Releases: readloud/BIOSMasterPasswordGenerator
Release list
cmossave-47
CMOSSave CMOSRest CMOSChk restore corrupted CMOS from backup and check
that CMOS has not been tampered with. Featured in Karen Kenworthy's
Windows Magazine column October 1994 and April 1995, and Fred Langa's in
1999. It has also been bundled on the CDs that come with various books.
Note: progam is called CMOSsave (double s) not cmosave.
Naive users sometimes meddle with CMOS settings. We need a fast way to
put the scores of subtle CMOS configuration settings back the way they
were.
Power surges can corrupt CMOS. We need a way for a naive user to quickly
restore all the CMOS settings, (at least the first 128 bytes worth).
If the battery fails, the contents will be lost. We need a way to restore
a known working CMOS configuration.
CMOSRest restores ALL of CMOS, including the proprietary extended COMS
settings like wait states, clock speeds, shadow RAM etc. It does not
handle the proprietary extended cmos.
CMOSRest can also be used to toggle between two CMOS configurations, for
example with and without a removable hard drive installed.
CMOSChk can detect subtle corruption to CMOS, as might be caused by a
rogue program or a virus, something that might slow your machine or make
it unreliable.
The CMOS suite will work under DOS, Windows 3.x, Windows 95/98/ME or OS/2.
It partly works under NT, Windows 2000 and XP, Vista and Windows 7. see
comossave.manual.html for details. However, these utilities are intended
to be used mainly within autoexec.bat during the DOS phase of the boot.
Further, there will be spurious CMOS changes when you reboot between Win95
and NT.
Why the computer chip icon? It represents the CMOS chip on your
motherboard where the BIOS settings are stored.
cmospwd-5.0
=========================================================================
CmosPwd
Christophe GRENIER
grenier@cgsecurity.org
http://www.cgsecurity.org
CmosPwd is a cmos/bios password recovery tool.
CmosPwd is under GNU Public License. You can freely distribute it.
It can be compiled under Dos, Windows, Linux, FreeBSD and NetBSD.
Platforms
-
Dos-Windows version
Well, ... it works! -
Linux && BSD version
Users can work on cmos backup but they need root priviledge to
use ioperm function to have full access to cmos. -
Windows NT, 2000, XP, 2003
To work on cmos memory, ioperm need to be installed and running.
ioperm gives direct port I/O access for specified ports to user-mode process
(ring 3) using Ke386SetIoAccessMap and Ke386IoSetAccessProcess kernel functions.
1- You need administrator priviledges to install this driver
"ioperm.exe -i"
2- Start the service if needed with "net start ioperm"
3- Run "Cmospwd_win.exe"
WARNING: You should disable or uninstall ioperm
with "ioperm.exe -u" if you don't want to decrease
your security!
¦ Typical Usage for DOS and all Windows users ¦
-
Identify your BIOS manufacturer (usually displayed at boot-up)
-
Start in DOS, or start a DOS session in Windows 95/98/ME.
For Windows NT or Windows 2000 boot from a DOS or Windows 95/98 boot
disk (you can find boot disks at www.AnswersThatWork.com), and run
CMOSPWD from your boot floppy (or another floppy). -
C: [Enter]
cd \CMOSPWD [Enter] -
Type CMOSPWD at the DOS prompt and press Enter.
-
CMOSPWD will display a list of possibilities. Use the possibilities
itemised against your BIOS manufacturer.
Remember :a) For AWARD BIOSes, use the Numeric Keypad (with NumLock ON). b) AWARD 4.50PG BIOS always accepts "AWARD_SW", or "d8on", or "589589". c) Old Phoenix BIOSes will accept "phoenix". -
If the standard method does not work, then try to kill
the CMOS password with CMOSPWD /K (and press Enter),
and then see if you can get into the CMOS without a password.
If you can, you successfully "killed" the old CMOS password.
DO NOT KILL THE CMOS ON LAPTOPS!
|General Usage (List of commands) |
cmospwd [/d]
cmospwd [/d] /[wlr] cmos_backup_file write/load/restore
cmospwd /k kill cmos
cmospwd /m[01]* execute selected module
/d to dump cmos in ascii and scan code
/m0010011 to execute module 3,6 and 7
Keyboard:
/kfr French AZERTY
/kde German QWERTY
default is US QWERTY
|Laptops |
On laptops, the password is usually stored in an eeprom on the motherboard,
you need an eeprom programmer (electronic device) to retrieve it.
Acer 630: eeprom 93c56 ?
Compaq M700: eeprom 24C02
Dell Inspirion 5100: eeprom 93lc46, password in scan code at 0x310
Dell Inspirion 7500: eeprom 24c164
Dell Inspirion 8100: eeprom 24c02
Dell Latitude C600: eeprom 24c02, password in scan code at 0x00, 0x10 and 0x90
Dell Latitude C610: eeprom 24c02, password in scan code at 0x00, 0x10, 0x80 and 0x90
Dell Latitude CPI: eeprom 24c02, password in scan code at 0x00, 0x10, 0x80
Dell D600: eeprom 24c04, password in scan code at 0x110
IBM Thinkpad X20: eeprom 24RFC08CN, password in scan code at 0x338
IBM TP 240: eeprom ?, password in scan code at 0x338.
IBM TP 380Z: eeprom 24c01, password in scan code at 0x38 and 0x40
IBM TP 390: eeprom 24c03 (be carrefull, there are two eeprom)
IBM TP 560X: eeprom 24c01, password in scan code at 0x38 and 0x40
IBM TP 570: eeprom ?, password in scan code at 0x338 and 0x3B8.
IBM TP 750C,755CX,760C,765D: eeprom 93c46, password in scan code at 0x38 and 0x40
OKI M811b may be written on the chip. Search near pcmcia slot or
adjacent the floppy connector on the top side of the board
IBM TP 770: eeprom 24c01
IBM TP 600E, T21, T23: 14 PIN 24RF08
IBM TP T20,X20,X30: 24RF08, password in scan code at 0x338 and 0x340
HP Omnibook 900,2100,4150,7150: eeprom AT24c164, 0x6D-0x7F area, unknow algo
put a 00 at 0x7F to clear admin password
HP Omnibook 6000: eeprom 24c08 or 24c164 0x50-0xBF area
(maybe 0x50-0x6F only), unknow algo
HP Omnibook 6100: eeprom 24c08
HP Omnibook XE3: eeprom 24c16
HP Omnibook 770x: eeprom 24c01
HP Pavilion ze4455ea: eeprom 24c08
HP VECTRA VL18: http://h200001.www2.hp.com/bc/docs/support/SupportManual/lpv06673/lpv06673.pdf
Sony pcg-fx950: eeprom 93c46 ?
Toshiba 74600C: eeprom 93c56
VAIO 641: eeprom 24c02 write zero at 0x0
be carrefull, there are two eeprom you must unsolder one to the pci
controler it is in the down side of the bord
VAIO 8851
eeprom 24c02 (ic 903) write zero at adres 0x0
the down side of the board
VAIO srx 87: eeprom 2408 write zero at 0x0
the ic is behind the modem in the top side of the board
VAIO PCG-FX150, eeprom 24c04 near the reference IC1103
VAIO PCG-GRX560, eeprom 24c04 near the reference IC1001
You can get/buy eeprom programmer in electronic shops or labs, you need
another PC to use it.
You can desolder the eeprom with hot air or you can try to "clip" the
eeprom. With the eeprom programmer, backup your eeprom and run
"cmospwd /d /l eeprom_backup". If you don't see the password, you can try
to fill the eeprom with zero or FF, don't forget the reset the cmos.
|Toshiba |
Differents passwords give the same 32-bit CRC, so CmosPwd can only give one
of them.
To reset the password of an old Toshiba, you can use KeyDisk. (cf my web page)
If this doesn't work, you can try to build the Toshiba Parallell loopback.
