Jump to content

Recommended Posts

Posted
being a quiet week with no one in but myself, I've been round the school resetting the bios password on all the machine and I found 5 unprotected by passwords. It may be worth your while to check your own school's machines.
Posted

Highly unlikely there is such a thing jwood.

 

I've set all of the bios passwords on any computers I've been at since starting work here 2 years ago, still find the odd one that hasn't got one though!

Posted

I doubt it too.

 

Personally I think any kid caught trying to get into a BIOS should get challenged as to what the hell they think they're trying to achieve.

 

There's too much emphasis on locking things down and not enough roastings for scruffy Asbo's who try to break stuff in the first place!

Posted

You can use CMOSPwd in a startup script to do this for any bios it supports.

 

http://www.cgsecurity.org/wiki/CmosPwd

 

You need to install the 'ioperm' service

 

ioperm -i

 

You need create a dump file for each type of bios you have.

 

cmospwd /d cmos_ami_dump.txt

 

 

Then you need to group machines per CMOS type. Once this is done you simply load the right dump file into each machine at startup. Group based security filtering is your friend here.

 

cmospwd /l cmos_ami_dump.txt

 

It's critical you keep on top of bios updates though. If you have disparate bios versions and attempt to load a dump file from another version bad things will happen, up to and including bricking your motherboard.

Posted
I doubt it too.

 

Personally I think any kid caught trying to get into a BIOS should get challenged as to what the hell they think they're trying to achieve.

 

There's too much emphasis on locking things down and not enough roastings for scruffy Asbo's who try to break stuff in the first place!

Why make it an either/or thing? Set the passwords so that they can't actually change anything, and then roast them for trying.

Posted
So you don't know about the backdoor passwords then?

 

Heh, some of those have saved me from having to open up cases in my time.......

Posted
Just tested on our iDesk computers - standard BIOSes and they wouldn't work... Don't tend to have any problems with kids trying to get into the BIOS anyway (smug)
Posted
None of those worked on my PCs...

 

and mine......

 

the problem with those kind of lists is that they're about 10 years old but get passed around in 'have you seen this....' kind of emails.

 

I'd bet that unless you have an old PC with an out of date BIOS that all of those are defunct.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...