<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Can You Use A Knoppix Live Cd To Hack A Supposedly Secure Computer?  How Can You Ensure Security?</title>
	<atom:link href="http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/</link>
	<description>do you want to touch my cybermantic love machine?</description>
	<lastBuildDate>Fri, 10 Feb 2012 13:54:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: cyanne2a</title>
		<link>http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/comment-page-1/#comment-452</link>
		<dc:creator>cyanne2a</dc:creator>
		<pubDate>Tue, 23 Jun 2009 16:38:42 +0000</pubDate>
		<guid isPermaLink="false">http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/#comment-452</guid>
		<description>It is possible - but you can stop it by doing the following:
1. Put a password for the BIOS options
2. Remove CDROM from the boot devices list in BIOS</description>
		<content:encoded><![CDATA[<p>It is possible &#8211; but you can stop it by doing the following:<br />
1. Put a password for the BIOS options<br />
2. Remove CDROM from the boot devices list in BIOS</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin</title>
		<link>http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/comment-page-1/#comment-451</link>
		<dc:creator>Kevin</dc:creator>
		<pubDate>Tue, 23 Jun 2009 15:18:37 +0000</pubDate>
		<guid isPermaLink="false">http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/#comment-451</guid>
		<description>Nothing is ever totally secure. :)</description>
		<content:encoded><![CDATA[<p>Nothing is ever totally secure. <img src='http://rootlove.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin</title>
		<link>http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/comment-page-1/#comment-450</link>
		<dc:creator>Kevin</dc:creator>
		<pubDate>Tue, 23 Jun 2009 15:07:50 +0000</pubDate>
		<guid isPermaLink="false">http://rootlove.com/2009/06/23/can-you-use-a-knoppix-live-cd-to-hack-a-supposedly-secure-computer-how-can-you-ensure-security/#comment-450</guid>
		<description>To answer your questions,
1) Can you use a Knoppix live CD to hack a supposedly secure computer?
Simply put, yes.
2) How can I protect my laptop against such an attack?
Some basic physical security steps would be
-Take it with you.  If you can&#039;t do that, then ..
-Lock it in your desk, file cabinet, office, etc
-If you can&#039;t do that, then lock it in someone else&#039;s.
Some other technical security steps
(provided that these are allowed by company policy)
-Remove the CD Drive and Floppy as possible boot disks in the bios setup
-Then password protect the bios.
3) Would the administrator of my network even be able to detect such a hack?
No, not if done correctly.  A good forensic investigator (or hacker) can use a boot CD with an OS like Knoppix that can bypass Windows security and NTFS permissions.  The forensic OS is booted, the computers partitions are mounted as read only, and the necessary data can be captured usually using netcat or cryptcat to send a binary image of the disks or partitions to a remote location for later investigation.
There would be absolutely no trace on the hard disk or event logs of any of the activity EXCEPT that the system had been rebooted to boot the forensic OS CD.  However, just because there&#039;s a note in the system event log that the system went down and eventually came back up does not in any way indicate that a forensic image was taken.</description>
		<content:encoded><![CDATA[<p>To answer your questions,<br />
1) Can you use a Knoppix live CD to hack a supposedly secure computer?<br />
Simply put, yes.<br />
2) How can I protect my laptop against such an attack?<br />
Some basic physical security steps would be<br />
-Take it with you.  If you can&#8217;t do that, then ..<br />
-Lock it in your desk, file cabinet, office, etc<br />
-If you can&#8217;t do that, then lock it in someone else&#8217;s.<br />
Some other technical security steps<br />
(provided that these are allowed by company policy)<br />
-Remove the CD Drive and Floppy as possible boot disks in the bios setup<br />
-Then password protect the bios.<br />
3) Would the administrator of my network even be able to detect such a hack?<br />
No, not if done correctly.  A good forensic investigator (or hacker) can use a boot CD with an OS like Knoppix that can bypass Windows security and NTFS permissions.  The forensic OS is booted, the computers partitions are mounted as read only, and the necessary data can be captured usually using netcat or cryptcat to send a binary image of the disks or partitions to a remote location for later investigation.<br />
There would be absolutely no trace on the hard disk or event logs of any of the activity EXCEPT that the system had been rebooted to boot the forensic OS CD.  However, just because there&#8217;s a note in the system event log that the system went down and eventually came back up does not in any way indicate that a forensic image was taken.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

