On newer Windows boxes the SAM is protected... but not from
LocalSystem :) PWDump3 is an example. It installs/dumps/uninstalls as
a Windows service.
-Patrick
On Mon, Jul 14, 2008 at 6:54 PM, Vikas Singhal
<vikas.programmer_at_gmail.com> wrote:
> Hi Friends,
>
> Nowaday, I am studying on the Topic - Cracking Windows password.
>
> There are lot of tools out there which can dump LM and NTLM hashes for
> you. But as far i know, you can't touch the SAM file when windows is
> running, so, how does these tools work.
>
> Is the sam dumped in-memory?
>
> Regards
> V
>
Received on Jul 16 2008