604"></span><br />
<a href="http://www.whatsmypass.com/wp-content/uploads/2009/04/konboot.png"><img class="aligncenter size-medium wp-image-606" title="konboot" src="http://www.whatsmypass.com/wp-content/uploads/2009/04/konboot.png" alt="" width="490" height="317" /></a><br />
Kon-boot which was initially started as a small project for Linux (mainly Ubuntu),where it allows to log into a Linux system as ‘root’ user without typing the correct password or to elevate privileges from current user to root. Now it was moved to windows platform where it enables Windows users to login to any password protected machine profile without any knowledge of the password.<br />
This program works with the following versions of Windows: XP (SP1, SP2, SP3), Vista (Business, Ultimate), 2000, Server 2003 and 2008, and Windows 7. Kon-Boot also allows you to boot Linux (distributions: Ubuntu, Gentoo, Debian and Fedora) without a password as well.</p>
<p style="text-align: center;"><a href="http://www.piotrbania.com/all/kon-boot/">http://www.piotrbania.com/all/kon-boot/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/bypass-windows-logon-password/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>10 ways of resetting a lost linux root password</title>
		<link>http://www.whatsmypass.com/10-ways-of-resetting-a-lost-linux-root-password</link>
		<comments>http://www.whatsmypass.com/10-ways-of-resetting-a-lost-linux-root-password#comments</comments>
		<pubDate>Wed, 22 Apr 2009 15:34:26 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[boot manager]]></category>
		<category><![CDATA[boot server]]></category>
		<category><![CDATA[cd/dvd player]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Id]]></category>
		<category><![CDATA[Lilo]]></category>
		<category><![CDATA[Linux system]]></category>
		<category><![CDATA[mobile devices]]></category>
		<category><![CDATA[Most linux installation]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[startup manager]]></category>
		<category><![CDATA[system administrator]]></category>
		<category><![CDATA[Toshiba HD-A1 Player HD-DVD Player]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=602</guid>
		<description><![CDATA[via: handlewithlinux.com A good password has the problem of being difficult to remember. And sometimes you might need to get in to a system where the root password is long forgotten (or left with the system administrator before you). Luckily there are ways of getting access to systems without having the password. This is of [...]]]></description>
			<content:encoded><![CDATA[<p>via: <a href="http://www.handlewithlinux.com/10-ways-of-resetting-a-lost-linux-root-password">handlewithlinux.com</a></p>
<p>A good password has the problem of being difficult to remember. And sometimes you might need to get in to a system where the root password is long forgotten (or left with the system administrator before you).<br />
Luckily there are ways of getting access to systems without having the password. This is of course in a sense also a security risk. That&#8217;s why you should always be aware that having unattended physical access to a computer system means the same as having root access to the operating system. Unless the information on a system is encrypted, it&#8217;s only as save as the room it&#8217;s in.</p>
<p>The method to use to reset the password if you lost the root (or only) password depends on the configuration of your system. But it mostly comes down to two separate tasks:</p>
<p>- get write access to the root partition</p>
<p>- change the password/circumvent control</p>
<p>Here are some things you can try from easy to more complicated.<span id="more-602"></span></p>
<h2>1.booting into single user mode from the start menu</h2>
<p>Some systems are configured to drop you into root shell without a password if you reboot them in single user mode. If your system has an option called single or recovery mode changes are it will drop you directly to the root prompt or as I know ubuntu does it serves up a menu with &#8216;drop to root shell prompt&#8217; as an option. Sometimes you have to hit escape at startup to enter the boot menu.<br />
Once in the root shell it&#8217;s as easy as typing passwd followed by your username and the passwd program will ask you for the new password. passwd without a name will change the root password.<br />
If you don&#8217;t know the username anymore you can do</p>
<p>#cat /etc/ passwd this prints the password text file where every entry before the : is a valid username</p>
<p>or</p>
<p>#ls /home  which will give you the username of the users on the system with a home directory (if the default home path is used)</p>
<p>If you have a system which has this boot option and you think this is just a to obvious security risk (don&#8217;t want your little sister to change your root password) you can easily remove this option by editing the file /boot/grub/menu.lst (if you use the grub boot loader) or /etc/lilo.conf (if you use lilo)<br />
If you use Ubuntu you can set passwords for the menu options in the startup-manager from the administration menu security tab or remove the option in the advanced tab.<br />
Grub and Lilo both have password options<br />
