Re: password security
From: Karl Levinson [x y] MVP (jamescagney90210@excite.com)
Date: 10/19/02
- Next message: Karl Levinson [x y] MVP: "Re: How do I implement Group policy?"
- Previous message: Karl Levinson [x y] MVP: "Re: administrator unable to logon interactively"
- In reply to: Altan: "password security"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Karl Levinson [x y] MVP" <jamescagney90210@excite.com> Date: Sat, 19 Oct 2002 10:49:15 -0400
Just purchase l0phtcrack or visit www.l0pht.com or search for documentation
on pwdump3 or search google. It's all described in great detail. [I think
it's hard to find the documentation on this at l0pht.com unless you own the
l0phtcrack program, I'm not sure there was a link to it on their web site,
only in the program itself.]
Getting the complete user database from a Windows 2000 domain controller is
more difficult than using pwdump to dump it from an NT domain controller.
pwdump3 documentation has more details. On the other hand, there are other
ways to get password hashes, such as by using the sniffer that is included
in l0phtcrack, by tricking the workstation or user into trying to connect to
your IP address, etc.
Windows 2000 domain controllers do not use a SAM for domain passwords, but I
understand there is a SAM for the local admin password for when booting into
Recovery Console mode, Directory Services Restore mode, or any mode where
Active Directory cannot be used to authenticate users because is not
started.
I have full confidence that you will only be using this knowledge for good
and not for evil.
"Altan" <n@s.com> wrote in message
news:708901c276cf$8bd33de0$3bef2ecf@TKMSFTNGXA10...
> Is their any possible way a domain user from his
> workstation to crack the users passwords from the domain
> controller from his workstation. Without physical access
> to the servers?
> Windows 2k servers and Win 2k workstations
- Next message: Karl Levinson [x y] MVP: "Re: How do I implement Group policy?"
- Previous message: Karl Levinson [x y] MVP: "Re: administrator unable to logon interactively"
- In reply to: Altan: "password security"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|