There are many valuable links, which I'd like to recommend for further reading:
KB818200 - An attacker with physical access to a computer may be able to access files and other data http://support.microsoft.com/kb/818200/en-us
- published 31st May 2007 rev 10.
Reduce Your Risk: 10 Security Rules To Live By http://www.microsoft.com/technet/technetmag/issues/2006/05/ReduceRisk/
May - June 2006 TechNet Magazine / Wes Miller
10 Immutable Laws of Security http://www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx?mfr=true
10 Immutable Laws of Security Administration http://www.microsoft.com/technet/archive/community/columns/security/essays/10salaws.mspx?mfr=true
Instead of pressing once "any key" and clicking four mouse clicks to be able to start copying files to usb-disk, you can download Vista WAIK-tools and make a WinPE-boot disk to make the cracking process easier. If you have WinPE boot media, just press "any key" to boot it, wait a couple of minutes and you have full access to your computer - no need for mouse clicks at all.
There are few things I'd like to point out:
- Yes, this is not a new method, I've been using L0phtcrack etc since 90's
- BUT this trick needs no special software nor technical knowledge. Anyone can use this method at any computer, if physical access is available. You don’t have to be able to speak C++ or to compile kernel.
- Yes, as mentioned later in this page, BIOS-settings can be removed /cracked, the computer's hard disk can be stolen and put to another machine to be copied. Unfortunately there are some (older) bios-versions, which allows user to choose between different boot devices even bios-passwords enabled :-(
- Summary: If you really want to secure your files and systems, I highly recommend you to keep physical access to your computer as tight as possible and ENCRYPT your hard disks.
How to crack Microsoft Windows Vista / XP-workstations and Windows 200x servers in a minute?