Quantcast
Channel: BIOS – What's My Pass?
Viewing all 11 articles
Browse latest View live

How to Bypass BIOS Passwords

$
0
0

BIOS passwords can be add extra layer of security for desktop and laptop computers, and are used to either prevent a user from changing the BIOS settings or to prevent the PC from booting without a password. BIOS passwords can also be a liability if a user forgot their passwords, or if a malicious user changes the password. Sending the unit back to the manufacturer to have the BIOS reset can be expensive and is usually not covered in an a typical warranty. However, there are a few known backdoors and other tricks of the trade that can be used to bypass or reset the BIOS password on most systems.

To enter the BIOS Setup try these keystrokes:

  • AMI BIOS:  Del key during the POST
  • DTK BIOS:  Esc key during the POST
  • Award BIOS:  Ctrl-Alt-Esc
  • misc BIOS:  Ctrl-Esc
  • Phoenix BIOS:  Ctrl-Alt-Esc or Ctrl-Alt-S
  • IBM PS/2 BIOS:  Ctrl-Alt-Ins after Ctrl-Alt-Del

Backdoor Passwords

Many BIOS manufacturers have provided backdoor passwords that can be used to access the BIOS setup in the event you have lost your password. These passwords are case sensitive, so you may wish to try a variety of combinations.

WARNING: Some BIOS configurations will lock you out of the system completely if you type in an incorrect password more than 3 times. Read your manufacturers documentation for the BIOS setting before you begin typing in passwords.

Award BIOS backdoor passwords:

ALFAROME BIOSTAR KDD ZAAADA
ALLy CONCAT Lkwpeter ZBAAACA
aLLy CONDO LKWPETER ZJAAADC
aLLY Condo PINT 01322222
ALLY d8on pint 589589
aPAf djonet SER 589721
_award HLT SKY_FOX 595595
AWARD_SW J64 SYXZ 598598
AWARD?SW J256 syxz
AWARD SW J262 shift + syxz
AWARD PW j332 TTPTHA
AWKWARD j322
awkward

AMI BIOS Backdoor Passwords:

AMI BIOS PASSWORD HEWITT RAND
AMI?SW AMI_SW LKWPETER CONDO

Phoenix BIOS Backdoor Passwords:

phoenix PHOENIX CMOS BIOS

Misc. Common Passwords

ALFAROME BIOSTAR biostar biosstar
CMOS cmos LKWPETER lkwpeter
setup SETUP Syxz Wodj

Other BIOS Passwords by Manufacturer

Manufacturer Password
VOBIS & IBM merlin
Dell Dell
Biostar Biostar
Compaq Compaq
Enox xo11nE
Epox central
Freetech Posterie
IWill iwill
Jetway spooml
Packard Bell bell9
QDI QDI
Siemens SKY_FOX
TMC BIGO
Toshiba Toshiba

Toshiba BIOS

Most Toshiba laptops and some desktop systems will bypass the BIOS password if the left shift key is held down during boot

IBM Aptiva BIOS

Press both mouse buttons repeatedly during the boot

Motherboard “Clear CMOS” Jumper or Dipswitch settings

Many motherboards feature a set of jumpers or dipswitches that will clear the CMOS and wipe all of the custom settings including BIOS passwords. The locations of these jumpers / dipswitches will vary depending on the motherboard manufacturer and ideally you should always refer to the motherboard or computer manufacturers documentation. If the documentation is unavailable, the jumpers/dipswitches can sometimes be found along the edge of the motherboard, next to the CMOS battery, or near the processor. Some manufacturers may label the jumper / dipswitch CLEAR – CLEAR CMOS – CLR – CLRPWD – PASSWD – PASSWORD – PWD. On laptop computers, the dipswitches are usually found under the keyboard or within a compartment at the bottom of the laptop.

Please remember to unplug your PC and use a grounding strip before reaching into your PC and touching the motherboard. Once you locate and rest the jumper switches, turn the computer on and check if the password has been cleared. If it has, turn the computer off and return the jumpers or dipswitches to its original position.

