Feeds

Tool makes mincemeat of Windows passwords

This Firewire is out of control

Top 5 reasons to deploy VMware with Tegile

A security researcher has released an easy-to-use tool that accesses locked Windows computers in seconds without entering a password.

The tool, which was released Tuesday by Adam Boileau, works by connecting a Linux machine to the Firewire port of the target PC and modifying the password protection that's stored in local memory.

The attack exploits a well-known weakness in Firewire that makes it easy for connected devices to read and write to the memory of the host machine. Similar hacks work on machines running OS X and Linux (see here).

Of course, the attack depends on having physical access to the targeted machine, and as most El Reg readers know, anyone who has physical control of the PC owns it. Then again, password protections have been a useful way to briefly secure a machine while a user runs to the bathroom. Until now. As Boileau's tool makes clear, such protections can be bypassed in a matter of seconds.

The other potential shortcoming to the attack is that it requires the targeted machine to have an IEEE 1394 port, better known as Firewire. This might present a problem for those trying to attack an older machine, but as Firewire ports have grown in popularity (seven out of eight laptops had one in an informal survey of Reg machines), the requirement is becoming less and less of an issue.

It's the second attack in as many weeks to siphon information that's stored in a computer's random access memory. Previously, researchers documented a novel way to access files that presumably were locked using disk encryption by accessing a "ghost image" of the key stored on a computer's memory chips.

Boileau first demonstrated the Windows shortcoming at a 2006 conference. But until now he has stopped short of publicly releasing the tool because "Microsoft was a little cagey about exactly whether Firewire memory access was a real security issue or not and we didn't want to cause any real trouble." according to this article.

Now that Boileau has refocused attention on the attack, Microsoft is sure to point out that it's made possible by features built into the IEEE 1394 specification. That's true, but we're not sure that's enough to get Microsoft off the hook for failing to fix a weakness that's been in the public domain for at least two years.

After all, how hard could it be disable Firewire connections while a PC is locked? ®

Internet Security Threat Report 2014

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Choosing a cloud hosting partner with confidence
Download Choosing a Cloud Hosting Provider with Confidence to learn more about cloud computing - the new opportunities and new security challenges.