Penetration Testing mailing list archives

RE: Stealing Password from BIOS


From: "Password Crackers, Inc." <pwcrack () pwcrack com>
Date: Fri, 26 Jun 2009 11:08:07 -0400

-----Original Message-----
From: listbounce () securityfocus com 
[mailto:listbounce () securityfocus com] On Behalf Of Jon Kibler
Sent: Friday, June 26, 2009 6:30 AM
To: pen-test () securityfocus com
Subject: Stealing Password from BIOS

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

A couple of years back I saw a tool illustrated at a 
conference that would pull the encoded password from BIOS. 
However, Google fails to show any such tool.

Note that I am not trying to clear/reset the password. What I 
want to do is to recover a BIOS password during a pen-test so 
I can reboot the box at will without making any changes to the box.

Any pointers greatly appreciated.

Jon

Try searching for CMOS password on Google.  There were many results
including cmospwd.

Bob Weiss
President
Password Crackers, Inc.
http://www.pwcrack.com/


------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: