Re: Pwdump3, LC4, SysKey & SAM with win2k passwords

From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 12/06/02


From: "Karl Levinson [x y] mvp" <levinson_k@excite.com>
Date: Fri, 6 Dec 2002 13:06:10 -0500


"Scott" <zugget@AOL.COM> wrote in message
news:27e1765b.0212051815.7d9fbd8c@posting.google.com...
> I have two laptops running win2k. On laptop #1 I have administrator
> rights, pwdump3 and Lopthcrack. On Laptop #2 I do not have
> administrator rights. My goal is to get the administrator password
> for laptop#2 without reseting the adminstrator password or installing
> another version of win2k.

I'm not sure why I'm helping answer this. It doesn't sound like you're
doing anything kosher.

I would recommend using one of the standard password reset boot disks and
find one that permits insertion of a new user into the SAM. [I think there
is at least one out there that will do this]. Then, as long as this user is
admin-equivalent, you can log in and run pwdump3 to get the SAM, get the
original admin password and then delete the user you added. If it works, I
feel that would be the easiest method I can think of.

http://securityadmin.info/faq.htm#password

> So far I have obtained the SAM file from Laptop #2 but as we all know
> LC4 cannot do anything with it because it is SYSKEY encrypted. I read
> that there is a loophole with earlier versions of SYSKEY. Does
> anybody know if I can do a HEX dump of the SAM file and Xor the hashes
> together to remove the encyrption?

I'd be surprised if it was that easy. I would think they're probably
talking about NT 4.0 Syskey for the most serious vulnerabilities.

> I know I can use pwdump3 to remotely access a SAM file but do I need
> administrator rights on both laptops?

I would think you would need administrator [or possibly system] privileges
on the target laptop. You could use a number of privilege escalation
attacks to gain administrator privileges. Try seeing if IIS is running and
has vulnerabilities that could permit running code as System.

> Finally, can I replace the SAM file on Laptop#1 with the SAM file on
> Laptop#2 and run lopthcrack without doing any major damage to Laptop
> #1.

I don't think so. I think you'd need to replace the SAM file outside of
Windows, and then even if it did work, you'd need to know an
administrator-equivalent password to be able to log into the laptop and run
pwdump3 to extract the SAM.



Relevant Pages

  • Re: Verification of replication
    ... >>> and even to corruption of the back end data file. ... >> thought was to ask the user for the cases then filter the forms to ... make sure that the users don't log on as an administrator. ... > laptop, and allow it to be administered only when connected to the ...
    (microsoft.public.access.replication)
  • Re: Problem with sharing a printer in VISTA
    ... Or right click Add Printer Run as administrator ... This Vista print subsystem is ... re-download the Vista drivers and try again? ... quad CPU running with 4GB of ram and my laptop is running duo CPU ...
    (microsoft.public.windows.vista.print_fax_scan)
  • Re: Logon problems with networked laptop
    ... The password that you now need to access the laptop is the password for the Local Administrator account. ... To access the built-in Administrator account press Ctrl+Alt+Del twice and the logon screen. ... I am the administrator of my workgroup, but I do not know the administrator passwords for the domain associated with work, I am thinking this is the one I would need. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Help in logging on to the system
    ... > laptop anymore! ... > network domain anymore, and when I fill in there my professional user ID ... Try logging on as Administrator, ... If no-one knows the local Administrator account password, ...
    (microsoft.public.windowsxp.network_web)
  • Re: Gaining Administrator Access to Windows XP Professional SP2 Sy
    ... "Shenan Stanley" wrote: ... me to gain Administrator access to my PC by blanking the ... what happens when your laptop is stolen and someone is ... Be sure you understand the encryption model you use (and how to ...
    (microsoft.public.windowsxp.security_admin)