Security researcher Rob Fuller has published a simple way to steal login credentials (passwords) from locked Windows and OS X computers.
For the attack you need:
Access to the target computer
A connected laptop that you have modified to act as a USB Ethernet adapter
and
a computer with software that will crack the hashes to be intercepted.
The actual attack can be carried out in less than half a minute, as you will see in the video below.
“Why? Because USB is Plug-and-Play. That means even if a system is locked, the device still works,” Fuller says.
“Now, I believe there are limitations with the types of devices you are allowed to install on a locked computer with newer operating systems (Win10/El Capitan), but Ethernet/LAN devices definitely work.”
On his blog, he describes how to set up a USB Armory or a Hak5 Turtle – two inexpensive ($155 and $49.99 respectively) USB-mounted Linux computers, to use in the attack.
Basically, they must be equipped with Responder, an open source software that simulates an authentication server. The operating system "recognizes" the server, and trusts it by default, as if it were on the local network. It then responds to the authentication request with the login credentials (passwords) recorded in a database.
To complete the attack, you need to crack the hashes of the stolen credentials. Different operating systems use different hashes, but all can be cracked or degraded into a form that can be used in “pass the hash” attacks.
The attack has been tested on various operating systems and OS versions. It works on Windows 98 SE, 2000 SP4, XP SP3, 7 SP1, and 10, as well as OS X El Capitan / Mavericks. It has not been tested on Linux at this time.
Watch the video and think about it the next time you lock your PC and think it's secure.
