Theft password from PC to 30 seconds or less

Rob Fuller, security researcher, published a simple way to steal passwords from locked Windows and OS X computers.

For the he needs:

Access to the target computer
A connected notebook that you have modified to impersonate a USB Ethernet adapter
and
a computer with software that will crack them to be intercepted.Password

The actual attack can be done in less than half a minute, as you will see in the video below.

"Why; Because USB is Plug-and-Play. This means that even if a system is locked, the it still works,” says Fuller.

"Right now, I think there are restrictions on the types of devices you can install on a locked computer with newer operating systems (Win10 / El Capitan), but Ethernet / LAN devices definitely work."

In his blog, tells how to set up a USB Armory or a Hak5 Turtle - two cheap ($ 155 and $ 49.99 respectively) USB-mounted Linux computers to use in attack.

Basically, they must be equipped with Responder, an open source software that simulates a control server ς. Το λειτουργικό σύστημα «αναγνωρίζει» το διακομιστή, και τον εμπιστεύεται εξ ορισμού, σαν να είναι στο τοπικό . It thus responds to the authentication request with the login credentials (passwords) recorded in a database.

To complete the attack, you must break the hashes of the stolen credentials. Different operating systems use different hashes, but all can be broken or downgraded to a form that can be used in attacks "Pass the hash."

Attack has been tested on various operating systems and OS versions. It works in Windows 98 SE, 2000 SP4, XP SP3, 7 SP1, and 10, as well as OS X El Capitan / Mavericks. It's not currently tested on Linux.

Watch the video and think the next time you lock your PC and think it's safe.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).