To make a simple device that you connect to your parallell port, a lot of
Toshiba computers remove the password when you boot it up.
The device, named "loopback" by some, could be made out of any
parallell wire with 25pins connectors (db25). You should connect
these pins: 1-5-10, 2-11, 3-17, 4-12, 6-16, 7-13, 8-14, 9-15, 18-25.
A db25 looks like:
1 13
_____/
14 25
Divers
- Medion
Try the password "am8888egh". - Award 4.50PG
There is an universal password AWARD_SW.
(d8on, 589589 ... works too) - Award 4.5x using DFI motherboards
The universal password is "Y. C. Lu" (spaces and capitals as shown).
Information from David Walker. - Award
Differents passwords give the same 32-bit CRC, so CmosPwd can only give one
of them. Use the numeric keypad. - COMPAQ LTE 5300 notebook
Tolga Sinan Guney: there is a reset jumper on the motherboard - DIGITAL PC300, Phoenix 4.0 Rel 6.0,0
Rene Pocisk: cmospwd /k works - Fujitsu ICL
aksion: passwords are stored in EEPROM - Fujitsu Point 1600
William Simcox: "I was able to clear the password and reset BIOS to
default values using CMOSPWD /K" - Phoenix
There is a backdoor in old version of Phoenix BIOS, the universal
password is "phoenix". - Siemens Nixdorf
PCD-4ND, Michael: You can clear the password of this phoenix 1.03 with "cmospwd /k"
Scenic Mobil 700, Josef Benda: "cmospwd /k" works! Phoenix Note BIOS v4.0
Scenic Mobile 510AGP, Bernd: "cmospwd /k" works! Phoenix 4.0 R6 Version 3F31 dated 9.2.2000 - Acer Travelmate 530
"cmospwd /k" removes the password. - Acer travelmate 2450
"cmospwd /k" removes the password. - Sony Vaio PCG505HS
Brad Frisbie: "cmospwd /k" works, Phoenix 6 R4 - Sony Vaio PCG-FR105
Andrea Michele Zoia: 'cmospwd_win /k' removes the password. - IBM NetVista 8303-41G
Roel: CmosPwd /k works, Phoenix Bios 4.0 Release 6.0. - Panasonic CF-25
Stefan Stevens: CmosPwd /k works - Tulip Vision Line bn 100
CmosPwd /k works, PhoenixBios 4.0 Release 6.0 11/03/01 - LG GS50-5FY notebook
Angelika Jurkiewicz: CmosPwd /k can remove supervisor password. - TI Extensa 600CD
Dathan Alley: CmosPwd /k works
What to do if you can't use cmospwd to clear your cmos ?
Under Dos/Win9x, you can use debug to reset cmos CRC stored at 0x2E-0x2F
debug
-o 70 2E
-o 71 0
-q
What to do if cmospwd don't work on your PC ?
Try to clear password with cmospwd /k.
If cmospwd /k doesn't work, password is stored in an EEPROM. Try to find a
reset jumper on your motherboard or contact your PC vendor.
If it works, I can try to discover how passwords are encrypted.
I need to know what Bios you used and
some cmos memory backup with their passwords. (cmospwd /w backupfile)
For passwords, choose
- some 1 and 2-letter passwords
- BBBBBBB
- BBBBBBC
- BBBBBCB
- BBBBCBB
- BBBCBBB
- BBCBBBB
- BCBBBBB
- CBBBBBB
Thanks to
- Philippe Garcia-Suarez (AMI Zenith, IBM Thinkpad)
- Mark Miller (AMI WinBIOS)
- Ian Sharpe (Award 4.51PG)
- Darren Evans (Phoenix 4 release 6)
- Teun van de Berg (bug report for "cmospwd /w")
- Giovanni (IO access under NT)
- Robert Rafai (Dell Latitude)
- Guillaume Letessier (Toshiba)
- hackvenger (Phoenix 4.0 realase 6.0)
- "P. MADRE" (Award 4.51PG)
- Ser...
bp-4_23
help string display with "/h" or run patcher without any options.
