Re: windows 2003 server



Yea if you used pwdump you need admin privledges to dump the hashes. If
you manage to get a reverse shell you can ftp the sam from the repair
folder and the system part of the registry. Then import them into L0pht
or LCP. If I am not mistaken, the sam file is sysked at level 1 by
default for 2k3? Could someone verify that for me?

SYSKEY has been enabled by default since Windows 2000.

By the way, "SYSKEY" and "REPAIR" things are of no use on a Domain
Controller (since the original question was about domain password
policy). All user information (including password) is stored in Active
Directory - namely the "NTDS.DIT" file, which is of undocumented format.

By accessing the SAM file on a Domain Controller, you would gain access
to local accounts that existed on the server before DC promotion. If I
remember well, some emergency utilities (like Directory Restore Mode)
make use of this password, but that's all.

Regards,
- Nicolas RUFF


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------



Relevant Pages

  • Re: RAM size
    ... The SAM file explination is here...this holds all password info. ... What I ideally decided to do is plug the hard disk into my other Windows ... Being able to login I used System Restore to reverse the system to a ealier ... I want to just delete the SAM file, bt not ure if tat is a good idea. ...
    (microsoft.public.windowsxp.general)
  • RE: Unwanted programs on Win2K
    ... Just for your info, there is a thing such as .SAM files, MS office uses ... the easiest is to crack the .SAM file. ... the backup copy of the ... Do you Yahoo!? ...
    (Security-Basics)
  • Re: cracking Y2k DC Admin password
    ... IronGeek wrote a cool article about cracking local SAM with SYSKEY: ... >> - rescue in windows folder and backup sam file from it, it has admin ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: Auditing Active Directory Passwords
    ... cracking SAM on windows is all you need for your particular task. ... Subject: Auditing Active Directory Passwords ... 2003 Active Directory did not use a SAM file for all of the domain accounts. ...
    (Security-Basics)
  • Re: Deleting the SAM
    ... Delete the entire SAM, all at once, ... regestry editing, etc. TIA ... You could install ... >other computer and find the SAM file and delete it, ...
    (microsoft.public.windowsxp.security_admin)