Removing the CMOS Battery

The CMOS settings on most systems are buffered by a small battery that is attached to the motherboard. (It looks like a small watch battery). If you unplug the PC and remove the battery for 10-15 minutes, the CMOS may reset itself and the password should be blank. (Along with any other machine specific settings, so be sure you are familiar with manually reconfiguring the BIOS settings before you do this.) Some manufacturers backup the power to the CMOS chipset by using a capacitor, so if your first attempt fails, leave the battery out (with the system unplugged) for at least 24 hours. Some batteries are actually soldered onto the motherboard making this task more difficult. Unsoldering the battery incorrectly may damage your motherboard and other components, so please don’t attempt this if you are inexperienced. Another option may be to remove the CMOS chip from the motherboard for a period of time.

Note: Removing the battery to reset the CMOS will not work for all PC’s, and almost all of the newer laptops store their BIOS passwords in a manner which does not require continuous power, so removing the CMOS battery may not work at all. IBM Thinkpad laptops lock the hard drive as well as the BIOS when the supervisor password is set. If you reset the BIOS password, but cannot reset the hard drive password, you may not be able to access the drive and it will remain locked, even if you place it in a new laptop. IBM Thinkpads have special jumper switches on the motherboard, and these should be used to reset the system.

Use the Debug command

Boot to MS- DOS prompt, run through the below example, this example is perfectly fine to run on any PC Computer running MS-DOS / Windows and will not harm anything.

DEBUG script that will just reset the password only

Type debug and press enter.   (ex.  A:\>debug )

After typing debug you will get “-” as a prompt ,type these exactly how they are written.

o 70 10
o 71 20
quit

Explanation of code:

DEBUG    ; Run DEBUG, “-” will appear on each line then type:
o 70 20     ; Send 70 to address 18
o 71 21     ; Send 71 to address FF
q              ; Quit DEBUG

or you can use this alternate DEBUG script that will just reset the the BIOS

A <ENTER>
MOV AX,0 <ENTER>
MOV AX,CX <ENTER>
OUT 70,AL <ENTER>
MOV AX,0 <ENTER>
OUT 71,AL <ENTER>
INC CX <ENTER>
CMP CX,100 <ENTER>
JB 103 <ENTER>
INT 20 <ENTER>
<ENTER> Note: Nothing is typed on this line
G <ENTER> By pressing G this will execute the above script
Q <ENTER>

Then reboot and you will get a Setup Checksum Error. Go into setup, correct all the incorrect values, time, date…


Alternatively you can use the program WipeCMOS from a boot floppy

Use the Decoding software

CmosPwd by CGSecurity – This is probably the most up to date and popular CMOS decryption tool. CmosPwd decrypts password stored in cmos used to access BIOS SETUP, you can also backup, restore and erase/kill cmos.You will have to be logged in as administrator, run ioperm -i command and then run cmospwd_win.exe

PC CMOS Cleaner – PC CMOS Cleaner is an easy-to-use tool to recover, delete, decode and display the superior passwords stored in BIOS whatever the brand is. It’s an bootable CD that runs on x86 and x86_64 computers. It can display the superior passwords of the BIOS, remove BIOS password(will set the BIOS to default status, need reset date).


Resetting Dell BIOS with a paperclip

$
0
0

Here’s a .pdf by Fastback68 which appears to to compiled from qasimtoep’s old website explaining how to reset a Dell BIOS password using a paperclip.The laptop that was used in this demonstration is a Model 630 type PPX.

There are a lot of people who have a dell or similar laptop that they are not able to use because of a special password chip that can’t be cleared by resetting the CMOS using software or by removing the battery. The chip that Dell uses is called a 24C02 chip. Dell will not give any help to these people without verifying that they are the original and registered owners of these laptops. Their justification is that it is part of their security / anti-theft program, and keeps people from stealing their laptops or accessing their data.

Included in the .zip file with the .pdf are instructions that show you step by step instructions on how to reset the chip  by using a paperclip and how to remove a laptop bios battery for Dell computers that support the resetting of passwords using that method (Latitude L400 is used)

Programs to create a bootable thumbdrive,CD or floppy to remove the Dell Service Tag Number from the bios.

