Syskey

From: Michel Arboi (arboi@yahoo.com)
Date: 09/06/02


Date: Fri, 6 Sep 2002 08:58:42 +0200 (CEST)
From: Michel Arboi <arboi@yahoo.com>
To: vuln-dev <vuln-dev@securityfocus.com>

By default, Windows 2K encrypts the SAM entries, so that a stolen
"sam" file cannot be used to retrieve passwords.
However, the encryption key is most of the time stored in the system
through a "complex obfuscation function" (dixit Microsoft).

I wonder if somebody has studied this function. It should be possible
to get the key and decrypt the SAM e.g. with a Linux boot floppy or
from a "stolen" hard disk.
(I *know* pwdump[1-3] and it does not solve this problem)

___________________________________________________________
Do You Yahoo!? -- Une adresse @yahoo.fr gratuite et en français !
Yahoo! Mail : http://fr.mail.yahoo.com



Relevant Pages

  • RE: question regarding SAM file / l0phtcrack / pwdump2
    ... required to dump the SAM? ... minimum password lengths, enabling password histories, ... Check out Yahoo! ...
    (Focus-Microsoft)
  • Sam Sloans Fide-Chess Yahoo Group
    ... The feed fide-chess at Yahoo! ... You can see what Sam is posting without ever having to open his web ...
    (rec.games.chess.misc)
  • [HPADM] autonegotiate
    ... We are going to set the switch to the same setting! ... The question is can I turn this off using SAM and will the setting survive a reboot? ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (HP-UX-Admin)
  • RE: Unwanted programs on Win2K
    ... Just for your info, there is a thing such as .SAM files, MS office uses ... the easiest is to crack the .SAM file. ... the backup copy of the ... Do you Yahoo!? ...
    (Security-Basics)