PDA

View Full Version : Deep Freeze problem


Tropicalchris
06-15-04, 02:26 PM
My school computers have these two programs called Deep Freeze and Novell. Most of you should know Novell. Deep Freeze is a program that makes it impossible for you to download things and keepthemon the computer. I am wanting to install games such as Age of Empires and stuff like that on the system, and need help bypassing this Deep Freeze program. And to all of you sarcastic people, NO I DO NOT HAVE THE PASSWORD. Can someone help tell me how to fix this problem.

roy
06-15-04, 02:26 PM
Boot into safemode and uninstall.<BR>or<BR>Find the directory where it's installed and try deleting as many files as possible, maybe that'll screw it up and prevent it from starting.<BR>or<BR>Search the net for programs that can crack the Deep Freeze bullshizz. Try www.astalavista.com.<BR><BR>Good luck <img src="i/expressions/face-icon-small-wink.gif" border="0">

Tropicalchris
06-15-04, 02:26 PM
I already tried to delete all the files in the folder, and only the one person in the school can do that, the computer lady. I will try to boot in in safe mode. Thanks for ur help.

chris watson
02-07-05, 12:57 PM
is it possible ot take the safe mode off the computer? cuz i went into the boot menu and i didnt see it. theres a linux penguin guy tho, but i dont know enuf about linux to start messing around with it. where can you find the deep freeze program to start deleting it?

Krap
05-18-05, 05:21 AM
Need to unfreeze Deep Freeze? Go to
http://www.unfreezer.cjb.net/

This guy found a way to do it! It works for XP/NT/9X and doesn't need to boot from floppy or CD.

Evil Genius
10-23-05, 01:31 AM
A black-hat computer programmer in Argentina with a grudge against Faronics, Emiliano Scavuzzo, has written a program to thaw Deep Freeze without knowing the password. It works on almost ALL versions of Deep Freeze, including the latest version, v5.60.120.1347, which recently came out (Oct-20-2005) to supposedly be immune to his program—it's not! You can use Deep Unfreezer to test for the vulnerability on your own machines:

Deep Freeze Unfreezer
http://usuarios.arnet.com.ar/fliamarconato/pages/edeepunfreezer.html

Method 1:

To perform the test you must first acquire DebugPrivileges (removed by Deep Freeze) by escalating to NT_AUTHORITY (the System account) using Task Scheduler from the command line (Start/run, cmd):

1) at 11:23pm /interactive taskmgr.exe (add one or two minutes from the current time)
2) End Task explorer.exe
3) File / New Task (Run...), Enter explorer.exe to launch the explorer shell under the System account which has Debug Privileges
4) Run Deep Unfreezer from the System account.

Method 2:

OR, use ntrights.exe from the Windows Server 2003 Resource Kit, a free download, http://tinyurl.com/6p6cy, to grant yourself the SeDebugPrivilege.
Syntax: ntrights -u Users +r SeDebugPrivilege
If you use ntrights, you must logoff and logon again for the privilege to take effect.

Then run Deep Unfreezer, View Status, click on the Boot Thawed button, Save Status, and restart the machine. If the machine reboots in thawed mode, your version of Deep Freeze is vulnerable, and you should take measures to provide additional security on your machines.

Deep Freeze Evaluation versions are also vulnerable to this attack. Deep Freeze Evaluation versions can be taken off machines by an attacker by forwarding the system date past 60-days which will expire Deep Freeze, causing the computer to restart in thawed mode, allowing Deep Freeze to be uninstalled. If you're using an evaluation version of Deep Freeze, here's how to perform this test:

Method 1:

1) Switch to the System account, as described above
2) Double-click the time in the system tray
3) Forward the date past 60-days
4) Restart in thawed mode
5) Use DeepFreezeSTDEval.exe to uninstall Deep Freeze. Deep Freeze is not uninstalled through Add/Remove Programs. It is uninstalled with the installation file, and ONLY with the installation file. Yes, the same file is used to install and uninstall. If you don't have it, download it here.

It's a free download:

Deep Freeze Evaluation -Trial Version - v5.60.120.1347
http://www.faronics.com/exe/DeepFreezeSTDEval.exe

Method 2:

Or, use ntrights.exe from the Windows Server 2003 Resource Kit to grant yourself the SeSystemtimePrivilege.
Syntax: ntrights -u Users +r SeSystemtimePrivilege
You must logoff and logon again for the new privilege to take effect.

Special Note:

Faronics came out with v5.60.120.1347 on 10-20-2005 as a response to Deep Unfreezer. It proved to be an impotent move. Emiliano's response to the new version? "rename frzstate2k.exe to anything else. Then attach to DF5Serve.exe instead". Does that work? Yes, it does. Thus, the newest version of Deep Freeze, intended to thwart Deep Unfreezer, continues to be vulnerable.

Deep Freeze protects over four million computers world-wide and over one million Macs (yes, there's a Deep Freeze for Mac). And most of them are vulnerable to this attack (but not the Macs). At this time Faronics does not have a fix, nor an immune version. If you are a network administrator in charge of maintaining a network of machines protected by Deep Freeze, please be advised of this situation and be prepared.

Faronics does not seem to be taking this seriously. They only made a token effort to thwart Deep Unfreezer in their latest version. Until they get serious about things, Deep Freeze is going to be melting away in the eyes of those who have grown to love and trust the program.

One of the main issues is the fact that so many computers these days allow Administrator status. Even a lot of internet cafes use Windows XP Home edition, with the user logged in as Administrator. The developers at Faronics are committed, however, to protecting the machine even from Administrators! The problem with that is, as you know, whatever is taken away from an Administrator, the Administrator can give back to herself. So if, for example, Deep Freeze removes DebugPrivileges, users can simply grant it back to themselves.

Another issue is their commitment to non-restrictive use. Their commitment with Deep Freeze is to protect the machine non-restrictively. That has worked... until now. I think they may be forced at this point to admit Administrator accounts can't be guaranteed protection any longer. Unless they can secure these issues, I don't see any other way.

BRK
12-13-05, 06:06 PM
i was able to remove deep Frezze by way of MS-dos but it still seems to work any thing saved gets removed , is there any other files that should be removed other than the ones in the deep frezze files ?

Evil Genius
12-16-05, 01:39 PM
Well, Faronics has really flubbed it this time. They had their chance and blew it. For months and months Deep Freeze Enterprise v5.70.220.1372 was in development to put a permanent end to Unfreezer. Instead, it only took a week or so for Emiliano to update his Unfreezer program to kill even this latest version without a password. Evidently there is nothing they can do to stop this method. This is going to hurt their software sales in a big way. As before, the only requirement is to first grant yourself the Debug Programs privilege. A lot of people are stumbling on account of this requirement. They don't understand why Unfreezer doesn't work. It's because they didn't first grant themselves this privilege. Instructions abound, but they don't read them.

SomeGuy
09-23-06, 12:36 AM
Well this is an old thread but I think things have changed. Emilano has all but disappeared and his site has not been updated for ages. I've installed deep freeze 6.00.220.1523 on two of my home machines and I have been able to thaw them using BartPE and editing the registry as instructed by Emilano (link is in above posts). The machine boots thawed and all is good that is until I try to reinstall DF6 with a password I know. It installs but the systray icon doesn't appear. The only way to rethaw is through BartPE and regedit. What I'm trying to do is thaw it. Uninstall it and reinstall my own DF workstation exe with my own password. I'm trying to be sneaky and I've been mucking around with this on my home computers.

Questions are: Is there a nice clean unfreezer for version 6? If not since I know how to thaw it the hard way how can I completely return my machine to a pre deepfreeze virgin state?

Grimreaper
09-23-06, 03:49 AM
Another kid and I were almost successfully expelled from high school 3 months from my graduation for using unfreezer to disable deepfreeze. The computer tech had no clue what we did and got pissed off because we made him miss his Braves game so he told the principle we hacked the school network. Is that BS or what? Needless to say our parents appealed it, got a lawyer, fought it, and won.:devil: Although I couldnt get on a school computer ever again there. They substitued my computer class with 4 1/2 hours of PE for the rest of the year.:angry:


1. No, I dont believe there is one for version 6 so I think your down to the hard way. Unless one came out in th recent months that I haven't seen.
2. I would think the way to go to pre-deepfreeze state would be to uninstall. If you run the original installer it should give you the option to uninstall deepfreeze.

P.S. Sorry for jacking thread with my story, got a little carried away.

SomeGuy
09-23-06, 12:39 PM
Believe it or not I'm a teacher and I understand what you're saying. Our tech is useless and incompetent and will look for any outside excuse for the bad things that happen to his network. I believe any good tech should know and explore his own security holes in an effort to either patch them up (disable boot menus so kids can't boot from a cd) or to at least be aware of them so he knows what to look for.

I've been playing some more and the uninstaller for the DF workstation doesn't remove DF completely after its thawed. When I try to reinstall the DF workstation (a version with a known password) it gives an error. After playing a little a little more I've found that if I thaw the machine the long way (BartPE) then restart the machine and run the DF seed after a couple of restarts and reinstalling the seed I can see the seeded machine from the DF consonle on another machine. From the df console I can then install DF to the client and all appears normal except for one thing the DF client will not show on his console. Hmm more exploration to come.