Master Password Generator: If your SERVICE TAG ends in D35B then you can use this to generate a password for your laptop, IT WILL NOT WORK FOR SERVICE TAGS ENDING IN 595B.

Also as an added bonus a simple vbs script that shows you your Dell Service Tag Number while in Windows

on error resume next
strComputer=InputBox ("Enter the computer name of the server you'd like to query for Service Tag")
Set objWMIservice = GetObject("winmgmts:\\" & strComputer & "\root\cimv2")
set colitems = objWMIservice.ExecQuery("Select * from Win32_BIOS",,48)
For each objitem in colitems
Wscript.echo "Dell Service Tag: " & objitem.serialnumber
Next

also this site has a good tutorial http://www.weeklygripe.co.uk/a709.asp

Toshiba Laptop BIOS Recovery

$
0
0

Toshiba laptops aren’t like most laptops where you can remove the BIOS battery and let it sit for a few hours to reset the BIOS. So what do you do? There are three forms of BIOS password removal being used currently by Toshiba:
1. Parallel port wraparound connector
2. Shorting a jumper, with power and with no power
3. Challenge/Response code

Method 1. Printer Dongle Method:

Works with Portege, Satellite, Satellite Pro, Tecra and Libretto Laptops of the following model numbers :

100(1xx) 200(2xx) 300(3xx) 400(4xx) 500(5xx) 600(6xx) 700(7xx)
1000(1xxx) 2000(2xxx) 3000(3xxx) 4000(4xxx) 7000(7xxx) 8000(8xxx)

(A15-S 127) (1415-S 173) SERIES & Some DVD Models
The “xxx” above means that each x can be any number, i.e. 1xx could be 101, 103, 111, 112 etc.

* First cut a plug from an old DB25 printer cable, and open the casing of the plug. This is how the pins look:

* Now connect:
o Pin 1 to Pin 5 and to Pin 10 ( go from 1 to 5 and from 5 to 10)
o Pin 2 to 11
o Pin 3 to 17
o Pin 4 to 12
o Pin 6 to 16
o Pin 7 to 13
o Pin 8 to 14
o Pin 9 to 15
o Pin 18 to 25

It should look something like this:

Plug it in and bootup

METHOD 2. Shorting a jumper:


In order to clear a BIOS of Compal manufactured units you need to use the NO POWER method, units manufactured by Inventec need to be to be POWERED ON to rest the BIOS.

To reset Compal units:

1. Turn off the POWER
2. Remove the battery and power cord
3. Peel back any black mylar (if any) covering the jumper
4. Using a flat screwdriver, short the jumper by connecting the two jumper points
5. Reset the computer and verify the BIOS has been reset, if not then repeat steps

Inventec units can skip steps 1 and 2

METHOD 3. Challenge/Response Code:


The challenge/response code method consists of matching a Challenge code ( power the machine up,press ctrl,then tab,then ctrl, then enter) generated on your machine and matching a Response code generated by Toshiba and calling a Toshiba Tech Support Agent.


added 5/31/10:

Satellite p100 and pro p100 : with laptop off,remove wifi card and short pads marked jp8 for 10 secs

satellite l10,l20,l30 and pro l20 : with laptop of short pads marked jp1 for 15 secs (l20 short pads marked g1)

satellite m100 and tecra a6 : with laptop off ,remove memory and insulation under memory and short pads marked clr1 for 15 secs

(satellite 17** series,1100,1110,1130, 1200, 1900, 2430, 3000 P20,P30, P33, A30, A70, A80, M40X, M50,M60, M70, M100)as above

tecra a3,s2,a5,a6 : pads are by memory modules and will be labeled J1, J2, J5, J7, J9 or clr1

satellite a100,tecra m7 : remove keyboard and short pads marked c88 while turning laptop on, remove short as soon as Toshiba logo appears

Satellite A100 (PSAA2A-02C01N) : Remove Memory Cover from base of machine
Release & remove right side Memory Module,Lift black plastic insulation
Locate & short PAD500 Pin 1 & 2 together,Power on machine while still shorting Pin 1 & 2
As soon as the TOSHIBA logo appears, remove short

