Jump to content

One Of The Not So Well Know Feature Of Vista:


Recommended Posts

Guest Reimar
Posted

As good as the recovery console is in Windows-it really aint that secure at all. Did you know that the Command Prompt tool found in Vista’s System Recovery Options doesn’t require a User Name or Password? And that the Command Prompt provides Administrator level access to the hard drive? For multiple versions of Windows? All you need is a Vista Install DVD and you’re all set to go.

Just boot from the DVD and select the Repair option, then select the Command Prompt!

Here you have full access to this computer, not only as an administrator but also as a system account user. After this you can insert usb-memory and copy any non-encrypted file from this computer to usb-memory and steal information without leaving any marks to the system or event viewer logs.

Also, you could for example copy SAM-file (contains names and passwords of local users) from c:\windows\system32\config to usb-memory and start cracking computer’s user password at remote computer.

A cracker can:

1. … copy files from hard disk to USB, floppy or network server

2. … create / modify / delete files and folders

3. … use most of the MS-DOS like commands

4. … use this method in Vista, XP, 200x

To protect you computer or workstation, try to:

setup bios boot order so that booting from other media than hard disk is not possible

setup startup password from your bios (mainly in home computers)

use hard disk encryption software, if possible (such as bit locker)

encrypt files and folders using EFS, if mechanisms above are not possible

This kind of reminds you of a Windows XP Home feature. The Administrator account password for XP Home is blank by default and is hidden in Normal Mode. But if you select F8 during boot for Safe Mode, you can access the Administrator account and have complete access to the computer.

Source

Posted
A cracker can:

1. … copy files from hard disk to USB, floppy or network server

2. … create / modify / delete files and folders

3. … use most of the MS-DOS like commands

4. … use this method in Vista, XP, 200x

Have had access to this technology for years via ERD Commander (acquired by MS in July 2006) and a wide assortment of other boot disks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.



×
×
  • Create New...