Want a daily update via mail ?

57 feed subscribers

Distant-Help vitals

Blog Stats
Google Page Rank
1,979,330
594
75
18

MacLockPick : Crack a MacIntosh with a simple USB stick

Via another site I often read about Mac’s I stumbled on this program for officials. With it, they can simply crack your computer and it’s data. Simple easy. Let’s hope that MacIntosh closes this ability quickly, or even better the community. This is just plain unacceptable. Imagine what happens if this is thrown into the hackers world. Won’t take long before they resample this to remote tools to get in your computers.

this is the official description :

MacLockPick™ is a valuable tool for law enforcement professionals to perform live forensics on Mac OS X systems. The solution is based on a USB Flash drive that can be inserted into a suspect’s Mac OS X computer that is running (or sleeping). Once the software is run it will extract data from the Apple Keychain and system settings in order to provide the examiner fast access to the suspect’s critical information with as little interaction or trace as possible.

A database of the suspects information is compiled on the Flash Drive to allow for easy transportation away from the suspect’s system. This database can be read by the included log readers on Microsoft Windows, Linux, or Apple Mac OS X computers back at base.

    Items recovered from the suspect’s computer.

The following is a list of file items that can be extracted using SubRosaSoft’s MacLockPick:
Apple Keychain Passwords

* System – The user password of the logged in user. Often this is shared for root access and FileVault encryption.
* General – Includes (but is not limited to) passwords for encrypted disk images, wifi base stations, iTunes music store, iChat login, Apple Remote Desktop.
* Internet – Includes (but is not limited to) login and password details for web sites, email accounts, some peer to peer networks, online services and stores, auction sites, and .mac accounts.
* AppleShare – A list of login and password details for appleshare servers this mac has connected to.

Files and Folder details

* Folder Dates – A list of all the key user folders along with their creation date, date of last modification, date of first access, and date of the most recent access.
* Disk Images – Paths to the most recent disk images that have been mounted on this mac.
* Preview – Full paths to recent files that have been viewed in the preview program.
* QuickTime – File names for recently viewed movies fro the QuickTime player applications
* Recent Applications, Documents, and Servers – Program names for the most recently used items on this Macintosh computer.

Instant Messaging

* Default Login – for iChat instant messenger system.
* Complete buddy list – including buddies who have since been deleted.

eMail

* Account Details – login names and server addresses used.
* Address Book – Address details for entries in the address book including contacts that have been deleted. This address book is used by most communication programs on the Mac and is used to synchronize with the iPod and other portable devices.
* Opened Attachments – Paths to files that have been received as an attachment then saved or opened including the date and time of opening.

Web History and Preferences

* Search Strings – The most recent items that the user has searched for using the google toolbar in safari.
* Cached Bookmarks – Sites that have been bookmarked in Safari including items that have been deleted.
* Current Bookmarks – Sites that are currently bookmarked in Safari.
* Cookies – A full list of cookies include the server address the cookie value and the date and time of assignment.
* History – Complete details of browsing history including the number of times visited and the date and time of the most recent visit.

Hardware Preferences

* iPod – Serial numbers of any iPod that have been connected to this Mac along with the date and time it was first used.
* Bluetooth Devices – hardware address of any bluetooth devices that have been paired with this mac along with the most recent time these devices have been paired.
* Wifi Connections – Listings for wifi base stations that have been used on this computer including the base address and the date and time of the first connection.
* Network Interfaces – MAC address for each integrated network interface on the suspect’s machine.

MacLockPick Features

Written specifically for Mac OS X, MacLockPick also includes log reader tools that can be used to access your suspect’s data even if you do not have a Mac.

Safety first – MacLockPick will never write to the disk or device being investigated. This makes the software “risk-free”. Instead MacLockPick simply extracts the data and saves it to it’s own flash drive.

Recovers files from sleeping computers – Once awakened a Mac will return it’s keychain access levels to the default state found when it was initially put to sleep. Suspects often (and usually) transport portable systems in this sleeping state.

Similar Posts:

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • Live
  • NewsVine
  • Propeller
  • Reddit
  • StumbleUpon
  • Technorati
  • Blogosphere News
  • LinkedIn
  • MisterWong.DE
  • MySpace
  • Slashdot
  • Yahoo! Buzz
  • Ping.fm
  • Twitter
  • Upnews
  • Yahoo! Bookmarks
  • MSN Reporter

Comments are closed.

Get Adobe Flash playerPlugin by wpburn.com wordpress themes