Thursday, September 13, 2012
Accessing System Setup (BIOS) and Backdoor Passwords - Part 2
You can try some methods suggested here:
Click on the link below and try the method mentioned under section “By Using MS DOS Command”:
http://www.askvg.com/how-to-reset-remove-bypass-a-bios-or-cmos-password/
BIOS/CMOS Password Recovery Tool ($24.95)
http://www.biospasswordrecovery.com/
CmosPwd tool (freeware)
http://www.majorgeeks.com/CmosPwd_d239.html
CmosPwd is a CMOS BIOS password recovery tool.
Use Hiren’s Boot CD
http://www.hirensbootcd.org/download/
You need to burn it on CD or you can create a bootable USB flash drive of this tool.
This video shows how to use it Hiren's Boot CD:
How to remove a Bios Password using the Hiren’s BootCD 15.1
http://www.youtube.com/watch?feature=player_embedded&v=uY0wZMqNzmw
Accessing System Setup (BIOS) and Backdoor Passwords - PART 1
The BIOS/CMOS password can be reset most of the time by just taking out the battery from the motherboard for a few hours, sometimes only 15 mins. This can be a bit tricky on a laptop, so be careful.
If you bought a used computer chances you do not know the password to your system setup or to your BIOS. Many BIOS makers include a backdoor password that can let you get in. This list has some of the most common backdoor passwords to the BIOS and is intended for legitimate use only:
NOTE: Do not try to guess the password on a passworded Hard Drive. 3 wrong guesses will often result in the information on the hard drive being lost forever.
BACKDOOR PASSWORDS
Award BIOS
ALFAROME
ALLy
aLLy
aLLY
ALLY
aPAf
_award
AWARD_SW
AWARD?SW
AWARD SW
AWARD PW
AWKWARD
awkward
BIOSTAR
CONCAT
CONDO
Condo
d8on
djonet
HLT
J64
J256
J262
j332
j322
KDD
Lkwpeter
LKWPETER
PINT
pint
SER
SKY_FOX
SYXZ
syxz
shift + syxz
TTPTHA
ZAAADA
ZBAAACA
ZJAAADC
01322222
589589
589721
595595
598598
AMI BIOS
AMI
AAAMMMIII
BIOS
PASSWORD
HEWITT RAND
AMI?SW
AMI_SW
LKWPETER
A.M.I.
CONDO
PHOENIX BIOS
phoenix
PHOENIX
CMOS
BIOS
MISC. COMMON PASSWORDS
ALFAROME
BIOSTAR
biostar
biosstar
CMOS
cmos
LKWPETER
lkwpeter
setup
SETUP
Syxz
Wodj
OTHER BIOS PASSWORDS BY MANUFACTURER
TOSHIBA BIOS
Most Toshiba laptops and some desktop systems will bypass the BIOS password if the left shift key is held down during boot
IBM APTIVA BIOS
Press both mouse buttons repeatedly during the boot
Here are some more:
VOBIS & IBM
merlin
Dell
Dell
Biostar
Biostar
Compaq
Compaq
Enox
xo11nE
Epox
central
Freetech
Posterie
IWill
iwill
Jetway
spooml
Packard Bell
bell9
QDI
QDI
Siemens
SKY_FOX
TMC
BIGO
Toshiba
Toshiba
There are other backdoor passwords listed here and they also suggest some software solution:
http://www.technibble.com/how-to-bypass-or-remove-a-bios-password/
NOTE
Most laptops cannot have its BIOS password bypassed with any of the above backdoor passwords. The laptop passwords are stored in a separate chip, and clearing CMOS or removing the battery will not work to get rid of them.
A good article to read about this topic can be read here:
Removing a Bios - CMOS Password
http://www.dewassoc.com/support/bios/bios_password.htm
The CMOS jumper referred to in the two articles I mentioned above is almost always near the battery of the motherboard. Use the jumper by moving it over for about five seconds. Then move it back (release it). By doing that most BIOS will be reset. This is much faster than waiting for all the power to drain. Some newer boards even have a button instead of a jumper.
SOURCES:
Overclock.net
Technibble.com
Wednesday, August 29, 2012
How to Unplug Java from the Browser
Java is a huge backdoor to anybody's system.
In Chrome you can also make it "click to play", meaning when a website wants to use Java (you can also do it for Flash) it just displays a grey box where it says "Click to run plugin". So if you are on a trustworthy site that requires Java you can just click and use it. To enable "click to play" go to chrome://plugins/ and uncheck "Always allowed" but don't disable Java.
If you are really security-conscious, you can set your web browser to only run plugins on your click.
In Firefox: Open a new tab, type this into address bar:
Double click the line to set the value to TRUE.
NOTE: If you want to automatically enable plugins for a certain domain (such as http://youtube.com ), follow this.
In Chrome: Open a new tab, type this into address bar:
chrome://chrome/settings/content
Scroll down to the bottom and click on "Show advanced settings".
Go to Privacy -> Content Settings button.
Scroll down to Plug-ins and select "Click to play" radio button and press OK.
In Opera: Press CTRL + F12
Go to Advanced -> Content.
Tick the box that says "Enable plug-ins only on demand" and press OK.
You could use NoScript extension for Firefox or similar addons and block Java on every site except the sites that you trust. OR...you can install the QuickJava extension to quickly enable Java when you want to go to a trusted site that uses Java or play RuneScape and disable it when you are done. A caveat on using NoScript -- it also blocks Javascript.
Chrome has a builtin sandbox. However Chrome's sandbox does not stop this Java exploit.
Java applications have the ability to examine and change properties about itself. If you load a page that uses a java app, it is installed on your system. You think it has limited access and no ability to alter or create important files. A baddy app can change its permissions so that it can write, create and delete files. And that means all files on all the drives you can connect to.
Javascript isn't Java. One is a browser scripting language while the other is a programming language which can be used within the browser when enabled with a plugin. You need Javascript for many websites to function properly. Java is used less frequently now and so it is safe to block it. The main idea behind Java was to create a language that would be "portable". In other words, a program written in Java can be distributed to people running different operating systems including Mac OS, Windows, Linux and others. It does this because another piece of software, known as the Java Virtual Machine, or JVM for short, sits between your operating system and the application. JRE stands for Java Runtime Environment and includes the JVM. The vulnerability in question seems to concern the Java applets. An applet is a Java program that runs in your browser to make web pages interactive. You need the Java plugin enabled in your browser for it to work. There have been many security complaints about them over the years. I hope I'm not wrong on this. But if I am do correct me for everyone's benefit.
How to Unplug Java from the Browser
From: http://krebsonsecurity.com/how-to-unplug-java-from-the-browser/
Below are instructions for unplugging Java from whatever Web browser you may use to surf the Web. These instructions were originally posted as a how-to in response to this piece: Attackers Pounce on Zero-Day Java Exploit.
For Windows users:
Mozilla Firefox: From the main menu select Add-ons, and then disable any plugins with the word "Java" in them. Restart the browser.
Google Chrome: Click the wrench icon in the upper right corner of the browser window, then select Settings. In the search results box to the right in the next screen, type "Java". A box labeled "Content settings" should be highlighted. Click that, and then scroll down to the Plug-ins section. Click the "Disable individual plug-ins" link, find Java in the list, and click the disable link next to it.
Internet Explorer: Apparently, getting Java unplugged from Internet Explorer is not straightforward. The U.S. Computer Emergency Response Team (USCERT) lists the following steps, which may or may not completely remove Java from IE:
In the Windows Control panel, open the Java item. Select the "Java" tab and click the "View" button. Uncheck "enabled" for any JRE version listed. Note that this method may not work on Vista or newer systems. As an alternative, you may use one of the following techniques:
Click the start key and type "regedit" in the search box. Double-click the regedit program file when it appears.
- Change the HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\\UseJava2IExplorer registry value to 0, where is any version of Java on your system. 10.6.2, for example.
If you are running a 32-bit version of Java on a 64-bit platform, you should set the HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\JavaSoft\Java Plug-in\ \UseJava2IExplorer registry value to 0.
- Run javacpl.exe as administrator, click the "Advanced" tab, select "Microsoft Internet Explorer" in the "Default Java for browsers" section, and press the space bar to uncheck it. This will properly set the above registry value, despite the option being greyed out.
For Mac users:
Safari: Click Preferences, and then the Security tab (uncheck "Enable Java").
Google Chrome: Open Preferences, and then type "Java" in the search box. Scroll down to the Plug-ins section, and click the link that says "Disable individual plug-ins." If you have Java installed, you should see a "disable" link underneath its listing.
Firefox: Click Tools, Add-ons, and disable the Java plugin(s).
Mozilla has taken the bold step of telling all Firefox users to disable Java while Oracle casually develops its fix, with the Firefox maker working on adapting its code so that all users running the exploitable version of Java will have the plugin automatically disabled for them.
At the top of the Firefox window, click on the Firefox button (Tools menu in Windows XP), and then click Add-ons. The Add-ons Manager tab will open.
By default, Firefox allows Java applets to launch automatically. However, you may decide that you do not want Java applets to run. To disable Java applets in Firefox:
In the Add-ons Manager tab, select the Plugins panel.
Click on the Java (TM) Platform plugin to select it.
Click on the Disable button (if the button says Enable, Java is already disabled).
Java applets will no longer be permitted to launch in Firefox.
You can go to http://www.isjavaexploitable.com/ to see if Java is enabled in your browser. And to test what version of Java you are using, you can go here:
http://javatester.org/version.html
You can go to http://www.isjavaexploitable.com/ to see if Java is enabled in your browser. And to test what version of Java you are using, you can go here:
http://javatester.org/version.html
There is one other way to insulate your computer from this Java exploit not mentioned in the article above. You can use HIPS programs like DeepFreeze (not a freeware) and Sandboxie (a freeware).
If you are really security-conscious, you can set your web browser to only run plugins on your click.
In Firefox: Open a new tab, type this into address bar:
about:config?filter=plugins.click_to_play
Click "I'll be careful, I promise!"...Double click the line to set the value to TRUE.
NOTE: If you want to automatically enable plugins for a certain domain (such as http://youtube.com ), follow this.
chrome://chrome/settings/content
Scroll down to the bottom and click on "Show advanced settings".
Go to Privacy -> Content Settings button.
Scroll down to Plug-ins and select "Click to play" radio button and press OK.
In Opera: Press CTRL + F12
Go to Advanced -> Content.
Tick the box that says "Enable plug-ins only on demand" and press OK.
You could use NoScript extension for Firefox or similar addons and block Java on every site except the sites that you trust. OR...you can install the QuickJava extension to quickly enable Java when you want to go to a trusted site that uses Java or play RuneScape and disable it when you are done. A caveat on using NoScript -- it also blocks Javascript.
This solution was also suggested in Krebs on Security:
If you primarily use Java because some Web site, or program you have on your system — such as OpenOffice or Freemind — requires it, you can still dramatically reduce the risk from Java attacks just by disabling the plugin in your Web browser. In this case, I would suggest a two-browser approach. If you normally browse the Web with Firefox, for example, consider disabling the Java plugin in Firefox, and then using an alternative browser (Chrome, IE9, Safari, etc.) with Java enabled to browse only the site that requires it.
Java is very widely used on the server side by tech companies like Google, Linkedin, Twitter as well as for web-facing business applications. Google does not use Java exclusively, in fact, every one of their services uses different tools to tackle the purpose. When you're a huge company, you have that luxury. Twitter is actually transitioning to Java.
Java applications have the ability to examine and change properties about itself. If you load a page that uses a java app, it is installed on your system. You think it has limited access and no ability to alter or create important files. A baddy app can change its permissions so that it can write, create and delete files. And that means all files on all the drives you can connect to.
Javascript isn't Java. One is a browser scripting language while the other is a programming language which can be used within the browser when enabled with a plugin. You need Javascript for many websites to function properly. Java is used less frequently now and so it is safe to block it. The main idea behind Java was to create a language that would be "portable". In other words, a program written in Java can be distributed to people running different operating systems including Mac OS, Windows, Linux and others. It does this because another piece of software, known as the Java Virtual Machine, or JVM for short, sits between your operating system and the application. JRE stands for Java Runtime Environment and includes the JVM. The vulnerability in question seems to concern the Java applets. An applet is a Java program that runs in your browser to make web pages interactive. You need the Java plugin enabled in your browser for it to work. There have been many security complaints about them over the years. I hope I'm not wrong on this. But if I am do correct me for everyone's benefit.
Tuesday, August 28, 2012
Multifox
Official Site - http://br.mozdev.org/multifox/
Multifox is an extension that allows Firefox to connect to websites using different user names. Simultaneously! For example, if you have multiple Yahoo accounts, you can open them all at the same time. Each Firefox window, managed by Multifox, accesses an account without interfering with each other.
Multifox creates commands in context menus (right-click) of links, bookmarks and even your browser tabs (Open in a New Identity Profile) and in File menu (New Identity Profile). Select the command. A new window will open. Your logins in this window are independent of other Firefox windows.
Namebench
Works with: Windows 7, Vista
Read more about Namebench here:
http://code.google.com/p/namebench/
One way to speed up your Internet browsing experience is using a faster DNS server. If you’re looking for a tool to help find a faster DNS server for your system, Namebench is your answer. This small, free utility performs benchmark tests on multiple DNS servers, reports back on which are the fastest, which the most secure, and so on, and recommends which DNS servers you should use. Once you get that recommendation, it's up to you to configure your PC to use the fastest DNS servers.
Chrome Plus: CoolNovo
I like to inform everyone about what others refer to as Chrome Plus browser but actually named CoolNovo. For more details on this browser:
According to the site:
"CoolNovo has all the functionalities that Google Chrome has. More, CoolNovo added some useful features such as Mouse gesture, Super drag, IE tab, etc. Meanwhile, CoolNovo is free with no function limitation and you can use CoolNovo to surf the internet in any case."
The differences between CoolNovo and Google Chrome in Privacy Policy can be read here:
http://coolnovo.com/compare.html?hl=en
If you have Vidalia or Tor Bundle installed and running it adopts the proxy settings automatically set in Tor.
Fixing Google Chrome Intermittent Lags & Freezes
Many people are experiencing temporary lags and freezes while browsing with Google Chrome. Consider the following suggestions:
1. As I suggested in a previous post try disabling the builtin Flash Player and Shockwave of Chrome. Then install Adobe Flash Player while all browsers are closed.
2. AUTO DISCOVERING PROXY: The "auto detect proxy" function of Win 7 may be causing lag for some users. To disable it, go to Wrench icon in Chrome -> Options -> Under the Hood -> Change Proxy Settings. Click "LAN settings" and uncheck "automatically detect settings". Alternatively click Wrench -> Settings (if it's not grayed out) -> Show advanced settings... -> (Network) Change proxy settings button -> (Connections tab) LAN settings button -> uncheck "Automatically detect settings.". Hit OK until you get back to the browser. Test to see if the problem has gone away. You may also have to re-start Chrome.
3. TABLET DRIVER/LOW LEVEL MOUSE HOOKS: This problem appears to be connected to "low level mouse hooks" causing problems in Win 7. Click the Start button, type 'services' and pick the Services item from the list. Scroll down to the Tablet PC Input Service and double click it. Click Stop, then change the 'Startup type' setting to "Disabled". Hit OK. If you run any other applications which change how your mouse functions (e.g. AutoHotKey), also kill those programs. Test to see if the problem has gone away.
4. Alternatively, instead of futzing with the Services, you can simply turn off Tablet PC Components as a Windows feature:
A. If viewing the Control Panel by category:
Control Panel > Programs > Turn Windows features on or off (under Programs and Features)
B. If viewing the Control Panel by icons:
Control Panel > Programs and Features > Turn Windows features on or off (left side panel)
In the list of Windows features that pops up, simply uncheck "Tablet PC Components" and hit OK.
5. Clear the Chrome browsing history, cache, etc. You may use CCleaner and Glary Utilities for thorough cleanup.
6. I think Chrome, during those temporary lags and freezes, is trying to use memory that Microsoft is busy loading with random crap. Super Fetch is a random crap loader. It isn't a virus or malware; it's one of those problematic features that attempts to load things you MIGHT need before you actually need them based on what you needed yesterday. A feature that front loads more and more overtime? Super Fetch service is a memory drain too that seems to slow down Chrome browsing. Look in the Task Manager for svcHost that has 100MB+ memory usage. Right-click it, go to Services. Turn off and then disable Super Fetch.
7. I also noticed after installing the Adblock extension that it's causing some lags to Chrome. Seems like disabling the AdBlock extension makes things smoother (not perfect, but better) for me.
8. A. Click Start, point to All Programs, and then click Accessories.
B. Right-click Command Prompt, and then click Run as administrator.
C. In the Administrator: Command Prompt window, type the following command, and then press ENTER:
netsh interface tcp set global autotuninglevel=highlyrestricted
D. Reboot computer.
The problem is described in Microsoft KB Article 929868: http://support.microsoft.com/kb/929868
9. One more thing you should try. Defrag your hard drive. I know it sounds simple, but Nike said, "Just do it!" (hehe... hopefully). In Cmd prompt, enter this command:
defrag c: /U /V
10. Back up your files that you can't afford to lose in your Documents and Settings account folders. Then re-install Chrome using RevoUninstaller. Give the hidden folders a clean out before re-install. Make sure Google Chrome is closed and none of its components are running in your Task Manager. If there are some stragglers there, END TASK them at once.
For Windows Vista - C:\Users\<username>\AppData\Local\Google\Chrome
For Windows XP - C:\Documents and Settings\<username>\Local Settings\Application Data\Google\Chrome
Sorry, I don't have Windows 7 here.
11. This site suggests deleting the Local State File and renaming the Default folder in the Google Application Data folder:
Subscribe to:
Posts (Atom)