<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MCB Systems &#187; kon-boot</title>
	<atom:link href="http://www.mcbsys.com/techblog/tag/kon-boot/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mcbsys.com/techblog</link>
	<description>Custom Software and I.T. Services</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:58:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Kon-Boot vs. Windows 7 BitLocker</title>
		<link>http://www.mcbsys.com/techblog/2009/10/kon-boot-vs-windows-7-bitlocker/</link>
		<comments>http://www.mcbsys.com/techblog/2009/10/kon-boot-vs-windows-7-bitlocker/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 10:33:58 +0000</pubDate>
		<dc:creator>Mark Berry</dc:creator>
				<category><![CDATA[IT Administration]]></category>
		<category><![CDATA[bitlocker]]></category>
		<category><![CDATA[kon-boot]]></category>
		<category><![CDATA[password recovery]]></category>

		<guid isPermaLink="false">/mark/post/Kon-Boot-vs-Bitlocker.aspx</guid>
		<description><![CDATA[I&#8217;ve been running Windows 7 with BitLocker for a couple months and am quite pleased with it. BitLocker encrypts the hard drive so that if my laptop is lost or stolen, it should not be possible to access the data on the drive even if you remove the drive and attach it as a second [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been running Windows 7 with BitLocker for a couple months and am quite pleased with it. BitLocker encrypts the hard drive so that if my laptop is lost or stolen, it should not be possible to access the data on the drive even if you remove the drive and attach it as a second drive to another system.</p>
<p>Recently though I read about a password &#8220;bypass&#8221; program called Kon-Boot that dynamically replaces the Windows kernel during bootup and allows logging in with <em>any</em> password. I wondered if BitLocker was vulnerable to this kind of program. If a thief could simply log on to my BitLocker-protected system, the encryption would be useless.</p>
<p>So I decided to give it a try.</p>
<p><span id="more-30"></span></p>
<p><strong>Caveat:</strong>&#160; I have no idea if Kon-Boot can harm a computer and/or upload data. Even with a full backup, there is a risk that it might corrupt the BIOS or otherwise make the computer unusable. Use at your own risk.</p>
<h1>BitLocker Kicks Kon-Boot</h1>
<p>So I booted Windows 7 with the Kon-Boot disk in the CD drive. BitLocker promptly reported that &#8220;the system boot information has changed&#8221;:</p>
<p><a href="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20001_2.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="BitLocker 001" src="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20001_thumb.jpg" width="244" border="0"></a></p>
<p>When I pressed Enter to continue, BitLocker prompted me for my password (Label and ID blacked out):</p>
<p><a href="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20002_4.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="BitLocker 002" src="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20002_thumb_1.jpg" width="244" border="0"></a> </p>
<p>I didn&#8217;t want to actually change the BIOS, so I didn&#8217;t provide the password. I got this screen:</p>
<p><a href="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20003_2.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="BitLocker 003" src="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20003_thumb.jpg" width="244" border="0"></a> </p>
<p>After rebooting without the Kon-Boot CD, I got this heart-stopping message:</p>
<p><a href="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20004_2.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="BitLocker 004" src="http://www.mcbsys.com/techblog/wp-content/uploads/WindowsLiveWriter/KonBootvs.Bitlocker_9494/BitLocker%20004_thumb.jpg" width="244" border="0"></a> </p>
<p>Had Kon-Boot in fact damaged my system? Fortunately after another reboot, Windows 7 came up fine.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcbsys.com/techblog/2009/10/kon-boot-vs-windows-7-bitlocker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

