|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 55
Members: 0
Total: 55
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
obviously not as easy a crack as I hoped it might be.. |
|
|
|
|
I've been running LM alpha tables just against a ton of accounts, with cain.. and it works great, and when it gets 1/2 the pw it shows that 1/2 of it.... Got me about 4000 pw's off the bat.. in just a ... |
|
|
|
|
I'm not sure why it's empty.. other than the pw could be longer than 15 characters??
The pc registry for logon is not set to not keep LM hashes..
Domain policy also does not say "no lm hash'....
... |
|
|
|
|
registry of the pc?
hmmm
could try that... not sure where it would have stored it. |
|
|
|
|
success probability 0
well that sucks... |
|
|
|
|
not forced to change password.
Just looks like it got changed... the 2nd hash did anyway...
hash is now
pandenclv:"":"":AAD3B435B51404EEAAD3B435B51404EE:39C8871C817D9FE0046BD54E566ACC15 |
|
|
|
|
123Gb?
I told winrtgen to do 7-14 characters, lower alpha-numeric, ntlm...
and it says it will do it in 600mb
is that incorrect? |
|
|
|
|
I'll apologize now before I annoy the crap out of you... Appreciate the help.
Got winrtgen... generating tables for pw's of 7-15 characters... that will make 600mb of rainbow tables. I could then d ... |
|
|
|
|
cain/abel w/ the syskey won't work?
As I said, new to this, so I'm kind of grasping at straws...
I thought maybe if I can dump the sam, it would work. |
|
|
|
|
Ok I have a hard drive from the domain controller of the system I was working on, installed into a separate piece of hardware....
So I have this "clone" of the DC, totally outside the network, offlin ... |
|
|
|
|
It seems like it's a possibility. Just not sure.
I went ahead and set the account to reversible. I'm going to dump the AD out tomorrow, and see if C&A can figure anything out..
For whatever rea ... |
|
|
|
|
Seems I can't find much documentation on the "store as reversible" field.
Microsoft doesn't document when the change is made... I've searched everywhere I can think of though.
Anyone tried it ever? |
|
|
|
|
Yes, it's NTLM out of a dump from AD.
I tried to brute force it as well but I couldn't get it. I'm not sure, maybe it's longer of a pw than I thought.
I have a followup question on this, maybe so ... |
|
|
|
|
admittedly new to this, got a few so far, can't get this one.
pandenclv:"":"":AAD3B435B51404EEAAD3B435B51404EE:4355D77672F12CAB3962DBC21A44479A |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|