This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to hardware-reset (or passwort reset) without monitor or console?

Hi everybody,

 

since my KeePass container somehow disposed my admin-password to the utm webinterface (UTM 120 appliance), I am no longer able to gain access to it.

I tried to hook up a serial connection, but everything putty (or kitty, tried both) shows is a blank, black CLI. Nothing else. COM interface as shown in windows settings with speed of 9600 (default setting).

When linking the appliance via VGA to my monitor, it shows a nice and clean nothing to it (e.g. the monitor changes from analog back to digital due the lack of a signal).

The appliance was updated to the newest version two weeks ago, if that information is helpful.

So, the big question is: How will I be able to regain access to the aapliance? Data-loss accepted if needed.

Any ideas? What am I doing wrong?



This thread was automatically locked due to age.
Parents Reply Children
  • Soooo, seems there was probably a problem with the user Password before.

    I had tried my two firstnames as example. Both using the correct key mapping to a qwerty layout (even when used on qwertz as you correctly assumed).

    So this time, I tried "test" as password for root. I immediately tried it out after reboot and I was able to login. NICE! Appliance beeped shortly afterwards as signal to be booted completly. "exit" -> relogin: "password incorrect" *WTF*

    There is ANOTHER hurdle: Sophos (nicely) checks the used passwords agains simplicity, length and (and this I did not expect) dirctonary. So obviosly, both names where contained in that dictionary. 
    Either the password was accepted without error or, which may be now as I saw the specific errors, I just oversaw that password because the shell still announce the password as being set. Even if it is not, as it seems.

    Next turn, I tried out some passwords an finally "ClosedDoor" did not throw any errors (nothing in dictionary, huh? Oo). 

    Login worked, password-reset worked, set-new-webadmin-password-form showed up.

    On webadmin I changed the passwords to strong ones, excluding not-same-mapped characters. Tried to login to console with the new password: Works (typing random 30 chars is a pain, when shell resets after some seconds xD )

     

    tl;dr: Reset worked with both instructions (obviously as they were the same). Just keep an eye on the password policy errors!

     

    Thanks you both for your nice help :)

  • Hi,

    good to hear.

    So then ... njoy your new admin console ... maybe this time u should backup keepass container ;-)

     

    Cheers,

    Chris

  • Gabriel

    You really made my day!

    A year ago I went insane with the same problem on two UTMs. Nobody could help me including Sophos Support.

    Solution was always: "You have a special problem - normally the reset-instruction works - do a Factory reset or re image the box".

    Reading the post I already smiled pitying because I assumed you wouldn't find a proper answer (which you didn't -> you solved it yourself).

    Thanks a lot! I'll document it in our knowledge DB and link your post :-)

    Maybe Bob should add it to the "rulez".

    Cheers

  • Chris, Janbo suggested that I add your trick to the Rulz, but I'm afraid I don't understand.  If the loginuser and root passwords are no longer known and one cannot get into WebAdmin, what is your solution?

    Cheers - Bob

  • Hi Bob, 

     

    maybe Janbo was suggesting my explanation to be aware of ALL the output when using passwd, not only the last line of it :D

    Especially the lines indicating, that the password is not allowed (but nevertheless apparently accepted).

     

    Greetz, Gabriel

  • Hi Bob,

    maybe we should write it like this:

    Password reset procedure: community.sophos.com/.../115346

    Good to know:

    1. Passwords are beeing checked on simplicity / dictionary on next time boot.

    2. Sophos uses qwertz - keyboard layout in Console, be aware of setting a temporary password containig Y Z or special chars.
    set an unsecure temporary password and change it to a secure one later on via WebAdmin. ( "ClosedDoor" worked for another user)

    3. Remeber setting a more complex password after regaining access to your system

    cheers,
    Chris

  • Ahh, now I see!

    Instead of adding something to Rulz, shouldn't that article mention this issue?  I've left a comment there with a link back to this thread.

    Cheers - Bob