Page 2 of 2 FirstFirst 12
Results 11 to 17 of 17

Thread: LMHashes

  1. #11
    Thank you for the quick reply. Appreciate it.
    MySig != Worth your time

  2. #12
    Junior Member
    Join Date
    Mar 2003
    Posts
    1
    hi, kind of new around here

    a while ago I ran into
    smbproxy
    link was down right now but I'm sure you can find it somewhere
    it allows you to mount smb shares with the hash from the sam file, without spending time cracking it

  3. #13
    Junior Member
    Join Date
    Feb 2004
    Posts
    10
    and nobody mentions that the only way to access your SAM file is through another OS (or by using something like LC4 which was mentioned) like knoppix std, or perhaps you could use minuteOS, but from what I read you cant access the SAM file of the OS you are running at the time, I tried and kept getting told that it was inaccessible, on a win2000pro box. I havent tried on my XPpro machine at my house.

    oh yeah the password Moemoemoe1 (upper and lowercase letters, and number, and something that wouldnt \get found in a dictionary attack) took almost 5 hours to crack with LC4, with an Athlon XP 2600+ w/256MB PC2700 DDR RAM, while not running anything else (other that Trillian, and the regular OS stuff)
    btw that was just a random (well not totally random) password that I threw in my admin acount for the test.

  4. #14
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    If you really want to make the password cracker's job difficult throw in the old <ALT>NNN keypad character somewhere in the password. I have yet to come across password crackers that go that far. Lopht etc. go as far as all printable characters and doing that the time to brute force a password > 8 characters is in the "months" timeframe. Adding the additional 127(?) non-printable characters would make the job nearly impossible for someone without practically unlimited resources.

    Put 2 or 3 of them in a 10+ length password including all printable characters and you could almost email your favorite hacker the SAM and sit back and giggle.....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  5. #15
    Senior Member Maestr0's Avatar
    Join Date
    May 2003
    Posts
    604
    and nobody mentions that the only way to access your SAM file is through another OS (or by using something like LC4 which was mentioned) like knoppix std, or perhaps you could use minuteOS, but from what I read you cant access the SAM file of the OS you are running at the time
    A copy of the SAM can be created easily in Windows NT using rdisk, and in Windows 2000/XP access to the hashes can be gained by accounts with debug rights using lsadump or pwdump3.

    -Maestr0
    \"If computers are to become smart enough to design their own successors, initiating a process that will lead to God-like omniscience after a number of ever swifter passages from one generation of computers to the next, someone is going to have to write the software that gets the process going, and humans have given absolutely no evidence of being able to write such software.\" -Jaron Lanier

  6. #16
    AO Guinness Monster MURACU's Avatar
    Join Date
    Jan 2004
    Location
    paris
    Posts
    1,003
    Another very simple thing to do is use "?" or "*" characters. A lot of password crackers use these to show the characters of the password that are not yet found. The programme will still find the password but it might confuse a script kiddie a bit.

    If you have to go with a lmhash because of backward compatabilty I would suggest that the first and eight charater, at least should be either special charaters of the type "@" "&" or nonprintable as was suggested above.
    For the best passwords go with the unprintable characters.
    \"America is the only country that went from barbarism to decadence without civilization in between.\"
    \"The reason we are so pleased to find other people\'s secrets is that it distracts public attention from our own.\"
    Oscar Wilde(1854-1900)

  7. #17
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    it might confuse a script kiddie a bit.
    ROFLMAO..... I just had this picture of the skeleton of this skiddie sat in front of his computer staring at a screen that says "Password so far: mary?"
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •