Re: Re: Copying secret windows file



Hi,
Sorry to destroy your sense of insecurity, but this is not the case.

There are a number of methods that may be used to dump SAM in memory. Any user with Debug privilages has effectively full access to memory and many system are set this way). On top of this, there are means to obtain access without authorisation.

Take Meterpreter for instance. This toolset comes with "Sam Juicer". Sam Juicer "slides" over a memory channel as a direct memory injection that leaves no disk or registry evidence (hence my push on memory forensics).

Any memory/LSASS, services channel, direct disk or registry hole can be used to get the SAM. The SAM Juicer uses the first. There are other tools for all the other levels.

Regards,
Dr Craig Wright (GSE-Compliance)

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • [HPADM] SUMMARY Kernel parameter names and suggested values
    ... Thanks for all the replys here was the original question.I made the changes through SAM and all is well. ... We have an application that is using a lot of memory. ... For most of them I can just put in the number, but when I get to maxDsiz, maxTsiz, and maxSsiz I think I will have to put in their hex value??? ...
    (HP-UX-Admin)
  • Re: physical memory in HP
    ... >Please let me know how we check the physical memory on HP Unix Box. ... The 'sam' admin tool will show that somewhere along with the ... Use the kernel configuration section of 'sam' - really. ...
    (comp.unix.shell)
  • Re: Conditional Format - Formula to Colour Every 3rd Cell in Offset Range
    ... Thanks Sam! ... My eyes and memory are playing tricks on me! ...
    (microsoft.public.excel.misc)
  • Re: meia player 9
    ... Media 10 is out now. ... "SAM" wrote in message ... Any idea what the configuration of the memory for media player would be? ... My xp professional with 512 memory crashes every time I want to use it. ...
    (microsoft.public.windowsxp.general)