MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 9 posts ] 
Author Message
 Post subject: When bad goes to worse for passwords.
PostPosted: November 30th, 2013, 18:43 
Offline

Joined: November 25th, 2013, 15:30
Posts: 6
Location: Denmark
Hi .

I work in a company where IT security thought it would be a brilliant idea to put a harddisk password on 250 Lenovo laptops.
The User password should be desided by the user.
The master password should be random and saved in a Excel Workbook with each laptops serial number.

Simply the most annoying idea ever.
And I got the job of setting the master passwords.
I finished this job in March and now we are installing Windows7 with bitlocker, so now they want the HDD password removed again.
This how ever seams to be a problem.
I'm guessing that some one made a sort on the excel workbook.
All the random passwords looks to be sorted nicely...
And none that I have tested match the serial number next to them.

I see 3 solutions:

1. I start with one PC and test as many passwords it will take to find the right one then delete it from the list and start over with the next PC. For every PC I fix there will be fewer passwords to test with. But it will probably take weeks.

2. I figure out how to use Victoria og MHDD for the job.
- Victoria dosn't seam to have a proper manual for this type of job.
- MHDD is not able to see any disks (maybe I doing some thing wrong).

3. I find a boss who is willing to pay for 250 new harddisks.

Can anyone please guide me to solution 2?

Kind regards Jgaard


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: November 30th, 2013, 19:08 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 16960
Location: Australia
Try http://malthus.zapto.org/viewtopic.php?f=95&t=166

BTW, how are you entering the password? Are you doing this is in the laptop via BIOS, or from within a software application?

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: December 1st, 2013, 10:09 
Offline

Joined: November 25th, 2013, 15:30
Posts: 6
Location: Denmark
fzabkar wrote:
Try http://malthus.zapto.org/viewtopic.php?f=95&t=166

BTW, how are you entering the password? Are you doing this is in the laptop via BIOS, or from within a software application?



All Passwords has been entered via BIOS.


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: December 1st, 2013, 10:14 
Offline

Joined: November 25th, 2013, 15:30
Posts: 6
Location: Denmark
Spildit wrote:
Solution 4 - Send the drives to me (Portugal) and i will unlock them for a price $$$$

Well, what is the model of the drives ?

What is the model of the laptops ?

If it's recent WD drives on recent lenovo you will not be able to access SA of the drive with the password on.

The idea of entering the password by Victoria or MHDD might NOT be a good one, because the lenovo laptop might hash the password that you type and lock the drive with the hash, not with the password you entered.

Does the laptops have BIOS lock or just HDD lock ?

I have one lenovo T60 and there are some settings that can be done at BIOS that allow for the ATA password to be the one that you input or to be the hash password and on that case you can use as many letters/numbers as you wish, password can be of any lenght, etc ....
Also if you unlock the HDD password but you have a BIOS password you will not be able to unlock the BIOS. But i'm assuming it's just the HDD password.



Thanks for the offer. But data can not leave the building if net encrypted. So sending disks out like that is not an option.

The laptops only have harddisk lock.

It is mainly T4x0s and T5x0 laptops.

There are also 16 T60 laptops, used for education, but they have to be replaced before the end of the year.

I thought Victoria could format/delete the password intirely. The same was my thought about MHDD.
That was my understanding after googeling a lot over the past week.

Jgaard


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: December 1st, 2013, 12:42 
Offline

Joined: November 25th, 2013, 15:30
Posts: 6
Location: Denmark
Spildit wrote:
Jgaard wrote:
Spildit wrote:
Solution 4 - Send the drives to me (Portugal) and i will unlock them for a price $$$$

Well, what is the model of the drives ?

What is the model of the laptops ?

If it's recent WD drives on recent lenovo you will not be able to access SA of the drive with the password on.

The idea of entering the password by Victoria or MHDD might NOT be a good one, because the lenovo laptop might hash the password that you type and lock the drive with the hash, not with the password you entered.

Does the laptops have BIOS lock or just HDD lock ?

I have one lenovo T60 and there are some settings that can be done at BIOS that allow for the ATA password to be the one that you input or to be the hash password and on that case you can use as many letters/numbers as you wish, password can be of any lenght, etc ....
Also if you unlock the HDD password but you have a BIOS password you will not be able to unlock the BIOS. But i'm assuming it's just the HDD password.



Thanks for the offer. But data can not leave the building if net encrypted. So sending disks out like that is not an option.

The laptops only have harddisk lock.

It is mainly T4x0s and T5x0 laptops.

There are also 16 T60 laptops, used for education, but they have to be replaced before the end of the year.

I thought Victoria could format/delete the password intirely. The same was my thought about MHDD.
That was my understanding after googeling a lot over the past week.

Jgaard


Victoria/MHDD would work if you were to know the correct password.
Now if you input a password on the lenovo and the lenovo hash the password and send a "hash" instead of what you typed to the HDD, even if you know the password and input it to the drive it will be wrong password because the correct one is the hash.
Best chance is to unlock the drives directly.
What are the model of the drives ? WD ones ? Seagates ?




Lenovo does hash (or use keyboard output codes) so the drives can not be unlocked by an HP desktop.
For how long should ZU run?
Is it possible to move the drive to an HP desktop and do some sort of lowlevel formatting that clears the password?

The drives are a mix. I've seen ST, WD and HGST. There is no way of telling what the next might be.

JGAARD

EDIT: I'm tsting on my old R61 at the moment ZU says 3:03:34.... It has been running for 30 min.


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: December 1st, 2013, 13:22 
Offline

Joined: July 2nd, 2011, 14:16
Posts: 463
Location: England
looks like it might be good idea to take another look at that excel workbook that contains all the passwords. The best thing is to recover the original file. What excel version did you use. Sometimes excel creates a backup copy in the application data folder. Do you have a backup copy?

Shane


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: December 1st, 2013, 13:53 
Offline

Joined: November 25th, 2013, 15:30
Posts: 6
Location: Denmark
ShaneWard wrote:
looks like it might be good idea to take another look at that excel workbook that contains all the passwords. The best thing is to recover the original file. What excel version did you use. Sometimes excel creates a backup copy in the application data folder. Do you have a backup copy?

Shane


The workbook was shared on a network drive. It's not possible to revert the changes.


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: December 2nd, 2013, 14:27 
Offline

Joined: November 25th, 2013, 15:30
Posts: 6
Location: Denmark
Spildit wrote:
But look .....
If the drives are locked with ATA password then the users can't access the laptop to start with !

Assuming that what you have told is correct, there is a MAJOR issue with your story .... Just ask for the USER password for the drive and UNLOCK the drive with that ! End of story :)

You just need to ask for the users to provide the password or to unlock the drive themselfs. When the drive is unlocked you just remove the locking with a "dispwd" on MHDD, if you can't find a way to do that on the BIOS of the laptop. You don't need the MASTER password if you have the USER password instead.

When the drive is unlocked by ATA you can encrypt by software even if you don't know the master password.



Problem is that the user set user password. The user knows this. But we set Master password. You need the master password to completly remove the user password.
On Thinkpads you can set/alter both passwords.
The idea being that the master password gives you a backdoor should the user forget his user password.


Top
 Profile  
 
 Post subject: Re: When bad goes to worse for passwords.
PostPosted: December 3rd, 2013, 4:06 
Offline

Joined: August 3rd, 2012, 7:47
Posts: 396
Location: slovenija
Hello Jgaard,

you can try with Lenovo support
Next time when you set master password write it on paper put it in envelope nad then save it in safe.
For excel you can use create backup option in SaveAs window under Tools/General options .
Othervise as some pro in your country to help you solve this problem.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 69 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group