Re: AD password Auditing

From: David Cravshaw (david.cravshaw_at_gmail.com)
Date: 08/06/05

  • Next message: Tonie: "RE: AD password Auditing"
    Date: Fri, 5 Aug 2005 19:05:53 -0500
    To: Lohan Spies <lohan.spies@ifs-sa.co.za>
    
    

    Just run <insert choice of windows password dump utility here> on the
    domain controller. Pwdump, l0pht crack, etc will pull the hashes just
    fine. I've only seen one instance of those actually crashing the dc
    and not being able to pull hashes and that was on 2003.

    On 8/5/05, Lohan Spies <lohan.spies@ifs-sa.co.za> wrote:
    > Hi there,
    >
    > I want to know how can I copy the AD (Active Directory) database so that I
    > can run a password cracking tool against the accounts?
    >
    > Could someone please point me in the right direction regarding the tools to
    > use and how to copy the db?
    >
    > Thanks
    >
    > ------------------------------------------------------------------------------
    > FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
    >
    > Learn the hacker's secrets that compromise wireless LANs. Secure your
    > WLAN by understanding these threats, available hacking tools and proven
    > countermeasures. Defend your WLAN against man-in-the-Middle attacks and
    > session hijacking, denial-of-service, rogue access points, identity
    > thefts and MAC spoofing. Request your complimentary white paper at:
    >
    > http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
    > -------------------------------------------------------------------------------
    >
    >

    ------------------------------------------------------------------------------
    FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't

    Learn the hacker's secrets that compromise wireless LANs. Secure your
    WLAN by understanding these threats, available hacking tools and proven
    countermeasures. Defend your WLAN against man-in-the-Middle attacks and
    session hijacking, denial-of-service, rogue access points, identity
    thefts and MAC spoofing. Request your complimentary white paper at:

    http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
    -------------------------------------------------------------------------------


  • Next message: Tonie: "RE: AD password Auditing"