Author Topic: How to get past a bios password on a target machine  (Read 1855 times)

0 Members and 1 Guest are viewing this topic.

Offline thepacifist

  • NULL
  • Posts: 3
  • Cookies: 0
  • ~Pacify hacking
    • View Profile
How to get past a bios password on a target machine
« on: October 18, 2014, 12:44:58 am »
Imagine this, you want to get in to a computer. You don't know the windows administrator password, but KonBoot should take care of that quite easily. The real problem is that you can't coot in to KonBoot because the boot order and bios are password protected. The obvious methods are resetting the motherboard jumper, or taking out the battery and waiting a bit. But you want to do it inconspicuously without turning the PC on its side and opening it up in front of dozens of people. You have access to a basic user account. How would you gain access to that computer?
~The Pacifist

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #1 on: October 18, 2014, 05:43:03 am »

Many BIOS's have default passwords.

Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Re: How to get past a bios password on a target machine
« Reply #2 on: October 18, 2014, 07:44:37 am »
metasploit/other priv esculation attacks.  GO introduce yourself.

That doesn't necessarily mean you can do it from within the OS. Most BIOS's can only be set/changed during boot. Some, however, like toshiba have a tool called HWSetup or something similar that can be used.

A BIOS update might remove the password, but I haven't tried it.

Simply having admin rights on a computer does absolutely nothing, and is bad advice, you should feel bad.

Resetting or removing the battery is the best and most effective option. You have to remember, the BIOS starts and controls whether or not the actual OS will boot in the first place. The OS has nothing to do with it.
>>>import this
-----------------------------

Offline thepacifist

  • NULL
  • Posts: 3
  • Cookies: 0
  • ~Pacify hacking
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #3 on: October 18, 2014, 03:33:22 pm »
Thanks. They're intel motherboards so I'll see if there is a default password or one of the aforementioned tools.
~The Pacifist

Offline Darkcast

  • /dev/null
  • *
  • Posts: 5
  • Cookies: 0
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #4 on: October 19, 2014, 08:50:42 am »
Depending on the model of the hardware their could safety precautions for example the password could be burn into the motherboard and the only way to reset it is with a passkey

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: How to get past a bios password on a target machine
« Reply #5 on: October 19, 2014, 08:22:27 pm »
Most BIOS can be defeated with rainbow tables attacks.

Offline mohittiwari009

  • NULL
  • Posts: 1
  • Cookies: 0
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #6 on: October 24, 2014, 03:36:26 am »
I have seen a device....like com port connector....you can make it yourself and can plug into your com port or VGA port to short the BIOS WITHOUT OPENING THE CASE

You can use YouTube to make this port
« Last Edit: October 24, 2014, 08:21:11 am by Kulverstukas »

Offline voodoo

  • Serf
  • *
  • Posts: 42
  • Cookies: 4
  • Try Harder
    • View Profile
    • Security Voodoo
Re: How to get past a bios password on a target machine
« Reply #7 on: October 24, 2014, 07:11:38 am »
There is a jumper on the motherboard.  Bridging the connection will circumvent the bios password.  Physical access and its game over.
keep it simple

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #8 on: October 24, 2014, 10:26:11 am »
If using the jumper on the motherboard/removing the CMOS doesn't work, can you tell me what machine it is? Sometimes there are keyboard inputs that you can put in on boot to reset/negate BIOS passwords.
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001

Offline FinalFrontier

  • /dev/null
  • *
  • Posts: 15
  • Cookies: 0
  • | Internets Most Holy.
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #9 on: October 29, 2014, 07:23:05 pm »
I think we are in the same seat on this one, but I would like to expand my problem.
My school has a system where by when you want to log into the computer you write you usr&pass and it
connects to a server from where it fetches your user.
They have the computers chassis locked and the bios has a password protect so I can't access the boot order and
boot form ... lets say Kon.
What can I do? And can Kon deal with the fetching from a server part?
Nortcele didn't like my | I'm new.

Offline d3crypt

  • NULL
  • Posts: 4
  • Cookies: 0
  • Hackers of the world unite!!!
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #10 on: October 30, 2014, 03:03:33 am »
At the risk of sounding like an idiot, is there any risk to damaging a computer by doing this?

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #11 on: October 30, 2014, 10:54:21 am »
At the risk of sounding like an idiot, is there any risk to damaging a computer by doing this?

Not really, but there is always a chance of corruption in files/making a mistake shouldn't be too much to worry about though :)
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #12 on: October 30, 2014, 10:54:56 am »
I think we are in the same seat on this one, but I would like to expand my problem.
My school has a system where by when you want to log into the computer you write you usr&pass and it
connects to a server from where it fetches your user.
They have the computers chassis locked and the bios has a password protect so I can't access the boot order and
boot form ... lets say Kon.
What can I do? And can Kon deal with the fetching from a server part?

Why do you need to do this?
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001

Offline FinalFrontier

  • /dev/null
  • *
  • Posts: 15
  • Cookies: 0
  • | Internets Most Holy.
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #13 on: October 30, 2014, 02:54:04 pm »
Why do you need to do this?
Just because, I do not want to inflict damage, just wanna play around alittle. ;)
Nortcele didn't like my | I'm new.

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How to get past a bios password on a target machine
« Reply #14 on: October 30, 2014, 03:14:56 pm »
-.-
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001