to password protect grub create a md5 hash of your password ( #/sbin/grub-md5-crypt ) and edit the file /boot/grub/grub.conf add below the line timeout the following line:</p>
<p>password &#8211;md5 password-hash-here</p>
<p>grub configuration should be user root group root and 600 permissions.</p>
<p>to password protect boot menu entries just enter lock below the title line in the /boot/grub/menu.lst file</p>
<p>for protecting lilo edit the /etc/lilo.conf file before the first image stanza place the option</p>
<p>password=clear-text-password</p>
<h2>2. booting into single user mode when there&#8217;s no menu entry at startup</h2>
<p>If there&#8217;s no single or recovery option in the boot menu you can still boot into single mode by editing the startup entry. To do this in grub, while in the menu press &#8216;e&#8217; this will let you edit the menu entries. Just append single to the line starting with kernel. press &#8216;b&#8217; and the system will boot into single mode.<br />
If your boot manager is Lilo you can pass Linux 1 or Linux emergency as boot parameters.<br />
This approach won&#8217;t help you on all systems because many systems will ask you for the root password when booting into single user mode.(Debian does)</p>
<h2>3. boot to root shell by using shell as init</h2>
<p>If the single user mode has been disabled or is password protected just press &#8216;e&#8217; in the grub boot menu and add init=/bin/bash (or any other shell executable) to the kernel line. Press &#8216;b&#8217; to boot and you&#8217;ll get a root shell because the init process is replaced with bash while booting. This gives you a rather limited shell but it&#8217;s good enough, depending on your system configuration you might have to mount the root partition read/write before you can change the password. Do this by entering</p>
<p>#mount -no remount,rw /</p>
<p>After that you can use passwd again as in previous examples.</p>
<p>If your startup manager is Lilo you can give the boot parameters Linux init=/bin/bash</p>
<h2>4. boot from alternative file system</h2>
<p>This method is much less likely to be available as it requires some kind of &#8220;alternative file system&#8221; to be available. If you have non-root access and there is a writable partition (/tmp for instance) and you can place a linux file system relative to that partition for instance by downloading a minimal linux distro and unpacking it you can then give the root= option to grub and set the partition where you placed your own file system as root file system.<br />
Executing the mount command will show the available partitions and how they are mounted. This will only work in very specific circumstances though.</p>
<h2>5. boot from a bootable usb stick</h2>
<p>If you have no way to access single user mode from the boot menu, or if your single user mode is password protected, you can still use an alternative boot medium. Many systems these days provide a boot option for booting from a usb stick. This is actually a very easy method. The access of boot sequence menu differs by system, most systems display a text like press esc to enter boot menu or something like that. Sometimes the system is already configured to try booting from removable medium first. Many systems also allow changing the boot sequence from the bios. Just change the boot sequence of the system to boot from usb or choose that option from the boot menu. This does require you to have a boot-able usb stick of course. There are many ways to make a usb stick boot-able one of them is described in my article about backtrack, which makes a great distro to use for this purpose by the way. Just boot from the usb device, and open a root shell. The next thing you have to do is find out which is the root partition. Use fdisk to list the available partitions:</p>
<p>#fdisk -l</p>
<p>This will show the disks available.<br />
You can mount them with the mount command. First create a directory mkdir /newdir or mount the partition on an existing directory. Then mount the partition you think is the root.</p>
<p>#mount -o,rw /dev/hda1 /newdir</p>
<p>if mount complaints you have to specify partition type, you find the type as a letter/number combination where it says Id. To show a list of partition type name/Id combinations use /sbin/sfdisk -T</p>
<p>in this case use mount with -t option:</p>
<p>#mount -o,rw -t ext3 /dev/hda1 /newdir</p>
<p>check if it&#8217;s the right one with ls:</p>
<p>#ls /newdir  (should list a root filesytem)</p>
<p>if it is the wrong partition, just do umount /newdir to unmount it and redo the previous steps with another partition from the list.</p>
<p>If it is the right partition use chroot:</p>
<p>#chroot /newdir</p>
<p>this will make the newdir your root dir</p>
<p>and then enter passwd to change the root password and reboot your system.</p>
<h2>6. boot from CD</h2>
<p>This is basically the same as option 5 but requires you to have a Linux live-cd or rescue-cd. Most linux installation cd&#8217;s double as recovery cd&#8217;s by giving you a rescue option at boot or some drop to root shell menu option anywhere in the process. You do need to have a cd/dvd player installed to use this option. The method is exactly the same as in option 5. There are a lot more systems that allow booting from cd/dvd (most older pc&#8217;s do) than from usb this makes it a more viable approach.</p>
