Sunday, October 7, 2007

It’s Apple Mac-Guyver: pocket sized detective tool hacks into computers

SubRosaSoft’s MacLockPick is a USB sized gizmo that can extract passwords, e-mail addresses, recently accessed files, search strings, bookmarks and internet history from running or sleeping computers. But the US$499 device can only penetrate the defences of Macs running OSX – apparently, anyone who manages to build an empire of crime using Windows deserves to keep it.



The “live forensics tool” is based on Flash drive technology and is available only to law enforcement officials - amateur gumshoes will have to tread the mean streets of the internet superhighway without it.


MacLockPick takes advantage of the fact that the default state of the Apple Keychain is open, even if the system has been put to sleep. It also makes use of the openly readable settings files used to keep track of your suspect's contacts, activities and history. These data sources even include items that your suspect may have previously deleted or has migrated from previous Mac OS X computers. The MacLockPick extracts data from the Apple Keychain and system settings to provide the examiner fast access to the suspect's critical information with as little interaction or trace as possible.


A database of the suspect’s information is compiled on the Flash Drive to allow for easy transportation away from the suspect's system. This database can be read by the included log readers on Microsoft Windows, Linux, or Apple Mac OS X computers back at base.
The following is a list of file items that can be extracted using SubRosaSoft’s MacLockPick:
Apple Keychain Passwords
System: The user password of the logged in user. General: Includes (but is not limited to) passwords for encrypted disk images, wifi base stations, iTunes music store, iChat login and Apple Remote Desktop. Internet: Includes (but is not limited to) login and password details for web sites, email accounts, some peer to peer networks, online services and stores, auction sites, and .mac accounts. AppleShare: A list of login and password details for appleshare servers this mac has connected to.

No comments: