There are utilities for extracting the syskey and decrypting the SAM at
http://studenti.unina.it/~ncuomo/syskey/ . Note that this is the third
result on Google if you search for "syskey" :p
From there it's just a basic LM or NT password cracking exercise...
-Brendan
> -----Original Message-----
> From: Anzaldo, Oscar [mailto:Oscar.Anzaldo_at_xerox.com]
> Sent: Tuesday, February 08, 2005 10:50 AM
> To: vuln-dev_at_securityfocus.com
> Subject: SAM encrypted with syskey
>
> Hi list,
>
> Does any one knows a method to retrieve the password for the SAM
> (NT/W2K) that has been encripted with syskey? Or bypass the system
> startup password?
>
> Regards
>
> Oscar.
>
>
>
Received on Feb 11 2005