Obtaining Internet Explorer Passwords: Theory and Practice
1. Introduction
2. Types of passwords stored in Internet Explorer
2.1. Internet Verification
2.2. AutoComplete data
2.3. AutoComplete passwords
2.4. FTP passwords
2.5. Sync passwords
2.6. Identity passwords
2.7. AutoForms data
2.8. Content Advisor Password
3. A brief overview of Internet Explorer password recovery programs
4. PIEPR - the first person you know
5. Three real examples
5.1. Recovering the current user's FTP passwords
5.2. Receiving website passwords from unloaded operating system
5.3. Receiving rare unsaved passwords
6. Conclusion
1. Introduction
No one can dispute the fact that Internet Explorer is the most popular web browser today. Statistically, about 70% of online users choose to use this program alone. Controversy over its good and bad can last forever; still, this browser is the leader of its industry, and this is a fact that does not need proof. Internet Explorer has many built-in technologies, designed to make the average user's life easier. One of them - IntelliSense - is designed to take care of common tasks, such as auto-completion of visited web pages, automatic filling of form fields, user passwords, etc.
Most modern websites require registration, that is, the user will have to enter a username and password. If you use more than a dozen such websites, you will need a password manager. All modern browsers have a password manager built into their arsenal, and Internet Explorer is no exception. Really, why should one remember another password if it is going to be forgotten for some time soon? It is very easy for the browser to do the normal job of remembering and storing your passwords. It’s simple and comfortable.
This would be a perfect solution; however, if your Windows operating system crashes or is restored and not in the way it should be restored, you can easily lose your entire list of passwords. That is to pay for luxury and ease of use. Well almost every website has a save button that says 'I forgot my password'. However, this button will not always remove your head from you.
Each software developer solves the problem of recovering a forgotten password in his own way. Some of them officially recommend copying a few important files to another folder, while others send all registered users a special application that allows them to manage migration of private data, while others pretend they do not see the problem. However, the need to create offers, and password recovery programs are currently very much needed.
In this article, let's try to identify the types of confidential data stored in Internet Explorer, look at data recovery programs, and learn real examples of recovering lost Internet passwords.
2. Types of passwords stored in Internet Explorer
- Internet Explorer can store the following types of passwords:
- Internet Verification Features
- AutoComplete data
- AutoComplete passwords
- FTP passwords
- Sync passwords for saved websites
- Identities Passwords
- AutoForms data
- Content Advice Password
Let's take a closer look at each item listed.
2.1. Website Verification Features for websites
Internet authentication means logging in with the user passwords required to access certain websites, which are processed by the wininet.dll library. For example, when you try to enter a secure website, you may see the following username and password Prompt (fig.1 http://www.passcape.com/images/ie01.png).
If the 'Remember my password' option is selected on that information, user details will be stored on your local computer. Older versions of Windows 9a store that data in a user's PWL file; Windows 2000 and newer keep it in secure storage.
2.2. AutoComplete data
AutoComplete data (passwords will be covered continuously) is also stored in Protected Storage and appears as a list of HTML field names and associated user data. For example, if an HTML page contains an email address inbox: if the user has entered his or her email address, Protected Storage will have the HTML field name, address number, and the last time the record was accessed.
HTML page title and website address are not saved. Is that good or bad? It is difficult to determine; you may be better off than worse. Here are the obvious benefits: it saves free space and speeds up browser performance. If you think the last note is not important, try to imagine how you would have to do several more tests in the thousands (this is not as uncommon as it may seem to us) a list of automated fillings.
Another obvious combination is that data like name (and frequency by subject) HTML form fields will be stored in the same location, and standard data will be used for the automatic filling of such pages. We will see this in the example of this. If a single HTML page contains an auto-fill field labeled 'email', and the user enters his or her email address in that field, IE will include storage, approximately, '[email protected]'. From now on, when a user opens another website, with a page with the same field name 'email', the user will be prompted to automatically fill in the value they entered on the first page ([email protected]). Therefore, the browser somehow finds the power of AI within it.
The biggest drawback of this data storage method stems from its recently described benefit. Imagine, a user has inserted auto-fill data into a web page. If someone knows the HTML form field name, that person can create their own simple HTML page with the same field name and open it from a local disk. To obtain information entered in this field, such a person will not be able to access the Internet and open the first WWW address.
Nice post please follow back 👍
You must be logged in to post a comment.