Hacking into IRIX accounts
#11
RE: Hacking into IRIX accounts
(04-03-2020, 12:44 AM)Raion Wrote:  IRIX doesn't have /bin/bash.
I just meant in many UNIX-like systems, not IRIX specifically.
nintendoeats
Octane

Trade Count: (0)
Posts: 85
Threads: 8
Joined: Nov 2019
Location: Canada
Find Reply
04-03-2020, 12:48 AM
#12
RE: Hacking into IRIX accounts
/bin/bash is a GNU/Linux-ism, so it's not really correct.
/bin/sh itself is what you're technically talking about. This isn't to correct you, it's for the next person's benefit who comes across the thread.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,240
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
04-03-2020, 12:52 AM
#13
RE: Hacking into IRIX accounts
Yeah, perfect physical security is just not possible, so why bother?

This is how i used to do it with Windows NT back in the days:



Code:
1. Take the harddrive out of the target box and hook it up to another NT computer
2. Open a cmd shell
3. C:\> copy <TargetSystemRoot>\System32\logon.scr .
   C:\> copy <TargetSystemRoot>\System32\cmd.exe <TargetSystemRoot>\System32\logon.scr
4. Swap the disk back, boot the target box to the login prompt, and wait
5. When the screensaver kicks in, type "musrmgr" into th command prompt that appears
6. Use that to change the Administrator password




Works also on Win 2000, IIRC. I had to do that several times for colleagues, friends, and family. And stuff similar to what you did on Solrais, IRIX, and Linux. Nowadays, everybody works with admin rights all the time, so that is not happening any more, but back then it was pretty common.

"The early bird gets the worm, but the second mouse gets the cheese!"

SGI: Octane MXE, O2, Fuel (defunct), VW320 (defunct)
DEC: PC164, PC164SX, AXPpci
sgt_barnes
Octane

Trade Count: (0)
Posts: 101
Threads: 1
Joined: Mar 2019
Location: Germany
Find Reply
04-04-2020, 12:21 PM
#14
RE: Hacking into IRIX accounts
Another trick was to replace the stickykeys executable (sethc.exe) with cmd.exe by booting from a Linux live CD, or a WinPE disk. Boot Windows, press Shift 5 times and an elevated command prompt would appear. It was then pretty trivial to reset the admin password, or create another local admin account. This worked up to and including Windows 7. I used to use it at a previous place of work I contracted at when a machine got kicked out of the domain. Local admin accounts were locked and it was a damn-sight quicker than backing up data and re-imaging the machine.

Indigo2 R10000/IMPACT  R10000 195MHz, 384MB RAM, MaxIMPACT (1MB), 36GB 15k & 300GB 10k drives, new/quiet fans, 100Mb G160 NIC, IRIX 6.5.22&
[Image: Fuelb.png] R14000 600MHz, 4GB RAM, V10 Graphics, 72GB 15k & 300GB 10k drives, new/quiet fans, 1Gb NIC, IRIX 6.5.30
O2  in storage...
Trippynet
Indigo2 IMPACT

Trade Count: (0)
Posts: 304
Threads: 7
Joined: Dec 2017
Find Reply
04-04-2020, 07:59 PM
#15
RE: Hacking into IRIX accounts
Anybody else remember l0pht and l0phtcrack? Man, this takes me back...

Yes, I used similar tricks to
a) gain the passwd file from a 486 portable 'laptop' a friend gave me, which had Slackware 1.2 on it. I used johntheripper to decipher his passwords.
b) gain access to a Sparcstation IPX i found that had SunOS 4.1.3_U1 on it. It was fun to poke around the OS and software that hadn't been booted in decades

Have fun!
ghost180sx
Now-MIPS-Powered

Trade Count: (0)
Posts: 110
Threads: 6
Joined: Dec 2018
Location: The Great White North
Find Reply
04-15-2020, 04:10 PM
#16
RE: Hacking into IRIX accounts
Pretty much every OS vendor ever has said publicly that there's way to secure systems that the black hats have physical access to. Network security, yes; everyone tries really hard to thwart remote exploits, physical security, no; they don't even think about it...

Project: Temporarily lost at sea
Plan: World domination! Or something...
vishnu
Tezro, Octane2, 2 x Onyx4

Trade Count: (0)
Posts: 1,245
Threads: 41
Joined: Dec 2017
Location: Minneapolis, Minnesota USA
Find Reply
05-27-2020, 12:14 AM


Forum Jump:


Users browsing this thread: 1 Guest(s)