|
|||||||
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello all. I just read Bryce's latest article on resetting a Windows password using utilman.exe. This is not the way that I go about resetting passwords but I would like to ask a question that stemmed from reading his article. When resetting a customer's password, how can I keep from losing access to their encrypted files when I do not know the previous password? Can I use konboot to boot into windows and then export the encryption certificate? I would like to know how you guys go about this because the last thing I want is to reset a password for a customer and then realize that they now do not have access to their encrypted (and most important) files. Thanks.
__________________
|
|
#2
|
||||
|
||||
|
Personally I've never run into this problem, so don't take this as gospel. I think the best way to deal with this would be to use Ophcrack; it doesn't manipulate the SAM file and if it finds the password then you can login normally using the correct password and view all the files. I think using Konboot would work to boot the machine and view/copy the files, but otherwise I'm not sure.
__________________
put that in your pipe and grep it |
|
#3
|
||||
|
||||
|
What about using a MsDart disk? Should be ok with that or am I missing the point?
|
|
#4
|
||||
|
||||
|
my understanding is that kon-boot just bypasses the login screen. So there is no need for a password reset.
Last edited by tf76; 04-23-2012 at 01:10 PM. |
|
#5
|
|||
|
|||
|
Quote:
Quote:
Thanks for the replies.
__________________
|
|
#6
|
|||
|
|||
|
Only way to find out is create the situation yourself on one of your bench or testing computers...or virtually too. Thats how i test things out before i actually do it to a customers pc. Good luck and let us know what works for you.
|
|
#7
|
|||
|
|||
|
Ophcrack was pretty infallible with XP but I'm thinking I read that it won't crack passwords longer than 8 characters in Vista or Win 7. Or, more correctly, the size of the rainbow tables that need to be loaded to break passwords longer than eight characters are in excess of the terabyte range.
|
|
#8
|
||||
|
||||
|
You could always backup all their data first then do the password reset if needed.
__________________
_ Before you decided to post your problems on the forums, did you run a FULL diagnostic? Be willing to do what your competition is not. "The smartest and most successful people in the world are those who surround themselves with smarter and more successful people than themselves" |
|
#9
|
|||
|
|||
|
But if they had encrypted files that were part of the backup and then I reset the password without knowing the old password wouldn't I lose access to all the encrypted files?
__________________
|
|
#10
|
||||
|
||||
|
Quote:
And just on a side note, there is an easier way to do this process . . . its similar, but easier. Also, I do not remember ever seeing a warning for encrypted files the way I do it, but that may be just something I never paid attention to . . . .
__________________
_ Before you decided to post your problems on the forums, did you run a FULL diagnostic? Be willing to do what your competition is not. "The smartest and most successful people in the world are those who surround themselves with smarter and more successful people than themselves" Last edited by PCX; 04-24-2012 at 07:22 PM. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|