Original URL: http://www.theregister.co.uk/2006/04/25/stolen_laptop_peril/
Infosec As web apps are becoming more secure stolen laptops have become among the easiest ways to break into corporate networks. High profile firms such as Fidelity and Ernst and Young along with celebrities such as Kevin Costner have lost laptops over recent months. Concern over these thefts has focused on the exposure of data left on these devices. But the potential to use stolen kit to lift user credentials also poses a grave risk.
During a presentation at Infosec on Tuesday, penetration testing firm SecureTest explained how DIY hardware devices or software available for purchase from eBay might be used to reset or circumvent passwords set in a laptop's BIOS. "If that fails you can always take the drive out and fit it with a USB connector," explained SecureTest's Rob Pope.
A Linux tool called Backtrack, which can run from a CD loaded onto a Windows PC, might then be used to get system keys and password hashes. Windows stores the hashes of passwords derived from the LM algorithm instead of directly storing passwords. But LM encryption is weak and susceptible to brute force attack using Rainbow Crack or other tools.
SecureTest pre-computed a rainbow table of password hashes totaling 19GB. Thereafter obtaining the plain text of a password becomes a simple job of matching password hashes. Most of the hacker tools in this area are American so the inclusion of a pound sign in passwords is capable of frustrating attacks.
Next up SecureTest showed how a program called Disk Investigator might be used to extract the encrypted form of WEP key passwords or remote desktop login credential from a Windows Registry file. It showed how a program called Cain was able to decode Cisco VPN client passwords given access to a purloined corporate PC. "What we find during penetration testing is that most passwords are based either around the Lord of The Rings, the names of planets or Star Wars," said Pope.

SecureTest md Ken Munro outlined a number of defences firms might employ against the attacks the firm highlighted. Although not foolproof, use of BIOS passwords is a significant barrier against attack. Firm should avoid setting up machines that can be booted from USBs, floppy discs, CD ROMs or from a network. Strong passwords contained a mix of alphanumeric characters should be used. Finally firms should implement either disc encryption or, at minimum, the encryption of sensitive files, Munro advised. ®
British Gas security scare as payments page springs a leak (4 May 2007)
http://www.theregister.co.uk/2007/05/04/british_gas_payments_security/
Security flap as Scottish council loses USB key (21 March 2007)
http://www.theregister.co.uk/2007/03/21/perth_council_usb_loss/
Nationwide fined £980,000 over stolen laptop (14 February 2007)
http://www.theregister.co.uk/2007/02/14/nationawide_fined/
'Contact us' attack takes out mail servers (1 February 2007)
http://www.theregister.co.uk/2007/02/01/web_form_dos_risk/
US.gov looks to crypto to plug data leak holes (29 December 2006)
http://www.theregister.co.uk/2006/12/29/us_data_encryption_comp/
Disk drive researchers turn up IDs, child porn (15 August 2006)
http://www.theregister.co.uk/2006/08/15/data_scavenging/
Networking sites could help hackers (14 July 2006)
http://www.theregister.co.uk/2006/07/14/networking_site_risk/
USB drives pose insider threat (27 June 2006)
http://www.theregister.co.uk/2006/06/27/usb_drives_security_threat/
Ernst & Young laptop loss exposes 243,000 Hotels.com customers (1 June 2006)
http://www.theregister.co.uk/2006/06/01/ey_hotels_laptop/
Ancient worm runs riot at Infosec (2 May 2006)
http://www.theregister.co.uk/2006/05/02/infosec_insecurity/
Early days of dial-up hacking recalled (27 April 2006)
http://www.theregister.co.uk/2006/04/27/infosec_blog_six/
BitLocker gives dual-boot systems the elbow (27 April 2006)
http://www.theregister.co.uk/2006/04/27/schneier_infosec/
PGP unfazed by MS disk encryption (26 April 2006)
http://www.theregister.co.uk/2006/04/26/pgp_infosec/
Afghan market sells US military flash drives (18 April 2006)
http://www.theregister.co.uk/2006/04/18/afghan_market_security_breach/
Fidelity lost HP's employee data to impress HP (24 March 2006)
http://www.theregister.co.uk/2006/03/24/hp_fidelity_laptop/
40,000 BP workers exposed in Ernst & Young laptop loss (23 March 2006)
http://www.theregister.co.uk/2006/03/23/ey_bp_laptop/
Forgotten password clues create hacker risk (20 March 2006)
http://www.theregister.co.uk/2006/03/20/forgotten_password_security_risk/
Hotel hacking could pump smut into every room (22 August 2005)
http://www.theregister.co.uk/2005/08/22/hotel_hacking_reloaded/
MoD suppliers' laptop turns up on rubbish tip (26 April 2005)
http://www.theregister.co.uk/2005/04/26/tip_secret_laptop/
© Copyright 2008