Security Basics mailing list archives

Re: Re: Fwd: How does the Cain and Abel SAM dump works?


From: anon () anon com
Date: 18 Jul 2008 06:29:06 -0000

Here is the source code for pwdump tool: http://us1.samba.org/samba/ftp/pwdump/pwdump.c

You need to be running with system privelages to access:

HKEY_LOCAL_MACHINE\SAM
AND
HKEY_LOCAL_MACHINE\SECURITY

SAM will give you the windows hashes and SECURITY will give you the LSA secrets.

To elevate your privelages from Administrator to SYSTEM do the following:

If the current time is 09:40:

Start > Run > at 09:41 /INTERACTIVE regedt32

In a minute the registry editor will fire up with system privileges and you will be able to explore the SAM database :)

Kind Regards,

Johann

http://www.linkedin.com/in/johannoosthuizen


Current thread: