Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Privacy » How to Obtain Win Account Passwords Using Autologon

How to Obtain Win Account Passwords Using Autologon

Category: Privacy
Published: 12/06/2006, 18:46  
Editor: Security Software Zone
 
Print article
Send to a friend
Search in reviews
A malicious software can  capture the all password of whichever account is set for autologon. The answer lines in the Windows reg directory and the password for the autologon account is in plaintext, i.e. unencrypted ! For this idea, I've coded a sample program called APwd.exe which "reads" the plaintext password from the registry and display it together with the user name and domain name of the account.

Win2K operating system , similar to WinNT supports autologon to enable a user to logon to the system without user manually typing r password. This is to speed up  logon as well as ease the user from the hassle of entering his/her password everytime he/she logs on to the system. Win2K by default disables autologon but this can be enabled using registry tweaks. I don't know if there exist other ways of managing autolog without manually editing the registry. I've searched in almost all the snap-ins in MMC but I didn't find any feature that could manage the autologon.The registry value for the account name and password of the user is stored in cleartext, in REG_SZ form. Thus by using the registry APIs exported from ADVAPI32.DLL such as RegOpenKeyExA and RegQueryValueExA, a malicious software  can simply obtain the password for whichever user account is set as autologon. I'm not sure if this can be applied to WinXP because I tested this method on my system running Win2K Advanced Server SP3 and it works !

The autologon feature requires that the AutoAdminLogon value set to 1, REG_SZ type. This can be found in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon( Windows registry). By default, this value doesn't exist in Win2K, but the user can create this value. Note that setting this value to 0 disables autologon. Next, 3 more values have to be set: DefaultDomainName, DefaultPassword and DefaultUserName. The password in the DefaultPassword value is in cleartext and so this can be retrieved easily.

 Basically, if the autologon is set to the "Administrator", the person obtaining the password can virtually do anything. If it's some other user, it's also worth it because the person can hijack that account, installs keyloggers, and other malicious programs under that user account.
Bookmark to:
Add 'How to Obtain Win Account Passwords Using Autologon' to Del.icio.us Add 'How to Obtain Win Account Passwords Using Autologon' to digg Add 'How to Obtain Win Account Passwords Using Autologon' to FURL Add 'How to Obtain Win Account Passwords Using Autologon' to reddit Add 'How to Obtain Win Account Passwords Using Autologon' to Technorati Add 'How to Obtain Win Account Passwords Using Autologon' to Yahoo My Web Add 'How to Obtain Win Account Passwords Using Autologon' to Stumble Upon Add 'How to Obtain Win Account Passwords Using Autologon' to Google Bookmarks Add 'How to Obtain Win Account Passwords Using Autologon' to RawSugar Add 'How to Obtain Win Account Passwords Using Autologon' to Squidoo Add 'How to Obtain Win Account Passwords Using Autologon' to Spurl Add 'How to Obtain Win Account Passwords Using Autologon' to Netvouz Add 'How to Obtain Win Account Passwords Using Autologon' to Rojo Add 'How to Obtain Win Account Passwords Using Autologon' to Bloglines Add 'How to Obtain Win Account Passwords Using Autologon' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to How to Obtain Win Account Passwords Using Autologon
 

Javelin Strategy & Research Report Sees Innovative Approach TranscationVault
 A provider of enterprise payment solutions to the integrated point-of-sale industry, Merchant Link (http://www.merchantlink.com ), announced that its TransactionVaultTM product for its innovative ability to move customer credit card data to a safe, secure, and fully monitored and managed location away from the merchant's POS terminals, was recognized and cited in a recent analysis by Javelin Strategy & Research.
Read More >
03/27/2008, 12:07
 

Upgrade Announced by freeIDENTITYprotect
 IDENTITYprotect.com is now offering customers even more to protect against identity theft. Insurance, theft alerts and identity theft restoration to the already free services of freeIDENTITYprotect.com is added by the upgrade. The existing free services are still free
Read More >
04/03/2008, 10:30
 

Protect Your Software and Revenue and Minimize Software Piracy With Protection! Licensing Toolkit
 Whether you license your software on a per seat basis or a per running copy basis, you have complete control over the number of copies that can run simultaneously.
Read More >
06/25/2007, 20:20
 

The Protexx, Data Guard, S.I.T.H. Software is a High Encryption VPM Used to Secure Data Transmissions in Wireless Environments
 The availability of Protexx, Data Guard encryption software was announced recently by Horizon WiFi.
Read More >
05/02/2007, 14:15
 

New state-of-the-art hard drive shredder
 New equipment for data recycling and destruction methods.
Read More >
03/22/2007, 20:32

Sponsored