<h2>7. boot from network</h2>
<p>Difficult to do in many cases, but if you have access to the bios or the system is already configured to try booting from the network, and you have a system which you can configure as a boot server, it&#8217;s more or less the same story as 5 and 6. Boot the system into a OS where you have root access and mount the disk, chroot and you are in.</p>
<p>If you can&#8217;t access the BIOS to change the boot sequence because it&#8217;s password protected, try searching Google for the master password for your BIOS. Or you can try removing the BIOS battery the BIOS battery is located on the motherboard and is there to keep the BIOS memory as the power is taken of the system. Unplug the system, remove the battery and wait for about 120 seconds. Be warned this will flush all BIOS information (configuration) most systems will boot fine when you reload default BIOS settings (not all). Some motherboards have jumpers for resetting BIOS, if you have the motherboard manual you can look it up. Laptops are sometimes equipped with security features which make flushing BIOS impossible or even render the system completely useless when trying to reset BIOS.</p>
<h2>8. place an extra disk in the machine</h2>
<p>In most cases the BIOS will auto-detect a new disk, so if you place a new disk containing a boot-able OS and make it the master and the old disk slave, you can make the system boot from the new disk.</p>
<h2>9. remove the disk and place it in another machine</h2>
<p>If you can&#8217;t do any of the above you can always take out the disk and place it in another Linux system. Than you can mount it, chroot to the disk and again use passwd to change the root password. Place back the disk and start the machine.</p>
<h2>10. Try to gain root trough known vulnerabilities</h2>
<p>If the system has been running for a long time (or not running) without anyone maintaining it, there&#8217;s a change it&#8217;s running a vulnerable service. This would probably take a lot of time to do. Try fingerprinting the system for running network services that have not been security patched. If there is a easy root exploit to run against the machine it might be possible to get in this way.</p>
<h2>Securing your system</h2>
<p>Securing yourself against all these options is very difficult. You can remove all removable medium drives, CD/DVD, diskette, fill your usb ports with glue, passwords on everything. The only real protection is encrypted disks on every device you can&#8217;t keep in a secure environment. If someone gains unattended physical access to your systems they have access to your data.</p>
<p>What you can do is make it very difficult, secure access to your computers as much as you think is appropriate considering the sensitivity of your data. When it comes to mobile devices, laptops netbooks and the like you should carefully consider what would happen if it gets lost or stolen and someone has access to all your data. Very good Encryption programs are freely available for Linux and you can even choose to encrypt your whole system, in some distributions this is an install option.</p>
<p>Think there is more to try? Easier ways? Think there are better ways to protect against it? Mistakes? Leave a comment. It can take a while before comments are published(different time zone)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/10-ways-of-resetting-a-lost-linux-root-password/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle User Privilege Escalation</title>
		<link>http://www.whatsmypass.com/oracle-user-privilege-escalation</link>
		<comments>http://www.whatsmypass.com/oracle-user-privilege-escalation#comments</comments>
		<pubDate>Thu, 30 Oct 2008 06:44:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Oracle Corp;]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=366</guid>
		<description><![CDATA[An Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB. This [...]]]></description>
			<content:encoded><![CDATA[<p>An Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB.</p>
<p>This paper will show how the issue can be exploited and most importantly how to secure against it. This is an original vulnerability affecting current versions of the DB and please note that Oracle Corp’s Security Department have already been informed in accordance with ethical procedures and have given their permission to publish.</p>
<p>Proof of concept code tested on 10.1, 10.2 and 11g on both Linux and Windows and is available below.</p>
<p><a href="http://www.oracleforensics.com/wordpress/wp-content/uploads/2008/10/create_any_directory_to_sysdba.pdf">Here is the paper.</a></p>
<p><a href="http://www.oracleforensics.com/wordpress/wp-content/uploads/2008/10/createdirectory2sysdba.sql">Here is the code.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/oracle-user-privilege-escalation/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KeyCarbon USB Keylogger</title>
		<link>http://www.whatsmypass.com/keycarbon-usb-keylogger</link>
		<comments>http://www.whatsmypass.com/keycarbon-usb-keylogger#comments</comments>
		<pubDate>Thu, 09 Oct 2008 04:25:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[internet activity]]></category>
