but i've been messing around with cain and able for some time now.
i need some help or advise
what are the best password crackers
what is the best method
and how would i make them portable?
thanks for helping this n00b
Sponsored by: █ Sparkhost - Hosting Without Compromises! █ Hybrid Performance Web Hosting █ Spark Host Stream Hosting █ Hybrid IRC & IRCd Server Shell Accounts
Posted 10 December 2009 - 07:39 PM
Posted 10 December 2009 - 08:03 PM
Posted 10 December 2009 - 08:09 PM
ok, lets say i need ways of obtaining the passwords.First off lets assume you are testing the strengths of your own passwords here.
Secondly, I'll assume you are testing Windows passwords? More than likely XP up? So NTLM(1 and 2)
There are countless techniques and tools for this. I'll go over a few quick ones.
If you are logged on to the PC and have admin privileges, you could run FGDump - which will dump the passwod hashes to a file for you. You then import that into your favourite password cracker. (You would have to install FGDump though, or if you ran it remotely, would need administrator privileges)
John the ripper - one of the oldest and best password crackers. Has customizable dictionaries and bruteforce. Can get most simple passwords very quickly. Load the hash once obtained with FGDump (predecessor of PWDump)
LopthCrack - Dictionaries, bruteforce (last i checked)
Cain - Can use dictionaries, bruteforce or rainbow tables.
Rainbow crack - Cracks only using rainbow tables
( Rainbow tables are pre-computed hashes. Makes cracking thousands of times faster.. but you need to obtain the right tables. You can learn more on them here http://en.wikipedia....i/Rainbow_table )
The tools mentioned above all crack Windows passwords. You just have to load the hashes. You want this to be portable. Perhaps you could install a Linux distro onto a USB stick (Like BackTrack and you could boot into these PCs and snatch the hashes and crack them later)
The tools above cover the PC once you are logged in. If you can't log in to the PC in question but have physical access then i'd recommend a bootkit. konboot will bypass all windows authentication. You can boot it up, log in with no password, run FGDump to get the password hashes then move on to cracking them with tools above. (There are numerous boot up disks with security tools, but the one i mentioned would probably be the easiest and quickest in this case... apart from)
opchrack http://ophcrack.sour...ge.net/ophcrack
ophcrack is a live linux distro, you boot off it, and it automatically loads all windows user accounts into a table, and automatically starts cracking them using built in dictionaries and rainbow tables. This will only crack simple passwords (or word combinations). But it will be very quick so usually good to start off with.
If you don't have physical access to the PC and want to crack their passwords remotely, you still need their password files. So the only way you can get on remotely is by exploiting a service on their box, 'hacking in' and getting their hashes.
There are many other ways of obtaining passwords - but you just asked about 'cracking them' so these are basically tools i know and use. Others may have different suggestions.
Posted 10 December 2009 - 08:46 PM
ok, lets say i need ways of obtaining the passwords.
First off lets assume you are testing the strengths of your own passwords here.
Secondly, I'll assume you are testing Windows passwords? More than likely XP up? So NTLM(1 and 2)
There are countless techniques and tools for this. I'll go over a few quick ones.
If you are logged on to the PC and have admin privileges, you could run FGDump - which will dump the passwod hashes to a file for you. You then import that into your favourite password cracker. (You would have to install FGDump though, or if you ran it remotely, would need administrator privileges)
John the ripper - one of the oldest and best password crackers. Has customizable dictionaries and bruteforce. Can get most simple passwords very quickly. Load the hash once obtained with FGDump (predecessor of PWDump)
LopthCrack - Dictionaries, bruteforce (last i checked)
Cain - Can use dictionaries, bruteforce or rainbow tables.
Rainbow crack - Cracks only using rainbow tables
( Rainbow tables are pre-computed hashes. Makes cracking thousands of times faster.. but you need to obtain the right tables. You can learn more on them here http://en.wikipedia....i/Rainbow_table )
The tools mentioned above all crack Windows passwords. You just have to load the hashes. You want this to be portable. Perhaps you could install a Linux distro onto a USB stick (Like BackTrack and you could boot into these PCs and snatch the hashes and crack them later)
The tools above cover the PC once you are logged in. If you can't log in to the PC in question but have physical access then i'd recommend a bootkit. konboot will bypass all windows authentication. You can boot it up, log in with no password, run FGDump to get the password hashes then move on to cracking them with tools above. (There are numerous boot up disks with security tools, but the one i mentioned would probably be the easiest and quickest in this case... apart from)
opchrack http://ophcrack.sour...ge.net/ophcrack
ophcrack is a live linux distro, you boot off it, and it automatically loads all windows user accounts into a table, and automatically starts cracking them using built in dictionaries and rainbow tables. This will only crack simple passwords (or word combinations). But it will be very quick so usually good to start off with.
If you don't have physical access to the PC and want to crack their passwords remotely, you still need their password files. So the only way you can get on remotely is by exploiting a service on their box, 'hacking in' and getting their hashes.
There are many other ways of obtaining passwords - but you just asked about 'cracking them' so these are basically tools i know and use. Others may have different suggestions.
so far cain works well when i do a dictionary & brute force on a lm hash.
my windows 7 only has ntls i believe its called
anyways once i get a hash, how would i hack or crack it using cain?
there is still a lot of stuff for me to learn and i would be happy if some one could teach me a bulk of the password obtaining/ cracking skill i need.
Posted 14 December 2009 - 12:07 PM
Posted 14 December 2009 - 12:12 PM
Posted 14 December 2009 - 08:09 PM
Posted 15 December 2009 - 12:16 PM
Posted 07 January 2010 - 11:02 AM
Posted 07 January 2010 - 01:01 PM
Yeah guys, I need to crack not reset. People come to me to have their passwords recovered and what not. The same goes for the encrypted files.
and Edu, what is the zip you are talking about?
Posted 08 January 2010 - 09:48 AM
Also when you're getting the hashes from the SAM, be sure to check if there are LM hashes. They are far more easier to crack. If you need to do this frequently rainbowtables are the way to go.Yeah guys, I need to crack not reset. People come to me to have their passwords recovered and what not. The same goes for the encrypted files.
and Edu, what is the zip you are talking about?
Posted 31 March 2010 - 07:26 AM
Posted 26 April 2010 - 11:54 PM
Yeah guys, I need to crack not reset. People come to me to have their passwords recovered and what not. The same goes for the encrypted files.
and Edu, what is the zip you are talking about?
Posted 30 July 2010 - 04:53 PM
Posted 02 August 2010 - 05:40 AM
0 members, 0 guests, 0 anonymous users