Re[2]: Hidden Sam (passwords) File on XP/2000 FileSystem

From: Phaedrus (
Date: 03/12/02

Date: Mon, 11 Mar 2002 15:57:22 -0800
From: Phaedrus <>
To: "R Hampson" <>

The "RP" directories in question are the restore points created by the
System Restore tool (either manually or automatically). Since System
Restore is designed to let you roll the machine back to a previous
state, I'm sure the restore-point directories include all sorts of
terribly interesting information; I'm not at all surprised that SAM
information is in there as well.

So this information isn't stored in this way unless the machine in
question is running System Restore (which, unless my memory is
failing, means that Win2K wouldn't store this informaiton, since it
doesn't include System Restore).

If you don't want attackers to access this information in this way,
you should either disable System Restore (and use some other backup
strategy), or set the permissions so that attackers can't have access
to it (which, arguably, the default permissions accomplish reasonably
well--if an attacker can execute code as SYSTEM, it's probably
game-over in any event).

Best regards,

