<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post7985619398289727565..comments</id><updated>2009-07-23T23:52:43.590-07:00</updated><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Bypassing a Windows login password in order to boo...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/7985619398289727565/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-756376357149297510</id><published>2009-07-23T23:52:43.590-07:00</published><updated>2009-07-23T23:52:43.590-07:00</updated><title type='text'>Thanks you very much  for this useful information....</title><content type='html'>Thanks you very much  for this useful information.&lt;br /&gt;Please keep on blogging.&lt;br /&gt;I am looking forward to read your next great article.&lt;a href="http://www.alkemi.com.au/" rel="nofollow"&gt;SEO&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/756376357149297510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/756376357149297510'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1248418363590#c756376357149297510' title=''/><author><name>Tauqeer</name><uri>http://www.blogger.com/profile/05829038056997522031</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3382940391542561938</id><published>2009-06-10T18:34:10.944-07:00</published><updated>2009-06-10T18:34:10.944-07:00</updated><title type='text'>This was a pleasure to read. Thank You!</title><content type='html'>This was a pleasure to read. Thank You!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/3382940391542561938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/3382940391542561938'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1244684050944#c3382940391542561938' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3946486164295446770</id><published>2008-05-06T09:55:13.518-07:00</published><updated>2008-05-06T09:55:13.518-07:00</updated><title type='text'>http://www.youtube.com/v/CmA2oily65A</title><content type='html'>http://www.youtube.com/v/CmA2oily65A</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/3946486164295446770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/3946486164295446770'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1210092913518#c3946486164295446770' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08464705455452496935'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3334979087126839581</id><published>2008-05-06T08:29:26.271-07:00</published><updated>2008-05-06T08:29:26.271-07:00</updated><title type='text'>Frizzi,That is a very *strong* statement, and not ...</title><content type='html'>Frizzi,&lt;BR/&gt;&lt;BR/&gt;That is a very *strong* statement, and not entirely true. I have tested this and there are a couple of conditions that exist that allow you to access the EFS data using the techniques I described, and then ther are some conditions in which you can't.&lt;BR/&gt;&lt;BR/&gt;I had not yet updated the blog to include them since I discovered them after my intial comment about being able to access EFS data. &lt;BR/&gt;&lt;BR/&gt;You are correct that if a user has a password set and then encrypts some data using EFS then using the above technique does not give you access to the EFS data. &lt;BR/&gt;&lt;BR/&gt;You are incorrect that if a user does not initialy have a password set then encrypts some data, then sets a password, the above technique will work. &lt;BR/&gt;&lt;BR/&gt;Thanks for your comments</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/3334979087126839581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/3334979087126839581'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1210087766271#c3334979087126839581' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08464705455452496935'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-580917342990404958</id><published>2008-05-06T03:21:20.329-07:00</published><updated>2008-05-06T03:21:20.329-07:00</updated><title type='text'>you CANNOT access EFS encrypted files on XP and Vi...</title><content type='html'>you CANNOT access EFS encrypted files on XP and Vista if you hex edit the SAM and do the 0x14 to 0x04 SAM conversion trick.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/580917342990404958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/580917342990404958'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1210069280329#c580917342990404958' title=''/><author><name>Frizzi</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4186168543689308133</id><published>2008-04-15T02:06:22.414-07:00</published><updated>2008-04-15T02:06:22.414-07:00</updated><title type='text'>I did some followup testing on this and found that...</title><content type='html'>I did some followup testing on this and found that when there are encrypted files using the EFS feature, and a password is set on the user account, you can use the technique I described to bypass the password and you can STILL GET ACCESS to the encrypted files!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/4186168543689308133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/4186168543689308133'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1208250382414#c4186168543689308133' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08464705455452496935'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5850768175806055648</id><published>2008-03-28T06:14:11.692-07:00</published><updated>2008-03-28T06:14:11.692-07:00</updated><title type='text'>Another (simple) way to get around user authentica...</title><content type='html'>Another (simple) way to get around user authentication is to use Dreampack : http://www.d--b.webpark.pl/dreampackpl_en.htm&lt;BR/&gt;&lt;BR/&gt;To make it even more convenient there's a plugin to use it with BartPE.&lt;BR/&gt;&lt;BR/&gt;Works flawless with XP, haven't tried it with VISTA yet...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/5850768175806055648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/5850768175806055648'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1206710051692#c5850768175806055648' title=''/><author><name>Christian</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2297745309702691924</id><published>2008-03-16T08:51:28.206-07:00</published><updated>2008-03-16T08:51:28.206-07:00</updated><title type='text'>Jeff,I knew I felt a presence in the darkness ;)Th...</title><content type='html'>Jeff,&lt;BR/&gt;&lt;BR/&gt;I knew I felt a presence in the darkness ;)&lt;BR/&gt;&lt;BR/&gt;That's a good question. I have never had the need to get access to protected storage this way so I have not tested it, but it would be a simple thing to test. As soon as I get a little time to test, I will post the results.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/2297745309702691924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/2297745309702691924'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1205682688206#c2297745309702691924' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08464705455452496935'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-104019914155065337</id><published>2008-03-15T10:11:39.919-07:00</published><updated>2008-03-15T10:11:39.919-07:00</updated><title type='text'>Long time e-stalker, first-time poster...Utilizing...</title><content type='html'>Long time e-stalker, first-time poster...&lt;BR/&gt;&lt;BR/&gt;Utilizing the second method you described - telling Windows that no password is set for a given account - will this method disallow you from accessing the protected storage when doing a live boot?  I know that blanking the password value would have this effect, but I'm curious what would happen if the password hash remains and you use a utility to dump the protected storage.&lt;BR/&gt;&lt;BR/&gt;Thanks!  And great blog, BTW.&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;Jeff</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/104019914155065337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/104019914155065337'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1205601099919#c104019914155065337' title=''/><author><name>Jeffrey</name><uri>http://www.blogger.com/profile/07560213599990360565</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5299149555893782998</id><published>2008-02-22T21:39:50.732-08:00</published><updated>2008-02-22T21:39:50.732-08:00</updated><title type='text'>Awesome stuff as usual. Thanks for the link to 'be...</title><content type='html'>Awesome stuff as usual. Thanks for the link to 'beginningtoseethelight', I have never seen this before.&lt;BR/&gt;&lt;BR/&gt;Cheers.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/5299149555893782998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7985619398289727565/comments/default/5299149555893782998'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html?showComment=1203745190732#c5299149555893782998' title=''/><author><name>Paul Bobby</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7985619398289727565' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7985619398289727565' type='text/html'/></entry></feed>