Jump to content

Recommended Posts

Posted

Have a couple of likely lads in my office at the moment trying to break my test windows 7 build.

 

Their plan is to boot from their own CD but of course the CD drive is not set to be bootable in the BIOS and the BIOS is password protected.

 

They think they can find a backdoor bios password....

 

Is this likely?

 

The BIOS is an award type.

 

Found this:

HOW TO BYPASS BIOS PASSWORDS

 

Which kind of supports their route in....

 

Worrying?

Posted (edited)

It sounds doable, at the very least they can open up the PC and reset the bios that way with the jumpers. I guess unless you pad lock it. Once in it’s a simple matter of using a boot CD to remove the windows passwords.

 

You could surprise them by having the hard disk encrypted.

Edited by Pottsey
Posted

jebus that website is OLD - I was giggling at the use of terms like "CMOS RAM" (heh?) then my giggles turned serious when they mentioned AT and XT machines. None of the standard passwords listed there will work in anything from the last 15 years.

There *are* backdoor passwords though, without giving too much away these days most of them are algorithmically based on serial numbers, manufacturer IDs etc.

 

Anyway, sooner the BIOS is dead the better :D long live UEFI!

Posted
Their plan is to boot from their own CD but of course the CD drive is not set to be bootable in the BIOS and the BIOS is password protected.

If they can obtain the checksum/hash of your BIOS password (trivial on many makes of computer) then it's actually quite simply to bypass your BIOS password using the script on the following website. I have tried it myself and it does work. :(

 

http://dogber1.blogspot.com/2009/05/table-of-reverse-engineered-bios.html

 

When a laptop is locked with password, a checksum of that password is stored to a sector of the FlashROM - this is a chip on the mainboard of the device which also contains the BIOS and other settings, e.g. memory timings. For most brands, this checksum is displayed after entering an invalid password for the third time.

 

 

the CD drive is not set to be bootable in the BIOS

Did you also disable booting from USB and PXE? If they knew what they were doing of, it wouldn't be too difficult to setup tftpd32 on another PC, network boot the machine they wish to compromise and then do whatever they want to it e.g. run DBAN. :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...