Lock computer (Ctrl+Alt+Del),can be accessed by other than admin

Or maybe did a hard reset of the machine?

In which case - he would still have to know the password to access the box.

As has been stated somewhere above - changing the administrator password is trivial if you have local access to the box - whether you currently know the password or not. Cracking the password is also fairly trivial if you have local access to the box. The former is very easy to spot (your password has mysteriously changed!). The latter is not, however, can be done a multitude of ways (cracking the SAM, keylogger, etc).

Essentially, what I'm saying is - the kid did not bypass the gina - the machine was either:

a) left unlocked
b) the password was known to the boy (whether this was socially engineered, or the password was extracted from the hash in the SAM)

EDIT: @ Zillah - If your friend definitely did not leave the box unlocked; then you have to consider the other option. Most keyloggers won't be found in add/remove programs, but a lot will be found by anti-virus / anti-malware solutions. It may also be a good idea to have a look at rootkit revealer by sysinternals. Either that, or find out from the lad how he did it.
 
Last edited:
In which case - he would still have to know the password to access the box.

As has been stated somewhere above - changing the administrator password is trivial if you have local access to the box - whether you currently know the password or not. Cracking the password is also fairly trivial if you have local access to the box. The former is very easy to spot (your password has mysteriously changed!). The latter is not, however, can be done a multitude of ways (cracking the SAM, keylogger, etc).

Essentially, what I'm saying is - the kid did not bypass the gina - the machine was either:

a) left unlocked
b) the password was known to the boy (whether this was socially engineered, or the password was extracted from the hash in the SAM)

yup

this thread is going round in circles, come back OP :)
 
i've heard of full circle, this is
newInfinity.jpg
 
Back
Top Bottom