Notices

Overclockers Forums > Software > Microsoft Operating Systems
Microsoft Operating Systems Microsoft Operating Systems and Applications
Forum Jump

someone hacked my comp...

Post Reply New Thread Subscribe Search this Thread
 
 
Thread Tools
Old 09-24-03, 05:11 PM Thread Starter   #1
sk-
Member

 
sk-'s Avatar 

Join Date: Feb 2003
Location: New York City

 
someone hacked my comp...


I live in a dorm and my computer has a windows password on it. But today I came back from class and my roommate told me that one of his friends was ****ing with my computer and he got into windows some how.

My roommate said it was only a joke and he had no bad intentions but still I dont like this invasion of privacy. Is there a program that adds better protection then the windows password.

Oh and he didnt use any cd's or floppy's to get into windowsXP pro. I guess he was lucky with the password.
sk- is offline   QUOTE Thanks
Old 09-24-03, 05:51 PM   #2
Oni
Oni-ni-Kanabō
Ninja Hippo eater Moderator

 
Oni's Avatar 

Join Date: Apr 2001
Location: St. Catharines, Ontario Canada

10 Year Badge
 
2 words: "l337sp34k passwords"


__________________
Mama, put my guns in the ground. I can't shoot them anymore.

On Indefinite Hiatus

Asus P6T SE
Intel i7 930 @ Stock
12GB Corsair DDR3 9-9-9-24
XFX Radeon 5830 @ Stock
Corsair 750 Watt PSU

Oni is offline   QUOTE Thanks
Old 09-24-03, 07:00 PM   #3
Xaotic
Very kind Senior

 
Xaotic's Avatar 

Join Date: Mar 2002
Location: Greensboro NC

10 Year Badge
 
Disable Guest, if it's activated.

Hard drive and BIOS passwords(HDD passwords are usually not easily cracked and almost impossible to bypass).

Use NTFS for the filesystem, keeps DOS boot disks from being used(unless someone is really motivated). You could disable FDD and CD boot for normal operation.

Use complex passwords. No caps to start. Minimum 8 characters. At least 2 must be numeric. Minimum 2 capitalized letters. No words, names or places.

Use password protected screen savers and lock the computer when you are away from it.

These are some of the basic security steps for unattended machines. There are many more.
Xaotic is offline   QUOTE Thanks
Old 09-24-03, 07:10 PM   #4
I.M.O.G.
Glorious Leader

 
I.M.O.G.'s Avatar 

Join Date: Nov 2002
Location: Rootstown, OH

10 Year Badge
 
Here's the method I use to make secure passwords.

Choose a phrase you will remember:

"You Can't Crack This Uber Password."

Take the first letter from each word:

"YCCTUP"

Append a number prefix or suffix that you can remember (personal like birthdate or system information like ram timings work well):

"19YCCTUP82"

No one is gonna guess a password like that, and creating it from a phrase makes it super easy to remember right from the point you make it. I'm real forgetful, so this works well for me.

__________________
The OC Forums Way
We are a team. We are a community. We are a fellowship made strong by mutual respect and shared dedication to the task of enriching all who come here.
The OC Forums Thank You Thread
Put your computer to work for our OC Forum Teams!
Try out our POST TEMPLATES, they save you time answering common questions!

I spend half my money on CPUs, GPUs, and Liquid Nitrogen. The other half I waste.
I.M.O.G. is offline Author Profile Benching Profile Folding Profile Heatware Profile   QUOTE Thanks
Old 09-24-03, 10:55 PM   #5
engjohn
Senior Member

 
engjohn's Avatar 

Join Date: Dec 2000
Location: SoCal

 
an even more secure password is something like

St@rBr!9ht (starbright)
sT@rl!9hT (starlight)
!33T$pE@k (l33tspeak)

or
( . )( . )

__________________
<--- Dave and My Girlfriend in Atlanta, Ga at the Ritz Carlton!!! Yahoo!! (I took the PIC!!)

und KEINE EIER!!!
My Heatware
engjohn is offline   QUOTE Thanks
Old 09-24-03, 11:44 PM   #6
KraziKid
Member



Join Date: Nov 2002

 
A few things come to mind in your case. Either a) your passwords are way too simple, b) Your Administrator password is null (meaning there is none), or c) Guest account is enabled. If the Administrator account has no password, poof, instant access. I doubt he used a brute force method, but if he used a boot floppy and decrypted the SAM file, here are some pointers. Any password 15 characters or more makes a Lan Man Hash invalid (it cannot be reversed). Also, characters from the extended ASCII table also make the Hash invalid, but, some values are represented by lower ASCII values, so it can make it potentially easier to crack. On my workstation, the password isn't that secure, but my server password is 31 characters long (that is basically impossible to crack). Also, do what engjohn said, replace common characters with characters that look the same, but aren't (a and @ for example).
KraziKid is offline   QUOTE Thanks
Old 09-24-03, 11:57 PM   #7
pik4chu
Senior Yellow Forum Rat

 
pik4chu's Avatar 

Join Date: Jan 2003
Location: Highlands Ranch, Colorado

10 Year Badge
 
My laptops that I carry around and leave running at various semi public places usually have entire sentences for passwords (uncommon ones )with numbers and caps added here and there. with BIOS passwords (both standard and supervisor) the admin and guest accounts have been renamed, then the guest account disabled. recovery console restricted access to partition. NTFS file system. Auto workstation lock on screen saver. with SS password. disabled floppy and cd read on startup and on local access unless authenticated admin. Guess Im a little paranoid

in fact my normal passwords for this machine are about 15 chars long with numbers letters caps and a symbol or two

__________________
DFI X58-T3EH8 | I7-920 C0@3.0 (V8) | 6*2GB Corsair Dominator @1800-7-7-7-18 | eVGA 285 | 1.5 TB RAID 0 | Win7 64-bit (456Watts)
Main Server (WIP): DFI X58-T3EH8 | I7-920 C0@3.6 | 3*2GB Corsair Dominator @1800-7-7-7-18 | 8*1.5TB in RAID 5 (283Watts)

Folding User Stats
Team 32 Countdown heatware
pik4chu is offline Benching Profile Folding Profile Heatware Profile   QUOTE Thanks
Old 09-25-03, 06:43 AM   #8
powerme
Member



Join Date: Aug 2003

 
make sure you "disable" a real "administrator" in winxp because it is there.

boot into safemode and you will see this administrator account along with your account.

you have 2 choices: delete your account and add password for this administrator account

or use your account and add password for your account and this administrator.

if you are using a laptop computer, take out the hard drive and carry it with you. Nobody will get access to your windows when they don't have this hard drive

when they try to do that, they will see "no operating system found". End of the story
powerme is offline   QUOTE Thanks
Old 09-25-03, 09:12 AM   #9
engjohn
Senior Member

 
engjohn's Avatar 

Join Date: Dec 2000
Location: SoCal

 
Quote:
Originally posted by KraziKid
Any password 15 characters or more makes a Lan Man Hash invalid (it cannot be reversed).
This is true, but the passwords can still be reversed by using the NTLM hash. It will take longer, but it can be done. Reversing a LM hash is fast and easy for passwords under 14 char. The LM hash is NOT case sensitive, and usually a quick NTLM hash is run after cracking the LM hash to get the proper Caps.

using special symbols @$#%&( and the like makes it even harder to crack. On a P4 2.8 it took 40 Hours to crack a 9 letter password using one special symbol and a number. do NOT place these only at the begining or the end. This is also easy to crack. They must be in the middle of the password...

Also, you can use an inline PS2 key logger to capture passwords...

Just some thoughts.

1. Secure passwords.
2. Disable un-used accounts.
3. set a bios boot password.
4. Make sure that your computer will lock if not being used.
5. Dont temp people to hack your system (and DONT tell people your password, or let them logon to your system)

__________________
<--- Dave and My Girlfriend in Atlanta, Ga at the Ritz Carlton!!! Yahoo!! (I took the PIC!!)

und KEINE EIER!!!
My Heatware
engjohn is offline   QUOTE Thanks
Old 09-25-03, 10:56 AM   #10
I.M.O.G.
Glorious Leader

 
I.M.O.G.'s Avatar 

Join Date: Nov 2002
Location: Rootstown, OH

10 Year Badge
 
Thanks for your comments John, they're very informative.

__________________
The OC Forums Way
We are a team. We are a community. We are a fellowship made strong by mutual respect and shared dedication to the task of enriching all who come here.
The OC Forums Thank You Thread
Put your computer to work for our OC Forum Teams!
Try out our POST TEMPLATES, they save you time answering common questions!

I spend half my money on CPUs, GPUs, and Liquid Nitrogen. The other half I waste.
I.M.O.G. is offline Author Profile Benching Profile Folding Profile Heatware Profile   QUOTE Thanks

Post Reply New Thread Subscribe


Overclockers Forums > Software > Microsoft Operating Systems
Microsoft Operating Systems Microsoft Operating Systems and Applications
Forum Jump

Thread Tools Search this Thread
Search this Thread:

Advanced Search


Mobile Skin
All times are GMT -5. The time now is 02:35 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
You can add these icons by updating your profile information to include your Heatware ID, Benching Profile ID or your Folding/SETI profile ID. Edit your profile!
X

Welcome to Overclockers.com

Create your username to jump into the discussion!

New members like you have made this the best community on the Internet since 1998!


(4 digit year)

Why Join Us?

  • Share experience
  • Max out your hardware
  • Best forum members anywhere
  • Customized forum experience

Already a member?