Penetration Testing mailing list archives

Stealing Password from BIOS


From: Jon Kibler <Jon.Kibler () aset com>
Date: Fri, 26 Jun 2009 06:30:07 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

A couple of years back I saw a tool illustrated at a conference that
would pull the encoded password from BIOS. However, Google fails to show
any such tool.

Note that I am not trying to clear/reset the password. What I want to do
is to recover a BIOS password during a pen-test so I can reboot the box
at will without making any changes to the box.

Any pointers greatly appreciated.

Jon
- --
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
c: 843-813-2924 (NEW!)
s: 843-564-4224
http://www.linkedin.com/in/jonrkibler

My PGP Fingerprint is:
BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkpEoy4ACgkQUVxQRc85QlN5HQCfb2jT41sK1Mcden1wxIPUxE7U
xm4AniAmWA0RV8pgXSltasRkEfPW8Iws
=fUGe
-----END PGP SIGNATURE-----




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.


------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------

Current thread: