Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: SAM encrypted with syskey

Re: SAM encrypted with syskey

From: Brendan Dolan-Gavitt <bdolangavitt_at_wesleyan.edu>
Date: Thu, 10 Feb 2005 22:09:35 -0500

There are utilities for extracting the syskey and decrypting the SAM at
http://studenti.unina.it/~ncuomo/syskey/ . Note that this is the third
result on Google if you search for "syskey" :p

From there it's just a basic LM or NT password cracking exercise...

-Brendan

> -----Original Message-----
> From: Anzaldo, Oscar [mailto:Oscar.Anzaldo_at_xerox.com]
> Sent: Tuesday, February 08, 2005 10:50 AM
> To: vuln-dev_at_securityfocus.com
> Subject: SAM encrypted with syskey
>
> Hi list,
>
> Does any one knows a method to retrieve the password for the SAM
> (NT/W2K) that has been encripted with syskey? Or bypass the system
> startup password?
>
> Regards
>
> Oscar.
>
>
>

Received on Feb 11 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos