Re: SYSKEY does only protect the NTLM-Hash

From: Michael Müller2 (1234egal@gmx.net)
Date: 02/17/02


From: 1234egal@gmx.net (Michael Müller2)
Date: 17 Feb 2002 02:47:18 -0800

1234egal@gmx.net (=?ISO-8859-1?Q?Michael_M=FCller2?=) wrote in message news:<3afe7250.0202160944.16a652fe@posting.google.com>...
> Hi,
>
> I have installed syskey (nt4sp6) but i can still sniff the
> syskey-unprotected LM-Hash to decrypt it then. ntlm-hash is decrpyted
> with syskey.
> this mustn't be, right? syskey should protect the lm-hash and the
> ntlm-hash!
> plz help

-----------
CORRECTION:
-----------

Hi,
 
I have installed and enabled syskey (nt4sp6) but when i sniff the
LM-Hash, i can still brute-force it (not syskey encrypted). ntlm-hash
is encrypted with syskey.
this isn't right, or? syskey should protect not only the lm-hash, but
lm and ntlm hash!
plz help



Relevant Pages

  • RE: Password "security" - was"Passwords with Lan Manager (LM) under Windows" and
    ... > protect the cache entries stored on the laptops. ... Without the SYSKEY ... > that booting with another OS would not give the attacker access to the ... files encrypted on NTFS partitions created in Windows 2000, ...
    (Pen-Test)
  • RE: issues with syskey in NT 4.0
    ... The purpose of syskey is to further protect the weakly-encrypted ... passwords in the SAM database. ... password hashes from LOCAL attack (i.e., someone able to access them off the ... Other than backing up to protect the key, ...
    (Focus-Microsoft)
  • Re: there are tools ...
    ... Yes, if the goal is to protect data from being stolen, use EFS. ... Syskey doesn't protect the "disk". ...
    (microsoft.public.security)