Results 1 to 8 of 8
  1. #1

    Default Deep Freeze In Deep Trouble


    Deep Freeze In Deep Trouble

    A black-hat computer programmer in Argentina with a grudge against Faronics, Emiliano Scavuzzo, has written a program to thaw Deep Freeze without knowing the password. It works on almost ALL versions of Deep Freeze, including the latest version, v5.60.120.1347, which recently came out (Oct-20-2005) to supposedly be immune to his program—it's not! You can use Deep Unfreezer to test for the vulnerability on your own machines:

    Deep Freeze Unfreezer
    http://usuarios.arnet.com.ar/fliama...punfreezer.html

    Method 1:

    To perform the test you must first acquire DebugPrivileges (removed by Deep Freeze) by escalating to NT_AUTHORITY (the System account) using Task Scheduler from the command line (Start/run, cmd):

    1) Type: at 11:23pm /interactive taskmgr.exe (add one or two minutes from the current time)
    2) Once Task Manager launches End Task explorer.exe
    3) File / New Task (Run...), Enter explorer.exe to launch the explorer shell under the System account which has Debug Privileges
    4) Run Deep Unfreezer from the System account.

    Method 2:

    OR, use ntrights.exe from the Windows Server 2003 Resource Kit, a free download, http://tinyurl.com/6p6cy, to grant yourself the SeDebugPrivilege.
    Syntax: ntrights -u Users +r SeDebugPrivilege
    If you use ntrights, you must logoff and logon again for the privilege to take effect.

    Then run Deep Unfreezer, View Status, click on the Boot Thawed button, Save Status, and restart the machine. If the machine reboots in thawed mode, your version of Deep Freeze is vulnerable, and you should take measures to provide additional security on your machines.

    Deep Freeze Evaluation versions are also vulnerable to this attack. Deep Freeze Evaluation versions can be taken off machines by an attacker by forwarding the system date past 60-days which will expire Deep Freeze, causing the computer to restart in thawed mode, allowing Deep Freeze to be uninstalled. If you're using an evaluation version of Deep Freeze, here's how to perform this test:

    Method 1:

    1) Switch to the System account, as described above
    2) Double-click the time in the system tray
    3) Forward the date past 60-days
    4) Restart in thawed mode
    5) Use DeepFreezeSTDEval.exe to uninstall Deep Freeze. Deep Freeze is not uninstalled through Add/Remove Programs. It is uninstalled with the installation file, and ONLY with the installation file. Yes, the same file is used to install and uninstall. If you don't have it, download it here. It's a free download:

    Deep Freeze Evaluation -Trial Version - v5.60.120.1347
    http://www.faronics.com/exe/DeepFreezeSTDEval.exe

    Method 2:

    Or, use ntrights.exe from the Windows Server 2003 Resource Kit to grant yourself the SeSystemtimePrivilege.
    Syntax: ntrights -u Users +r SeSystemtimePrivilege
    You must logoff and logon again for the new privilege to take effect.

    Special Note:

    Faronics came out with v5.60.120.1347 on 10-20-2005 as a response to Deep Unfreezer. It proved to be an impotent move. Emiliano's response to the new version? "rename frzstate2k.exe to anything else. Then attach to DF5Serve.exe instead". Does that work? Yes, it does. Thus, the newest version of Deep Freeze, intended to thwart Deep Unfreezer, continues to be vulnerable.

    Deep Freeze protects over four million computers world-wide and over one million Macs (Yes, there's a Deep Freeze for Mac). And most of them are vulnerable to this attack. At this time Faronics does not have a fix, nor an immune version. If you are a network administrator in charge of maintaining a network of machines protected by Deep Freeze, please be advised of this situation and be prepared.

    Faronics does not seem to be taking this seriously. They only made a token effort to thwart Deep Unfreezer in their latest version. Until they get serious about things, Deep Freeze is going to be melting away in the eyes of those who have grown to love and trust the program.