BTW notice I'm playing with the school software at home. Don't do this in your school lab and expect to not be noticed. Try to recreate the situation on a home computer and go from there. Then maybe (just maybe) do it to one of the school machines but be sure to button it back up. Its not worth risking expulsion.

Grimreaper
09-23-06, 01:12 PM
I would suggest getting your own copy if possible. When I was trying to learn more about the program I pulled a copy off of Limewire for "educational purposes" lol. You could also get the evaluation version from Faronics but I do believe that is a stripped down and time-limited version.

Good news though. The "Network Tech" was fired after this incident and is now an academic counselor.

SomeGuy
09-24-06, 01:13 AM
He likely wasn't fired he just got moved. Same pay as before its just how its done. They just try to move them somewhere less noticeable. And BTW of course I'm testing this on my home machines:p

Grimreaper
09-24-06, 03:04 AM
Well, if ya find anything interesting I would sure love to hear it. You never know...im in college now and they run deepfreeze also. :dev: Nah, definently not going down that road again, lol, but im always up for learning something new.

SomeGuy
10-04-06, 06:32 AM
Well things I've learned.

You can disable DF6 using Emiliano's guide (see above posts). If you want to reinstall your own version with a known password the best way to do this would be to use your own DF console and create your own DF seed maybe by running the console from a laptop plugged into the same network.

Other thing. By running a windows pe (miniPE built by DigiWiz - from bittorrent) you can resize the HD just slightly (by about 50megs). What this has done was have the machine believe that it has been freshly reimaged and has a thawed boot initially (only once though) from that point you have one chance to make the changes you want (and not be noticed!). Of course I think that DF has to be setup to allow 1thaw boot after imaging a machine.

redhat
10-12-06, 09:26 PM
I am following the tutorial on how to unfreeze DeepFreeze from http://www.ethicalhacker.net/component/option,com_smf/Itemid,49/topic,658.0/. I am very close to disabling it but I'm currently stuck at these steps:
Right click over the code and a context menu will appear, select 'Go to' and then 'Expression' (or use the shortcut Ctrl+G).
In the text box enter the following value according to the Deep Freeze version you have installed and press OK.

VERSION/VALUE
4.20.020.0598 / 40368D
4.20.120.0598 / 40368D
4.20.121.0613 / 4034F5
5.20.220.1125 / 4037E9
5.30.120.1181 / 4037E9
The program will jump to the line of code.

My question is: What is the correct value for version 6.00.220.1523?

Thanks.

doomloard
12-12-06, 04:06 PM
ok now every one has looked at this sulution difrent and yess i said sulution becase i found with shcools and i am shure the thecher that poste a while will bak me up here but shcools are on a very tight budget and that means they dont have the means for a very top of the line sicurity systems lol my shcool i can acsses the network settings frome a work station but now has any one even thought of interfaceing with df or deep freez i hurd hypethiticly it sposed to work but the problem is well at least at my shcool is that our computers have a small very anoying sicurity system to inter face with the files i have at home i need to get past the damn fire wall but deep freez has that abilaty blocked a littel thing our tecc added :fighty: so when i change the system so i have a conection port lol the configuration is changed back after i hit apply
lol so i gave a hint and also ui am asking for help how can i get aroun this rest on the ports

doomloard
12-12-06, 04:42 PM
ok mi am going to downloa deep freez and do some test simulations on it see if there is any way i will edit this post as soon as i find anything

aaroniko10
09-10-08, 06:04 AM
hello
i have a big problem with the seed of deep freez.
i have a class with 22 computers and one consul of deep freez that i manage from this computer the another conmuters on my class in my work
when i finish to install one competer and want to install the seed of deep freez there are two problems
the first i got erorr 33554432
the second problem if i success to install the seed is not appear on the consul
if somebody know about this problem pleaz help me

aaroniko10
09-11-08, 05:10 AM
dir sir

i have a big problem with deep freez and i hope tht you can help me

i have room with 50 computers and one computer that it is the consul of deep freez

when i trying to install the seed after my all intalations i got erorr messeg with number 33554432

i am olso intaliing service pack 3

what is the problem and how i should to fix it????



I want to emphasize that my computers are the same
technical specifications pentium 4 -proccesor 1.5- 256mb of ram and hard drive 40 gb

thank you very much for the helping

Comixion
09-11-08, 01:42 PM
aww Novell. I curse it daily.