Re: How does the Cain and Abel SAM dump works?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Carlos Madrid wrote:
Some advice.. only try to crack the LM hashes. They won't be longer
then 14 chars.

It's even better than that. You're cracking two seven character hashes.
For a total of fourteen. It's faster to crack two seven character
passwords, than it is to crack one fourteen character pass.

Lan Manager should NEVER be run in production.

EVER.


Also read a little bit for more info:
http://en.wikipedia.org/wiki/LM_hash

The hashes are best retrieved with dll injection into lsass.

Random link to save me typing:
http://www.lcpsoft.com/english/articles/passwords.htm


On Mon, Jul 14, 2008 at 3:54 AM, Vikas Singhal
<vikas.programmer@xxxxxxxxx> wrote:
Hi Friends,

Nowaday, I am studying on the Topic - Cracking Windows password.

There are lot of tools out there which can dump LM and NTLM hashes for
you. But as far i know, you can't touch the SAM file when windows is
running, so, how does these tools work.

Is the sam dumped in-memory?

Regards
V




- --
Rob

+-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+
| _ |
| ASCII ribbon campaign ( ) |
| - against HTML email X |
| / \ |
| |
+-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Ignorance is bliss...

iEYEARECAAYFAkiABPkACgkQcfN68iZZIcdvMwCeKJeICHy5P5yc1P8zrhZ3I9tj
R0MAn24GPdFh0XLZwBrzay0Jm+q+52DZ
=cApK
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Secure Password Policy?
    ... On the Windows platform, by default, LM and NTLM hashes are ... Both store the password in 7 character segments. ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)
  • Re: string generation
    ... >>> I want to generate every possible 16 character combination of the ... Yes, but it still sounds like a cracking device, Dangermouse! ... constructing the actual array is, er, infeasible, that hardly matters. ... converting to base 62, but neither is difficult.) ...
    (comp.lang.c)
  • Re: [Full-disclosure] Best way to crack NT passwds
    ... I rarely crack any hashes (good memory for my own ... able to maximise cpu time to cracking the passwords. ...
    (Full-Disclosure)
  • Re: LophtCrack and SAM Passwd
    ... the hashes were likely encrypted with syskey ... William Woodhams a écrit: ... > cracking it with LophtCrack nothing worked. ... > A. Anyone have any good sources for large word lists? ...
    (Pen-Test)
  • Re: John the Ripper 1.7; pam_passwdqc 1.0+; tcb 1.0; phpass 0.0
    ... For salted hashes (such as of Unix passwords), ... I am not aware of rainbow table implementations for salted hashes, ... When cracking large numbers of hashes at once, ...
    (Bugtraq)