Re: Windows 2K/XP/2K3 password question

From: Matt Gibson (mattg_at_blueedgetech.ca)
Date: 03/30/05


Date: Tue, 29 Mar 2005 14:18:45 -0800

One way hash.

You can use tools like dumpsec to dump the SAM.

Matt Gibson - GSEC

"Shangwu" <sqi@nospam.net> wrote in message
news:ulLh91JNFHA.3784@TK2MSFTNGP12.phx.gbl...
> Hello,
>
> Is it possible to retrieve the password of a service's logon account in
> user mode program or kernel mode driver?
> How does Windows save a password? I know it is saved in SAM registry? Does
> Windows encrypt a password in one way (hash, non-decryptable) or two ways
> (decryptable) approach?
>
> Thanks,
> Shangwu
>



Relevant Pages

  • Re: Windows 2K/XP/2K3 password question
    ... "Matt Gibson" wrote in message ... > One way hash. ... I know it is saved in SAM registry? ... >> Windows encrypt a password in one way ...
    (microsoft.public.windows.server.security)
  • Re: WinNT and previously used passwords
    ... going to go through the hashes to get the history, ... It just brute forces the hash until it can ... > 10 passwords are achived in the SAM or registry maybe? ... If I remember correctly l0pht crack grabs ...
    (Vuln-Dev)
  • Re: Adding a unique user name in a file
    ... Jürgen Exner wrote in comp.lang.perl.misc: ... > sam wrote: ... >> to speed up the search rather than using linear search. ... existing users into a hash looks reasonable. ...
    (comp.lang.perl.misc)
  • Re: passing $cgi object in hash.
    ... > sam wrote: ... It is a plain old hash. ... Errr, I thought the subroutine was named testing, what is ...
    (comp.lang.perl.misc)