		<category><![CDATA[James Bond]]></category>
		<category><![CDATA[keyboard logger]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[logger]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[NEC DISPLAY 1091011 DSX INTRAMAIL 4-PORT 8-HOUR VOICE - - Phone]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[Private]]></category>
		<category><![CDATA[stable tool]]></category>
		<category><![CDATA[Texas instruments]]></category>
		<category><![CDATA[text editor]]></category>
		<category><![CDATA[USB port]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=285</guid>
		<description><![CDATA[I had a chance to review the Keycarbon USB Home Mini this week. I&#8217;ve been wanting to try one of these to see how they would compare to a PS/2 keyboard logger, PS/2 is still pretty popular as far as cheaper keyboards but the shift in technology is going more towards USB keyboards. I was [...]]]></description>
			<content:encoded><![CDATA[<p>I had a chance to review the <a href="http://www.keycarbon.com/products/keycarbon_usb/overview/">Keycarbon USB Home Mini</a> this week. I&#8217;ve been wanting to try one of these to see how they would compare to a PS/2 keyboard logger, PS/2 is still pretty popular as far as cheaper keyboards but the shift in technology is going more towards USB keyboards. I was pretty impressed by the quality of the keylogger and its simple installation.<center><br />
<a href="http://keycarbon.com/products/keycarbon_usb/overview/"><img src="http://www.keycarbon.com/images/products/keycarbon_usb/seo_usb_keyloger_install.gif" alt="" /></a><br />
</center><br />
Who would need a device like this?</p>
<ul>
<li>Business owners needing to monitor employees</li>
<li>Parents needing to monitor children</li>
<li>People who might need backups of things they type (writers etc)</li>
<li>Private investigators, law enforcement, hackers, James Bond <img src='http://www.whatsmypass.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ul>
<p>Why would someone want a hardware keylogger as opposed to a software based one? Well this question has it&#8217;s pros and cons:</p>
<p>The pros are:</p>
<ul>
<li>It&#8217;s dead simple to install , just unplug the keyboard,plug this device in , and plug the keyboard into the device ,that&#8217;s it!</li>
<li>No need for root/admin level permissions to install</li>
<li>It can be installed on any system that has a USB port (Windows,Mac,Linux etc)</li>
<li>Since it&#8217;s hardware-based it wont be detected by antivirus/malware programs ever</li>
<li>It picks up EVERYTHING typed, even bios password passwords and log-ons</li>
</ul>
<p>The cons are:</p>
<ul>
<li>Since it doesn&#8217;t interact with the operating system it can&#8217;t get the name of windows where the text was typed so it makes it a chore to scan the logs for the juicy information</li>
<li>Easy to prevent logging by just removing the logger form the computer (which most people won&#8217;t be aware of anyhow, who actually crawls behind their computer everyday?)</li>
<li>Recovery of logs might be more difficult because they are stored physically on the device and not sent to a remote location. But if you were able to install it in the first place , then recovering it shouldn&#8217;t that much harder.</li>
<li>If the person has a PS/2 keyboard you can&#8217;t use an adapter because the device needs power from the USB port to work</li>
</ul>
<p>Recovering the logs from the device can be done on any computer even though they offer the software to recover the logs faster, it&#8217;s not needed which makes this device a good tool to have in your arsenal. To recover the logs alls you you need to do is open any text editor (notepad etc&#8230;) and type in the password (default password is phxlog) and the device goes into menu mode, where you have a few options to choose<br />
you have open so it&#8217;s best to open notepad or wordpad or any *nix/MAC equivalent before typing this. This menu will give you various options for the device ,which are:</p>
<ol>
<li>Partial/Full Log download</li>
<li>Erase logs (quick or thorough)</li>
<li>Setting the default password (alphanumeric only,under 17 chars)</li>
<li>Firmware upgrade</li>
<li>Diagnostics</li>
<li>Speed (that the logs are typed)</li>
</ol>
<p>Once you choose read the logs it starts auto typing the logs onto whatever window is open has the main focus (which is why you need to open a text editor).  If you don&#8217;t like to wait for it to auto-type (you might have days of saved logs) you can get the software to download it in one swoop. The only problem with the software that as of now it&#8217;s only compatible with windows.</p>
<p>Detection of the Device:</p>
<p>Because the device doesnt install into the operating system its pretty much insvisible to the normal user. Only a trained computer expert would notice the device it because the only sign it&#8217;s there is that it is seen as a USB hub by the OS. It shows up as a &#8220;generic 4 port hub Vid_0451&amp;Pid_2046&#8243; Vendor id of 0451 and a product id of 2046, which comes up as a generic <a href="/images/keylogger.jpg">Texas instruments device</a> which wont raise many eyebrows. Because it&#8217;s a USB 1.1 hub it is possible that it may be discovered if someone  plugs a USB 2.0 keyboard inline with it. (They might get a warning message  telling them that their device can perform at a higher speed if they use a  different port.) But the chances are slim of someone needing to replace their keyboard.</p>
