• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Content Advisor Password :: Is it recoverable?

Arctic Fire

Weaksauce
Joined
Jul 25, 2008
Messages
74
Well, as the title says, I'm wondering if it's possible to recover the content advisor password. There are a thousand and one articles on how to remove it, but none (that I can find) on how to get the current one. I know that it's stored in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings as a value called "Key". But I don't know what type of encoding/compression/encryption/whatever is used.

Is it possible to recover the password, or maybe a MD5 or similar hash that can be brute forced using rainbow tables? Maybe I should rephrase this, since I'm sure with enough time, someone could use a debugger to figure out how Internet Explorer does the whole process, like making a keygen. Is it simple to recover said password?
 
Apparently no one thinks it is worth the time and effort to create a tool to show the existing password.

The question is why do you need to know the existing password when it is so simple to remove?
 
My school uses the same password for the content advisor as they do for the server's administrator account. I want to report the security risk in doing this, but I want to be able to back up my claim that the password can be obtained from the local computers, rather than just say "it's good practice". I don't know for sure that it can be obtained in this manner, which is why I'm asking on here.

Of course, some other precautions should be taken as well, like telling the IT guys not to give the admin password to students, which is how I got it. :D
 
Of course, some other precautions should be taken as well, like telling the IT guys not to give the admin password to students, which is how I got it. :D

No offense, but after that statement, this seems to be wanting to prove you can circumvent the security on the network you do not administer. Which isn't allowed here
 
Well, not actually prove it. I'm not asking how to do it. I just want to know if it can be done, so I can backup my claim. I think some of the computers have a local admin password that's the same, which would mean that the hash can be acquired pretty easily. However, since the password has a symbol in it, it would require special rainbow tables and a lot of time. I wanted to know if the content advisor password is also a point of weakness. If no body knows what kind of encryption is used to store it, then there's no need in bringing it up when I talk to someone about this.
 
Tell your school administrator that it is poor policy to use the content adviser as a means to enforce internet security on their network.

They should be using some kind of enterprise solution from Websense, Cisco Ironport, OpenDNS, anything.
 
It's not a big school, so probably can't afford Cisco or Websense. They've used OpenDNS in the past; I'm not sure why they stopped. I guess I'll just tell them of my theory that the content advisor password can be recovered and let them go from there. Thanks anyway for your time.
 
wow, don't have anything constructive too add, but geez, someone should fire your IT admin...
Posted via [H] Mobile Device
 
Back
Top