RE: SAM user dump

From: Wyatt Neal (wyatt.neal_at_capcgroup.com)
Date: 09/18/05

  • Next message: Stephen J. Smoogen: "Re: Whitespace in passwords"
    Date: Sun, 18 Sep 2005 15:05:02 -0400
    To: <pen-test@securityfocus.com>
    
    

    I'm not sure if this is the answer you are looking for, but in a similar
    situation, I was able to dump the cached passwords using cachedump from
    http://www.cr0.net:8040/misc/cachedump.html and used a patched version
    of john to get the passwords. I know this is a lot brute-forcish, but
    using this, you might be able to figure out a way to change the
    cachedump into the standard SAM hashes so you could use rainbow crack or
    ophcrack against it.

    Best of luck,

    Wyatt Neal

    CAPC GROUP, LLC

    Professional IT Services

     

    3732 Lovell Ave. Suite 5

    Cincinnati, OH 45211

     

    phone: 513.285.4000x228

    mobile: 513.256.5587

    fax: 513.285.4000

    email: wyatt.neal@capcgroup.com

     

    CONFIDENTIALITY NOTICE: This e-mail message is intended only for the
    person or entity to which it is addressed and may contain confidential
    and/or privileged material. Any unauthorized review, use, disclosure or
    distribution is prohibited. If you are not the intended recipient,
    please contact the sender immediately by reply e-mail or call
    513.285.4000 and delete all copies of the original message. This email
    does not form a legally binding contract between sender and receiver.

    -----Original Message-----
    From: DokFLeed [mailto:dokfleed@dokfleed.net]
    Sent: Friday, September 16, 2005 10:33 AM
    To: pen-test@securityfocus.com
    Subject: SAM user dump

    Hey,
    I am looking for a way to dump the SAM hashes by USER account.
    assume the box doesn't have CD or Floppy to boot from.
    No repair files , or Registry SAM hashes available.

    any tools to dump the hashes for user from a cmd console
    or should we start coding one !

    DokFLeed

    ------------------------------------------------------------------------
    ------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on
    your
    website. Up to 75% of cyber attacks are launched on shopping carts,
    forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers
    are
    futile against web application hacking. Check your website for
    vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before
    hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    ------------------------------------------------------------------------
    -------

    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on your
    website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------


  • Next message: Stephen J. Smoogen: "Re: Whitespace in passwords"

    Relevant Pages

    • RE: SAM user dump
      ... I am looking for a way to dump the SAM hashes by USER account. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)
    • RE: SAM user dump
      ... > I am looking for a way to dump the SAM hashes by USER account. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are ...
      (Pen-Test)
    • Re: Exposing Dan Christensens aka DCPROOF lies about Cubafaq and me - why Dan Christensen aka DC
      ... Link to the real "Cubafaq" website: http://cubafaq.impela.net ... Link to Dan Christensen posting as "Dan Christensen" Jun 1. ... Your continued attacks will bring you more ... He is the one doing the "attacking" with his lies and slander. ...
      (soc.culture.cuba)
    • Re: Exposing Dan Christensens aka DCPROOF lies about Cubafaq and me - why Dan Christensen aka DC
      ... Link to the real "Cubafaq" website: http://cubafaq.impela.net ... Link to Dan Christensen posting as "Dan Christensen" Jun 1. ... Your continued attacks will bring you more ... He is the one doing the "attacking" with his lies and slander. ...
      (soc.culture.cuba)
    • RE: Pre-Scanning for Marketing
      ... installer there were some Security issue, ... vulnerabilities are easily and efficiently identified. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)