Re: Bypass grub edit protection password

Justin Rogosky <[email protected]>
Newsgroups gmane.comp.security.penetration
Message-ID <CANL9s55cq+pcky1LqT4m=4D9ary9zSxTv=jPQ_KkWqBBE-YRzw@mail.gmail.com>
I would attempt to locate the manual online (assuming it is a
commercial product).
Some other avenues might be (after a port scan)
-SNMP
     -guessing strings (password reuse)

-SMTP
     -vulnerabilities
     - VRFY (user name guessing)
     - Alternate route to bruteforce accounts

-SSH - as mentioned above (be careful of account lockout)

Also just from experience the BIOS access keys I have seen are F1, F2,
F12, Esc, and Del

--Justin





On 2/9/12, Carlos Pantelides <[email protected]> wrote:
> Have you access to any other account? Is there any network service running?
> Being centos 4.1 (2005-Oct-21 says the mirror) if it is unpatched perhaps
> you can find a vulnerability and gain more access.
>
>
> nmap it, is sshd running? try 500 most common passwords. Do you have time?
> try a bigger dictionary.
>
> Carlos Pantelides
>
>
> -----------------
>
>
> http://seguridad-agile.blogspot.com/
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually
> do a proper penetration test. IACRB CPT and CEPT certs require a full
> practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.