Unconfigured Ad Widget

Collapse

How to find or bypass passwords

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ojisan
    Agent 86
    CGN Contributor
    • Apr 2008
    • 11758

    How to find or bypass passwords

    My BIL passed unexpectedly last week.
    He had a stock brokerage business.
    His business has been passed to his father, who is not tech-savy or prepared for this.

    Of course, the business info and accounts are all on computer.
    Nobody can get into the computers without the passwords.
    No list of passwords or clues have been found.
    Clients and their attorneys are already calling.

    Does anybody know of a service who can gain access to the data or how to get past the passwords?
    Any CalGunners who can "break into" the computers? (one laptop, one desktop so far.)
    Of course, part two of this might be that the data is encrypted for security.

    Location is San Diego.

    Advice, help or suggestions, please!

    Thank you!

    Originally posted by Citadelgrad87
    I don't really care, I just like to argue.
  • #2
    M1Kev
    Member
    • Oct 2010
    • 298

    If it is windows you can try Hirems boot utility. I used it to get in my dad's PC after he passed. Download online

    Comment

    • #3
      choprzrul
      Calguns Addict
      • Oct 2009
      • 6544

      Here is what I always use on customer computers.

      Probably not a novice tool, but it always works for me.

      That being said, if whole disk encryption was used, there is nearly zero paths to recovery. If you boot the computer and see a standard username/password challenge, shut down normally and then boot to the above cd. In some instances, you can do the ctrl + alt + del 3 finger salute 3 or 4 times really quickly to get a domain type of password challenge screen. Change the default username that is autofilled with 'administrator' and leave the password field blank. If the default administrator account was never set up with a password, this can be a quick backdoor entry into a computer. Once into the administrator account, you can go into mmc and set a user's password.

      If this computer is part of a domain, and you can access the domain controller, just change the user's password and proceed as normal.

      Hope this helps.

      .

      Comment

      • #4
        ojisan
        Agent 86
        CGN Contributor
        • Apr 2008
        • 11758

        ^ AWESOME!
        Yes, I'm also searching the net for info, too.
        This one seems best so far.

        Originally posted by Citadelgrad87
        I don't really care, I just like to argue.

        Comment

        • #5
          bg
          Calguns Addict
          • Aug 2002
          • 5207

          Ophacrack

          Comment

          • #6
            bigmike82
            Bit Pusher
            CGN Contributor
            • Jan 2008
            • 3876

            Before you try anything, back up the hard drive to another hard drive. If his folders are encrypted with Bitlocker, resetting his password will make his files very, very, very difficult if not impossible to recover.

            If you're having difficulties, bring it by my office in Chatsworth...ntpasswd should do the trick for you though. It's always worked for me.
            -- 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0

            Comment

            • #7
              JDay
              I need a LIFE!!
              • Nov 2008
              • 19393

              I'm surprised that he would be the only one in the business with access to this information. But before you can do anything we need to know what version of Windows is on the machine.

              If the data is not encrypted you can just stick the drive into another computer and copy everything off of it (likely what you're looking for is in a spreadsheet). There are also ways to reset the Windows password, however if he encrypted any folders resetting the password will make that stuff unrecoverable.

              Originally posted by choprzrul
              [B][U]Change the default username that is autofilled with 'administrator' and leave the password field blank. If the default administrator account was never set up with a password, this can be a quick backdoor entry into a computer.
              That only works with XP.
              Last edited by JDay; 06-18-2012, 7:54 AM.
              Oppressors can tyrannize only when they achieve a standing army, an enslaved press, and a disarmed populace. -- James Madison

              The Constitution shall never be construed to authorize Congress to prevent the people of the United States, who are peaceable citizens, from keeping their own arms. -- Samuel Adams, Debates and Proceedings in the Convention of the Commonwealth of Massachusetts, 86-87 (Pearce and Hale, eds., Boston, 1850)

              Comment

              • #8
                stix213
                AKA: Joe Censored
                CGN Contributor - Lifetime
                • Apr 2009
                • 18998

                Originally posted by bigmike82
                Before you try anything, back up the hard drive to another hard drive. If his folders are encrypted with Bitlocker, resetting his password will make his files very, very, very difficult if not impossible to recover.

                If you're having difficulties, bring it by my office in Chatsworth...ntpasswd should do the trick for you though. It's always worked for me.
                ntpasswd has always worked for me as well, but I haven't tried it on anything newer than XP.

                Comment

                • #9
                  Nose Nuggets
                  Calguns Addict
                  • Apr 2008
                  • 6801

                  if none of the password breakers do it, just pull the hard drive out and put it in an enclosure. Plug it into your computer and grab what you need.


                  "It is to secure our rights that we resort to government at all." -Thomas Jefferson

                  Comment

                  • #10
                    Montu
                    Senior Member
                    • May 2011
                    • 1589

                    I would like to add to Nose Nuggets suggestion..you can also boot up to a Linux flash drive and copy the files onto another drive.

                    Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.


                    Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.


                    *if the drive is not encrypted

                    Nt password should work though
                    Last edited by Montu; 06-18-2012, 5:14 PM.
                    K.F.K|Μολὼν λαβέ

                    Comment

                    • #11
                      Corbin Dallas
                      CGN/CGSSA Contributor - Lifetime
                      CGN Contributor - Lifetime
                      • May 2006
                      • 6147

                      Originally posted by ojisan
                      My BIL passed unexpectedly last week.
                      He had a stock brokerage business.
                      His business has been passed to his father, who is not tech-savy or prepared for this.

                      Of course, the business info and accounts are all on computer.
                      Nobody can get into the computers without the passwords.
                      No list of passwords or clues have been found.
                      Clients and their attorneys are already calling.

                      Does anybody know of a service who can gain access to the data or how to get past the passwords?
                      Any CalGunners who can "break into" the computers? (one laptop, one desktop so far.)
                      Of course, part two of this might be that the data is encrypted for security.

                      Location is San Diego.

                      Advice, help or suggestions, please!

                      Thank you!
                      PM sent
                      NRA Life Member and Certified Instructor: Pistol - Rifle - Shotgun - PPITH - PPOTH - NRA Certified RSO

                      WTB the following - in San Diego
                      --Steyr M357A1 357SIG
                      --Five Seven IOM (round trigger guard)

                      Never forget - השואה... לעולם לא עוד.

                      Comment

                      • #12
                        redcliff
                        Calguns Addict
                        • Feb 2008
                        • 5676

                        Really sorry to hear about your brother-in-law ojisan. I hope you're able to help out the family in their time of need.
                        "You keep using that word. I do not think it means what you think it means."
                        "What we get away with isn't usually the same as what's good for us"
                        "An extended slide stop is the second most useless part you can put on a 1911"

                        "While Ruger DA revolvers may be built like a tank, they have the aesthetics of one also,
                        although I suppose there are a few tanks which I owe an apology to for that remark"

                        Comment

                        • #13
                          Coded-Dude
                          Calguns Addict
                          • Dec 2010
                          • 6705

                          Originally posted by JDay
                          I'm surprised that he would be the only one in the business with access to this information. But before you can do anything we need to know what version of Windows is on the machine.

                          If the data is not encrypted you can just stick the drive into another computer and copy everything off of it (likely what you're looking for is in a spreadsheet). There are also ways to reset the Windows password, however if he encrypted any folders resetting the password will make that stuff unrecoverable.



                          That only works with XP.
                          Originally posted by Nose Nuggets
                          if none of the password breakers do it, just pull the hard drive out and put it in an enclosure. Plug it into your computer and grab what you need.
                          you guys are old school.....I use Parted Magic. Download the ISO, burn it to CD(or USB), boot the CD/USB(it runs in memory) and copy every thing off the drive without even opening the case(you will of course need to plug in an external drive to coy the data to). Removing the drive can cause more problems than they are worth IMHO.

                          x2

                          Originally posted by Deadbolt
                          watching this state and country operate is like watching a water park burn down. doesn't make sense.
                          Originally posted by Obama
                          Team 6 showed up in choppers, it was so cash. Lit his house with red dots like it had a rash. Navy SEALs dashed inside his house, left their heads spinning...then flew off in the night screaming "Duh, WINNING!"

                          Comment

                          • #14
                            the86d
                            Calguns Addict
                            • Jul 2011
                            • 9587

                            Originally posted by Coded-Dude
                            you guys are old school.....I use Parted Magic. Download the ISO, burn it to CD(or USB), boot the CD/USB(it runs in memory) and copy every thing off the drive without even opening the case(you will of course need to plug in an external drive to coy the data to). Removing the drive can cause more problems than they are worth IMHO.

                            http://partedmagic.com/doku.php
                            I have done the same with some Knoppix distros, only dropped them off on a network share (if GIG Ethernet, hell even 100MBps is pretty fast if it is not a bunch of data).

                            But... taking the drive out and plugging it in direct yields full data speeds.

                            Comment

                            • #15
                              dem0critus
                              Senior Member
                              • Mar 2012
                              • 619

                              pm sent

                              Comment

                              Working...
                              UA-8071174-1