    One of the main issues is the fact that so many computers these days allow Administrator status. Even a lot of internet cafes use Windows XP Home edition, with the user logged in as Administrator. The developers at Faronics are committed, however, to protecting the machine even from Administrators! The problem with that is, as you know, whatever is taken away from an Administrator, the Administrator can give back to herself. So if, for example, Deep Freeze removes DebugPrivileges, users can simply grant it back to themselves.

    Another issue is their commitment to non-restrictive use. Their commitment with Deep Freeze is to protect the machine non-restrictively. That has worked... until now. I think they may be forced at this point to admit Administrator accounts can't be guaranteed protection any longer. Unless they can secure these issues, I don't see any other way.



    -------------------------------------------------------------------------------------------------------------------------------------------------

    ahak ambot kung tinood ni... the source: h++p://www.itfreaks.com/forum/deep-freeze-in-deep-trouble-5660.html

    Sorry for posting this sh*t here... but this will definitely be of good use to them Deep Freeze users here in Cebu, especially iCafe owners/admins/managers like me...

  2. #2

    Default Re: Deep Freeze In Deep Trouble

    this is the reason why i don't trust an all in one security tool. better use the conventional anti-intrusion tools.

  3. #3

    Default Re: Deep Freeze In Deep Trouble

    sure jd ni bro?bsg gba sd imo boot file sa deep freeze ani...

  4. #4

    Default Re: Deep Freeze In Deep Trouble

    switch nalang to shadow user when deep freeze unfreezer becomes widespread.

  5. #5

    Default Re: Deep Freeze In Deep Trouble

    hehehe.. i always believe there's no 100% secured PC... no matter what O.S. you're using...



    @acronis

    natry naka ining shadowuser? nindut ni bro? naka try kog deep freeze.. pero morag dili man niya ma freeze gyud ug maayo ang pc.. kay nakasulod man ang folder.htt ug iya mga kauban...hehehe hibolong gani ko nga nakafreeze gud...

    tnx bro!

  6. #6

    Default Re: Deep Freeze In Deep Trouble

    mga bro. asa ta ana maka download ana unfreezer na software para sa deepfreeze....dili man ma open nako ang ghatag na URL....

  7. #7

    Default Re: Deep Freeze In Deep Trouble

    bai asa ta maka download shadowuser nga trial !!!! can give me the site!

  8. #8
    Junior Member
    Join Date
    Sep 2005
    Gender
    Male
    Posts
    469

    Default Re: Deep Freeze In Deep Trouble

    bai ang folder.htt,ug destop.ini naa na daan sa system files!

    kung natingala ka nga maka sulod ang mga ginagmay nga virus.kay naay time nga ma unfreeze nimo or ma boot thawed ang deepfreeze,automatic sulod jud daun ang virus ana so dili jud ka maka ingon nga 100% wlay virus imo system unit!

  9.    Advertisement

Similar Threads

 
  1. Nvidia is in Deep Trouble...!!!
    By estoyra in forum Computer Hardware
    Replies: 89
    Last Post: 04-21-2010, 07:09 PM
  2. Replies: 7
    Last Post: 09-16-2009, 07:47 PM
  3. which is better, deep freeze or norton goback?
    By burdagol in forum Software & Games (Old)
    Replies: 17
    Last Post: 06-06-2009, 10:18 PM
  4. Deleting deep freeze file in BIOS' using boot disk
    By l3inad in forum Software & Games (Old)
    Replies: 1
    Last Post: 01-05-2007, 02:14 PM
  5. Anybody Know About Deep Freeze?
    By Subzero in forum Software & Games (Old)
    Replies: 42
    Last Post: 09-26-2005, 09:05 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
about us
We are the first Cebu Online Media.

iSTORYA.NET is Cebu's Biggest, Southern Philippines' Most Active, and the Philippines' Strongest Online Community!
follow us
#top