Re: Where are Windows "Enforce password history" passwords stored?

From: Jeffrey Denton (dentonj_at_gmail.com)
Date: 08/29/05

  • Next message: Stefano Zanero: "Re: Exploit for old 3com bug ("3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability")"
    Date: Mon, 29 Aug 2005 12:34:11 -0700
    To: Charles Gillman <charles.gillman@gmail.com>, pen-test@securityfocus.com
    
    

    On 8/29/05, Jeffrey Denton <dentonj@gmail.com> wrote:
    > On 8/28/05, Charles Gillman <charles.gillman@gmail.com> wrote:
    > > Can anyone tell me where the "remembered" passwords are stored when
    > > the "Enforce password history" is set in Group Policy?
    >
    > They are in the SAM.
    >
    > http://www.derkeiler.com/Mailing-Lists/NT-Bugtraq/2003-07/0033.html
    >

    Also, http://www.cqure.net/tools.jsp?id=22:

    "Patches that add the functionality of dumping password history hashes
    to pwdump version 2 and 3."


  • Next message: Stefano Zanero: "Re: Exploit for old 3com bug ("3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability")"