<p>All in all this device is a stable tool to use, it logged with no problems at all with every keyboard/OS i used with it.  Although the price is a little high for most people, it&#8217;s well priceless for businesses who need to keep an eye on employees, or a parent who needs to monitor their children&#8217;s internet activity. I want to thank <a href="http://keycarbon.com">Keycarbon</a> for giving me the opportunity to review and test this device. Check out their site for other devices they offer that I didn&#8217;t get to review , but are another great alternative to stealth hardware logging.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/keycarbon-usb-keylogger/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bypass IPhone Voicemail Password</title>
		<link>http://www.whatsmypass.com/bypass-iphone-voicemail-password</link>
		<comments>http://www.whatsmypass.com/bypass-iphone-voicemail-password#comments</comments>
		<pubDate>Sun, 05 Oct 2008 18:50:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Password Info]]></category>
		<category><![CDATA[AT&T]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[VOIP]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=251</guid>
		<description><![CDATA[As you know AT&#38;T is the only carrier for IPhones (unless its jailbroken). For many people jumping on the IPhone craze do not know that the convenience of listening to your voicemail from your Iphone (or any AT&#38;T phone for that matter) is a huge hole. The AT&#38;T voicemail system is configured by default not [...]]]></description>
			<content:encoded><![CDATA[<p>As you know AT&amp;T is the only carrier for IPhones (unless its jailbroken). For many people jumping on the IPhone craze  do not know that the convenience of listening to your voicemail from your Iphone (or any AT&amp;T phone for that matter) is a huge hole. The AT&amp;T voicemail system is configured by default not to ask for a password when you check your voicemail from the handset (it asks for your voicemail password if you call your number from another phone and press * when your voicemail answers). <span id="more-251"></span>AT&amp;T uses the ANI (Automatic Number Identification) number of the phone dialing-in as verification to enter the voicemail box.  All one had to do was spoof the caller ID to the number of the phone and it lets you right into the voicemail without prompting for a password. There are alot of instructions on the &#8216;net to spoof caller ID, such as buying a spoofing calling card , or setting up your own Asterix linux box and using a VOIP provider.</p>
<p>Here is how to protect yourself from this vulnerability:</p>
<ol>
<li>Call your AT&amp;T/Cingular voicemail (dial your own number from the iPhone).</li>
<li>Press 4 to go to “Personal Options”.</li>
<li>Press 2 to go to “Administrative Options”.</li>
<li>Press 1 to go to “Password”.</li>
<li>Press 2 to turn your password “ON”.</li>
<li>Hang-up and call your voicemail again from your iPhone. If your voicemail system asks you for your voicemail password you are all set.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/bypass-iphone-voicemail-password/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>OphCrack Live CD &#8211; Crack Windows Passwords</title>
		<link>http://www.whatsmypass.com/ophcrack-live-cd-crack-windows-passwords</link>
		<comments>http://www.whatsmypass.com/ophcrack-live-cd-crack-windows-passwords#comments</comments>
		<pubDate>Sun, 21 Sep 2008 00:17:35 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Password Info]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Microsoft Vista]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=184</guid>
		<description><![CDATA[Ophcrack LiveCD is a free bootable Windows password cracking CD based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms. Features: » Runs on Windows, Linux/Unix, Mac OS X, &#8230; » Cracks LM [...]]]></description>
			<content:encoded><![CDATA[<div>Ophcrack LiveCD is a free bootable Windows password cracking CD based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms.</div>
<div></div>
<p><strong>Features:</strong><br />
» Runs on Windows, Linux/Unix, Mac OS X, &#8230;<br />
» Cracks LM and NTLM hashes.<br />
» Free tables available for Windows XP and Vista.<br />
» Brute-force module for simple passwords.<br />
» LiveCD available to simplify the cracking.<br />
» Loads hashes from encrypted SAM recovered from a Windows partition, Vista included.<br />
<span id="more-184"></span></p>
<p>Starting with version 2.3, Ophcrack also cracks NT hashes. This is necessary if generation of the LM hash is disabled (this is default for Windows Vista), or if the password is longer than 14 characters (in which case the LM hash is not stored).</p>
<p><a href="http://ophcrack.sourceforge.net/download.php?type=livecd">Download</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/ophcrack-live-cd-crack-windows-passwords/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

