Passware Kit (http://www.lostpassword.com/kit-forensic.htm) is the first commercial software that recovers login passwords for Mac OS users in a matter of minutes. It supports all modern versions of Mac OS, including 10.6 (Snow Leopard) and 10.7 (Lion), the latest version. The software acquires the target computer memory image over FireWire, and then scans it and extracts login passwords for the given system.
I did some research on this and was hoping you could answer a question:
Apple put into place some protections around dumping RAM while the screen saver is active and requires a password. I know in most states that it is possible to work around this (i.e. if you can get to the fast user switching menu.) Can you still dump if user switching is turned off and the system is locked?
Also, this same attack is possible using libforensic1394, but requires a reasonable level of technical competency.
frameloss 5 months ago