hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

ThrillKill
hey there, been doing some reading i know its possible to get SQL password hashs from machine but you need 'sa' right or simpler,

question is if person has access to the machine remotely with Windows password is it possible to get SQL password ?
Guenter
to read the password hash you must be dbo (sa) ther is no other easy way to do this. anyway if you have a account (low priv.) in the database you can use some of the extented storaged procedures to get full controll (sp_exe..) everone have per default the execute right on this proc. and it run under the permission of the dbo (so everone can read the password hash). for the windows administrator more possib. exist.

sorry for my bad english

guenter
ThrillKill
yeh already know how to get the hashs and stuff main question was if its possible to get the hashs without having SQL password oh well guess not dry.gif
T3cHn0b0y
Just locate the master database! Open it with a text editor, find the sysxlogins table and use whatever methods u were to crack the hashes from there.
krackatoa
xfocus has a windows sql password sniffer.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.