|
|||||||
| Specialist Topics Suggestions for topic sections welcome! |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||
|
im having a little trouble with this "challenge" my buddy gave me, he uses red hat (2.6 kernel) and the whole hard drive is encrypted except /boot/, which i could find out with backtrack by opening up the hard drive.. my question is what are the steps one would go through to get root on this machine, or some kind of trick to decrypt the hard drive, and view its files...total noob here on encryption but i thought i could find an experienced user here in the specialist section
|
|
|||
|
Step 1: Install a keystroke logger
Step 2: Wait for you friend to log on Step 3: Profit Full hard drive encryption is tough to deal with. Technically it is also vulnerable to password cracking attacks, but most encryption packages make it very expensive, (time consuming), to make a guess, and there just aren't many good tools out there to even try simple password guesses. |
|
|||
|
thats what i was thinking, when you guess passwords at the login screen, it takes about 5 seconds, so brute forcing would be time consuming even i could get a dictionary to automatically be typed in...
what im going toward is fighting the boot loader, he uses grub, and i can freely edit the grub config file, so would there be some kind of argument that gets me a shell right at boot time? |
|
||||
|
If he's using Truecrypt, you can use Evil Maid. It hooks the Trucrypt function that asks user for the passphrase, so that the hook records whatever passphrase is provided to this function.
Game. Set. Match
__________________
Thorn “Never try to teach a pig to sing; it wastes your time and it annoys the pig.” - Robert Heinlein |
|
||||
|
Quote:
Or you could just install coreboot with Grub Invaders and tell him that you wiped his hard disc . No, just kidding, don't mess with his bios
__________________
Auswaertsspiel |
|
||||
|
Quote:
__________________
Please visit the new forums for any and all help with Back Track 4 Final. BackTrack-Linux is the new home. |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|