
- #How to change mac password in single user how to
- #How to change mac password in single user password
- #How to change mac password in single user series
Boot using Option key, see if there is no Lock Icon, shutdown and reboot from Single User Mode.
#How to change mac password in single user password
It is always good to boot a Mac first holding down the Option key to make sure the system does not have a Firmware Password before trying to boot into Single User Mode. I wanted to pass them on as they are really helpful!Ī few things I thought I would pass on about your post: These are some comments sent to me by Derrick Donnelly. Single user-mode logs in as root, and this can be very dangerous. I also recommend trying this on a test Mac before running these steps on actual evidence. I was limited to one test system, one hard drive and FileVault2 encryption. While these steps worked on my test Mac, examiners should always test and research the model they are encountering. dd if=/dev/rdisk0 bs=4k conv=noerror,sync of=/tmp/usb/rdisk0.dd (HFS USB).dd if=/dev/disk0 bs=4k conv=sync,noerror | split -b 2000m - /tmp/usb/disk0.split.


While the system is booting, select COMMAND-S to enter single-user mode. The first step is to boot into single-user mode. I have had some people in the community provide some great tips and suggestions since this was posted! The high level steps are:ģ) Mount the USB drive that will hold the imageĤ) Run the dd command to create the image

For each step I will cover both scenarios. I tested two scenarios, one without encryption and one with encryption (FileVault 2).
Were created by default during the initial setup: an EFI partition, a MacOSX partition, and a recovery partition. The system I used for testing was a Mac Mini, OS X Version 10.8.5 with one hard drive. Another benefit is that if there is FileVault encryption, the encrypted drive is decrypted after a username and password are supplied. This may be a good option where it is acceptable to get a live image, but the examiner wishes to minimize changes to the hard drive. While not as forensically sound as using a write blocker or booting into a Linux distro, less changes are made than fully booting the operating system to take a live image. In order to mount the USB drive, the internal drive needs to be changed to read/write to create a mount point. Once in single-user mode, a USB drive can be attached and dd can be used to create an image. In single-user mode, the internal hard drive is mounted read only and a limited set of commands are available. Single-user mode is a limited shell that a Mac can boot into before fully loading the operating system.
#How to change mac password in single user how to
I plan on following up this post with posts on creating a live image and how to mount and work with FileVault encryption after an image is complete. This post will cover another option, creating an image by booting a Mac into single-user mode. My first post was on how to image a Mac with a bootable Linux distro.
#How to change mac password in single user series
This is the second post in my series on different ways to image a Mac.
