Thursday, July 19, 2007

Windows NT SAM(crack administrator password)

Windows NT stores user information in the Security accounts Manager (SAM) database. Specifically, encrypted passwords are stored in the SAM._ file of the NT Registry, in the systemroot directory (The NT Resgistry is a database of information replacing the .ini files used in the Windows 3.X environment). Passwords are encrypted by a two part process when stored in the NT registry. First, passwords are hashed using the RSA MD4 scheme, then they are further obfuscated using DES encryption. Typically, access to the NT Registry is limited to the Administrator account. However, a back-up copy of the SAM._ file is normally created whenever the Emergency Repair Disk is updated and is stored in %systemroot%\repair\SAM._. The group "Everyone" has Read permission by default on this back-up copy of SAM._. As a result, "Everyone" has the potential to obtain or copy the encrypted password file. These are some software that will allow you to find the administrator password.

Crack a Sam Database using Ophcrack Ophcrack is a Windows password cracker based on a time-memory trade-off using rainbow tables. This is a new variant of Hellman's original trade-off, with better performance. It recovers 99.9% of alphanumeric passwords in seconds.















CIA Commander is the first tool in the world, that will give you full graphical access to any NT/Win2K installation after only 10 seconds boottime with one single bootfloppy. With graphical filemanager, registryeditor and usermanager that can even change passwords for any user or unlock locked accounts.















Active Password Changer is a DOS-based solution designed for resetting local user passwords in case of administrator's password is forgotten or lost. Forgotten password recovery software is useful if you lost the administrator password and cannot access the operation system. Other Windows login security restrictions like 'Account is disabled', 'Password never expires', 'Account is locked out' and 'Logon Hours' can be changed or reset.

No comments: