Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Microsoft > Security

August 23rd, 2012, 14:27 GMT · By

Windows 7 and Windows 8 Registries Reveal Password Hints, Researchers Find

SHARE:

Adjust text size:

Password hint location
Enlarge picture
Security researchers have identified a registry in both Windows 7 and Windows 8 which contains user password hints. The precious data is encoded, but as experts have demonstrated, it’s not that difficult to break the encryption.

Passwords are a hot topic these days. If users choose them wisely and keep them secure, companies are the ones to expose them. In other cases, when website owners make sure that their systems are bulletproof, their customers choose passwords such as “123456.”

This is another article about password security and it’s based on research performed by Trustwave’s SpiderLabs. They identified a registry key called “UserPasswordHint” in the SAM database, located at HKLM\SAM\SAM\Domains \Account\Users \<userkey>\UserPasswordHint.

A system administrator can easily read the key by doing a query, but as expected, the hint is encrypted. However, this turned out not to pose such a great challenge to the experts after they noticed a pattern of zeroes (see screenshot).

“Having dealt with a fair amount of PHP malware in the last couple months, one of things the 'baddies' do is chunk up their payload data into individual characters and then encode them in their ASCII numerical representation,” Jonathan Claudius of SpiderLabs explained.

“Well in looking at this registry value, it seemed to follow a similar approach, so I wrote a little decoder in Ruby to see if I could learn this users password hint.”

The decoder worked perfectly and in no time the password hints were revealing themselves.

Since this could be of great aid to penetration testers, the experts integrated the decoder into Metasploit.

While the exposure of password hints could represent a risk for users, in reality, it shouldn’t. Microsoft, for instance, recommends customers to choose a hint that is “vague enough so that nobody else can guess the password, but clear enough that it will remind them of their password.”


6,874 hits · 2 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


avast! 7.0.1466 Product Suite Released

Opera 12.02 Very Close to Release Candidate Stage

Expert on Windows 8 Interface: Confusing, Burden on User’s Memory

Microsoft Releases Live SDK 5.2 in Final Version

Download the Latest Google Chrome 21 Stable Security Fix and the Updated Chrome 22 Dev

READER COMMENTS:


Comment #1 by: Xertox on 29 Aug 2012, 03:13 UTC reply to this comment

Awesome, I can't wait to try to find it on my system!


Comment #2 by: Fleet Command on 22 Sep 2012, 12:25 UTC reply to this comment

Very funny! Why did they researched something that Microsoft has already published? It is possible to query password hints using WMI. Furthermore, EVERYONE can read password hints from the logon screen without access to registry.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM