New way to extract local user passwords!

Discuss it here

Re: New way to extract local user passwords!

Postby Xcellerator » Tue Dec 22, 2009 4:24 pm

So, can I copy SAM and SYSTEM from C:\Windows\System32\config through SafeMode?
Hypnotoad compels you to OBEY!!!

http://www.14215469003554774018810.net16.net/
User avatar
Xcellerator
Power Member
 
Posts: 364
Joined: Mon Jul 06, 2009 6:09 pm

Advertisement

Re: New way to extract local user passwords!

Postby muto » Tue Dec 22, 2009 9:34 pm

I doubt it. You can rip the contents with Administrator rights (using Cain or something), but since they're key parts of the registry, they're still in use in safe mode. Booting Linux does the trick though.
muto
Power Member
 
Posts: 417
Joined: Sat Mar 29, 2008 11:46 am

Re: New way to extract local user passwords!

Postby ICT Tech » Wed Dec 23, 2009 12:04 am

In Safe Mode you may be able to login locally!

This means if you login locally via Safe Mode you would be able to copy this!! :P
ICT Tech
Power Member
 
Posts: 1340
Joined: Thu Jul 26, 2007 5:33 pm

Re: New way to extract local user passwords!

Postby Xcellerator » Wed Dec 23, 2009 10:52 am

But I don't know the passwords to log in locally... That's what I'm trying to find out.

Also, can CAIN be run from USB? Because then I could export it to a *.lc file then crack it at home...
Hypnotoad compels you to OBEY!!!

http://www.14215469003554774018810.net16.net/
User avatar
Xcellerator
Power Member
 
Posts: 364
Joined: Mon Jul 06, 2009 6:09 pm

Re: New way to extract local user passwords!

Postby ICT Tech » Wed Dec 23, 2009 2:15 pm

Hmm, good point, I forgot about that!

I'm not sure if Cain can be run from a USB, that's more of a question for JD or muto, they're good with this sort of stuff!! :P
ICT Tech
Power Member
 
Posts: 1340
Joined: Thu Jul 26, 2007 5:33 pm

Re: New way to extract local user passwords!

Postby muto » Wed Dec 23, 2009 2:45 pm

Cain can be run from a USB stick, but there are a couple of things you need to consider.

The packet sniffing functions will not work without the WinPCap driver installed
Abel.dll is required for the hash dumping, and many antiviruses detect (and delete) it
You need admin rights to dump hashes
muto
Power Member
 
Posts: 417
Joined: Sat Mar 29, 2008 11:46 am

Re: New way to extract local user passwords!

Postby Xcellerator » Thu Dec 24, 2009 12:07 pm

Well, on these two glitchy computers at my school, you have local admin rights on it! I can use cmd with full admin privileges, but I don't want to change the password, I want to crack it so I can run any program as admin on any computer! Also, I'm not worried about the sniffer function, I'm only trying to crack a password.
Here's my plan:
1. Log-on
2. Log-off
3. Remove Network Cable
4. Log-on (No Securus, or anti-virus, cos that's all run from the server!)
5. Use USB to dump Local Password Hashes!
6. Remove USB, then insert network cable!
The Server is none the wiser that I've done anything!
Hypnotoad compels you to OBEY!!!

http://www.14215469003554774018810.net16.net/
User avatar
Xcellerator
Power Member
 
Posts: 364
Joined: Mon Jul 06, 2009 6:09 pm

Re: New way to extract local user passwords!

Postby muto » Thu Dec 24, 2009 12:29 pm

It'd be worth dumping the Domain Cached Credentials as well, you might get lucky and get the admin hashes in there, if not, you should at least get a couple of other student accounts to work from.
muto
Power Member
 
Posts: 417
Joined: Sat Mar 29, 2008 11:46 am

Re: New way to extract local user passwords!

Postby ICT Tech » Fri Dec 25, 2009 2:37 am

muto wrote:It'd be worth dumping the Domain Cached Credentials as well, you might get lucky and get the admin hashes in there, if not, you should at least get a couple of other student accounts to work from.


Very True!! :lol:

And Well Done!! :P
ICT Tech
Power Member
 
Posts: 1340
Joined: Thu Jul 26, 2007 5:33 pm

Previous

Return to RM Community Connect

Who is online

Users browsing this forum: No registered users and 1 guest


  • Advertisement
cron