TECRA A4 & Satellite M40

Open modem & Wi-Fi card cover,Remove mini PCI Wi-Fi card
Lift up black plastic,Locate & short C738 Pads 1 & 2 together
Power on machine while still shorting Pads 1 & 2
As soon as the TOSHIBA logo appears, remove short

tecra s1 : TECRA S1

Open palm rest cover,Remove mini PCI Wi-Fi card
Lift up black plastic,Locate & short C5071 Pin 1 & 2 together
Power on machine while still shorting Pin 1 & 2
As soon as the TOSHIBA logo appears, remove short

NOTE SOMETIMES THESE WILL TAKE A COUPLE OF TIMES TO WORK,BUT THEY WILL WORK.

Fujitsu Siemens laptop BIOS Master Pass Generator

$
0
0

This python script generates master passwords which can be used to unlock the BIOS passwords of most Fujitsu Siemens laptops (Lifebook, Amilo etc.) http://dogber1.googlepages.com/pwgen-fsi.py

Spunlock BIOS Cracking Services

$
0
0

Over this past week I had a job come in the shop of a Sony Vaio laptop that had a bad motherboard. I had searched on Ebay for a cheap buy and settled on someone who had the same motherboard for about $100 less than anyone else. When I received the motherboard I promptly installed it , upon powering it up I was faced with a password prompt. Dammit! The motherboard had a BIOS password that wasn’t mentioned in the auction. Now being that I know most known methods for bypassing BIOS passwords, Sony has no known method of removing the password. I talked to a few friends and was forwarded to http://spunlock.com .

I was a bit weary at first about paying for a service , but the customer needed their laptop back that day to go on a trip. So getting the customer’s O.K. I purchased the BIOS cracking service.In order to get the correct challenge response BIOS code for most laptops you needs to enter the password incorrectly 3 times, after the third time , the BIOs should spit back a challenge code, this is what they need in order to crack the code.

After sending the payment and challenge code,much to my amazement 1 1/2 hours later I was opening an email with my code to remove the BIOS password. I punched it in and I was now watching Windows starting up. Spunlock has BIOS cracking support for many laptop brands like Dell,Fujitsu,Sony (of course) and more. So for you Techs and others who got burned on ebay, or people who simply forgot their password , give them a shot, you have nothing to lose, Don’t forget to mention whatsmypass.com in your email to them :)

ACER:SOME
ADVENT:SOME
ASUS:SOME
COMPAQ:SOME
DELL:ALL + 2A7B
E-SYSTEM:SOME
FUJITSU SIEMENS:ALL
HP:SOME
PACKARD BELL:SOME
PHILLIPS:SOME
SAMSUNG:SOME
SONY VAIO:ALL
TOSHIBA:SOME

Recover IBM Thinkpad Bios Password from the EEPROM

$
0
0

atmel chip

Did your IBM ThinkPad Supervisor password? This involves a bit more than just removing the backup battery, the supervisor (SVP) password is stored in a chip called ATMEL 24RF08. It can not be reset by disconnecting the BIOS battery or shorting any jumper. SoDoItYourself has an article detailing the retrieval of password data from an EEPROM. Although IBM claims their TP BIOS passwords are impossible to break, there is a easy and cheap way to fix this. The stuff you need cost about 5 $ at your closest radio shack type of store, you will also you need a spare PC with a serial port. Once you have done all the soldering you will also needs these 2 programs to help you dump the password
http://www.allservice.ro/forum/viewtopic.php?t=61 –programmer
http://www.allservice.ro/forum/viewtopic.php?t=56 –IBMpass Lite
http://h1.ripway.com/hdst/dl/ alternative dl site

via: sodoityourself.com/

BIOS Password Recovery

$
0
0

WhatsMyPass now introducing BIOS Password Recovery Services!!!
We can recover Dell (2A7B, 595B, A95B or D35B service tag), Sony VAIO PCG & VGN models, Samsung,Fujitsu-Siemens, Hewlett-Packard, Compaq, Phoenix BIOS. You will receive the password within a few hours, sometimes almost instantly. The price is only $10 per password recovered, if we can’t recover it, you get your money back.