Notes:
-
In the directory with parched file must be:
cbrom.exe (rom.by/Award/patcher/cbrom.rar)
lha.exe (rom.by/Award/patcher/lha.rar)
reall.cod (rom.by/Award/patcher/real_microcodes.rar) -
Patch file, which is referenced in the command line
(when starting BP), i.e. nor what other "new" will not be created. -
If patcher some points did not find, this be not bad -
- after all basically searches mistakes, but once they not found,
signifies their simply no.
De-CMOS3
CMOS DE-ANIMATOR VERSION CHANGELOG
=================================================
v3.0.1
Released on 24th June 2014
New features:
- Added wizard for bootable media creation
called "CMOS De-Animator bootable", which
does not format the drive and also doesn't
require administrator privileges to work
Changes:
- Test CMOS read now displays hour and minute
- Executable size decrease to 628 kB
Bootable version features:
- Clear CMOS, hexadecimal/ASCII CMOS dump
- 24C06 EEPROM dump (Dell)
- Clear User/Supervisor passwords (Acer)
v3.0.0 ("revision 0")
Released on 27th October 2013
New features:
- dump 24C06 EEPROM to ASCII scancodes (Dell)
- command-line support, use /? to get help)
- silent mode
- new GUI
Changes:
- Compatible with Win95/NT 3.51 all the way
up to Windows 8.1 (tested 2014)
v2.1
Released on 11th August 2011
Changes:
- Minor bugfixes
- Usage warning added
v2.0 ("v2")
Released on 15th September 2010
New features:
- Backup and restore CMOS from a file
- Single-executable GUI
- Test CMOS reading at startup
Changes:
- Compatibility: Win98 up to Win7
- Less false-positive alertss from antivirus
software
v1.0 (x86 and x64)
Initial release.
Released on 14th August 2010
- Clear CMOS under Windows!
- Compatibility: Windows all (x86)
Win XP, Vista, 7 (x64)
CrystalDMI
/*****************************************************************************
-
* -
CrystalDMI * -
Copyright (C) 2004-2010 hiyohiyo * -
* -
The modified BSD license * -
mail: hiyohiyo@crystalmark.info * -
web : http://crystalmark.info/?lang=en *
*****************************************************************************/
Operating Environment
OS : Windows 7/2008/Vista/2003/XP/2000/NT4/Me/98 [x86]
Windows 7/2008/Vista/2003/XP [x64]
Font : Courier New (9pt)
Required : SMBIOS/DMI 2.2 or later
License
CrystalDMI is distributed under The modified BSD license.
Reference
- DMTF "System Management BIOS Reference Specification"
Version 2.6 Final
http://www.dmtf.org/standards/smbios
Support Feature
00 BIOS Information
01 System Information
02 Base Board Information
03 System Enclosure or Chassis
04 Processor Information
05 Memory Controller Information
06 Memory Module Information
07 Cache Information
08 Port Connector Information
09 System Slots
11 OEM Strings
13 BIOS Language Information
16 Physical Memory Array
17 Memory Device
19 Memory Array Mapped Address
20 Memory Device Mapped Address
32 System Boot Information
126 Inactive
127 End-of-Table
Unsupport Feature
10 On Board Devices Information
12 System Configuration Options
14 Group Associations
15 System Event Log
18 32-bit Memory Error Information
21 Built-in Pointing Device
22 Portable Battery
23 System Reset
24 Hardware Security
25 System Power Controls
26 Voltage Probe
27 Cooling Device
28 Temperature Probe
29 Electrical Current Probe
30 Out-of-Band Remote Access
31 Boot Integrity Services (BIS) Entry Point
33 64-bit Memory Error Information
34 Management Device
35 Management Device Component
36 Management Device Threshold Data
37 Memory Channel
38 IPMI Device Information
39 System Power Supply