For more info and a list of supported computer models visit here:
BIOS Password Recovery Service


In order to serve you better when purchasing this service, if possible please enter the challenge/response hash with order. If you don’t know how to get the challenge hash, please email us first.
Enter Challenge Hash and click “Pay Now”:

HP Mini BIOS password recovery

$
0
0

We are now offering BIOS password recovery for HP/Compaq Mini netbooks.
How it works: Enter 3 incorrect passwords, after the third attempt you will be given a 10 character error code (ex: CNU92347K21)

This is the code you need to send along with your laptop model. If you have any questions please emails us before sending payment.

Enter Challenge Hash and laptop model and click “Pay Now”:


CMOS De-Animator

$
0
0

Sometimes when you can’t enter the BIOS because there is a password, but you can still boot into windows, you can try to use CMOS De-Animator to clear the BIOS settings. Works on both 32 and 64 bit. In the event that it doesn’t work try to use our BIOS password recovery service. CMOS De-Animator can be downloaded from the author’s website ::HERE::

HP Probook/Elitebook BIOS Password Reset [Utility]

$
0
0


There are now 2 versions of the tool created by Mazzif. The Original Windows based system what creates a key based on your input, or the new DOS based tool that gets all parameters automatically. See this [ Post ] for information on the newest release. The windows based solution offers a bit better support for more models, while the DOS tool-set is just easier to use.

[SUPPORTED MODELS]
HP 6550B, HP 2530P, HP 6930P, HP 8530W, HP 8460P, HP 6460B, HP 2230S ,HP 6455B, HP 2730P, HP 8530P, HP 2740P, HP 4310S, HP s4510, HP 6535B, HP 6730B, HP 6735B, HP 8730W, HP 2560P, HP 8560P, HP 8440P, HP 8540W, HP 8560W
If your model is not listed you may experiment with the ‘Make All’ or SHOTGUN.


[UPDATE BIOS]

If you need to update your BIOS, see this post here: http://bit.ly/Kp5yAv

[USE]
To use this system, select your supported hp probook/elitebook model
from the drop-down list. The Serial Number field and UUID Filed will need
to be populated with data. This data needs to be that of your own
laptop’s. Booting to this thumbdrive (if this package was created from official .img)
will obtain this information automatically and can be imported.

Once data is entered/imported into the fields, click the ‘make key’ or ‘Make All’ button and a file will be
created in the /output folder.

You may then reboot to this thumbdrive and CD to ‘output’ and run your exe file, or CD to ‘\output\all’
and run shotgun.bat

[ABOUT]
Displays this information


[IMPORT]

Booting to this USB Drive will collect information about your and save it to file.
Clicking ‘Import’ will read the information and fill out the fields automatically.
If you have noot booted this thumbrive, there will be nothing to import.

[MAKE ALL]
Is your modle not on the list? Use the ‘Make All’ button to create all posible
keys Using your UUID and SN. This will output them to the ‘\output\all’ directory.
This will also create shotgun.bat file. Boot to this thumbdrive and CD to ‘\output\all\.
Run shotgun.bat.

[MAKE KEY]
This makes a single Key based on your SN and UUID for the selected Model.
file will be created in the ‘\output’ folder.
Reboot to this thumbdrive and CD to ‘\output’ and run your exe file.

[LOCKED BOOT ORDER]
If your BIOS has a locked set boot order, and will only boot to HDD,
you need to take a laptop sata drive and use an external adapter and
make it dos bootable on another host machine also placing the files
on this drive, then replace the internal hdd with your created dos
boot-able HDD. Powering on the machine will boot to the dos
environment. Using DOS commands, navigate to your files and
execute them following directions on screen. BIOS will be free of
passwords, TPM will be cleared.

[VIDEOS]

http://www.youtube.com/watch?v=AwwpuAs-Ug0

Updated DELL BIOS Recovery

$
0
0

We now can generate master BIOS passwords for  1D3B, 1F66, 6FF1 type DELL computers, Please visit our bios password recovery service page for DELL and other brand BIOS recovery options.

Viewing all 11 articles
Browse latest View live