SlideShare a Scribd company logo
1 of 17
“Dumping and Cracking SAM Hashes
to Extract Plaintext Passwords”
By:
-Vishal Kumar
(CEH, CHFI, CISE, MCP)
info@prohackers.in
Lab - 1
“Dumping and Cracking SAM Hashes to
Extract Plaintext Passwords”
Pwdump7 can be used to dump protected files. You can always
copy a used file by executing pwdump7.exe –d c:lockedfile.dat
backup-lockedfile.dat Ophcrack is a free open-source (GPL
license) program that cracks Windows password by using LM
hashes through rainbow tables.
Lab Scenario
The Security Account Manager (SAM) is a database file present on
Windows machine that store user account and security decryptors
for users on local computer. It store user’s password in a hashes
format (in LM hash and NTLM hash). Because a hashes function is
one-way, this provide some measure of security for the storage of
the passwords.
In a system hacking life cycle, attackers generally dump
operating system password hashes immediately after a
compromise a target machine. The password hashes enable
attackers to launch a verity of attacks on system, including
password cracking, pass the hash, unauthorized access of other..
Lab Scenario
System using the same password, password analysis, and pattern
recognition, in order to crack other passwords in the target
environment.
You need to have administrator access to dump the content
of the SAM file. Assessment of a password strength is critical
milestone during your security assessment engagement. You will
start your password assessment with a simple SAM hash dump and
running it with a hash decryptor to uncover the plaintext
password.
Lab Objective
The objective of this lab is to help peoples to lean how to;
• Use the pwdump7 tool to extract password hashes.
• Use the Opcrack tool to crack the hash and obtain the
plaintext password.
Overview of the Lab
Pwdump7 can be used to dump protected file. You can always
copy a used file executing the command pwdump7.exe –d
c:lockedfile.dat backup-lockedfile.dat. Rainbow table for LM
hashes of alphanumeric passwords are provided free by the
developers. By default, Ophcrack is bundled with table that allow
it to crack passwords not longer then 14 characters using only
alphanumeric characters.
Lab Task 01:- Generate Hashes
• Open the command prompt, and navigate the location the
pwdump7 folder. Alternatively you can navigate from the windows
explorer to the pwdump7 folder and right-click and select open
Cmd Here.
• Now run the command pwdump7.exe, and press Enter. This
displays all the
Lab Task 01:- Generate Hashes
password hashes as shown in the above screenshot.
• Now, save the hashes in a text file by issuing the command
pwdump.exe >d:hashes.txt and press Enter, in this command
we are saving the hashes in the hashes.txt file in the D: drive.
• Now, open the D: drive and locate the hashes.txt and double-
click to open the
Lab Task 02:- Install Ophcrack
• Navigate to the directory you have saved the setup od Ophcrack
and double-click on the ophcrack-win32-installer-3.6.0.exe,
to install the Ophcrack. You can also download the Ophcrack
from the www.Ophcrack.sourceforge.net.
• Ophcrack installation window opens, click next to install the
application.
Lab Task 02:- Install Ophcrack
• In the choose components section, uncheck all the options,
and click Next
Lab Task 03:- Task 03:- Crack the Password
• On completion the installation
open the application from the
Apps screen . The Ophcrack
main window appears as shown
in the screenshot.
Lab Task 03:- Task 03:- Crack the Password
Click the Load menu and select
PWDUMP file. The Open PWDUMP file
window appears. Browse the D: and
select the hashes.txt which has been
created through Pwdump7, and click
Open.
Lab Task 03:- Task 03:- Crack the Password
• The hashes are loaded in the Ophcrack under the NT Hash
column. Now, click on the Table menu, the Table Selection
window appear, select Vista free and click Install.
Note:- to install the Tables you need to download the tables from the internet,
you can download the table from http://Ophcrack.sourceforge.net/tables.php.
• The Select the directory which contains the tables window
appears, brown the location where the table has been
downloaded or stored. Select the folder in which the tables are
stored and click Select Folder.
Lab Task 03:- Task 03:- Crack the Password
This tables_vist_free is a pre-
computed tables for reversing
cryptographic hash functions and
recovering a plaintext password up to
a certain length.
The selected table_vista_free is
installed under the name Vista free,
which is represented by a green
colored bullet. Select the table and
click OK.
Lab Task 03:- Task 03:- Crack the Password
• Click Crack on the menu
bar. Ophcrack begin to
crack the passwords.
• The cracked password are
displayed in the plaintext
as in the below screenshot.
Lab Analysis
We have analyze the password hashes gathered during this lab, and
figured out what the password was.
Tool/Utility Information Collected/Objectives Achieved
Pwdump7
Ophcrack
IP Address Range/target:- Windows 8.1
machine
Scan Result:-
•Generate the user password Hashes
•Crack the password in the plaintext
Feedback
Thanks for reading this presentation
Please give us your feedback at
info@prohackers.in
Your feedback is most valuable for us for improving the presentation
You can also suggest the topic on which you want the presentation
Website: www.prohackers.in
FB page: www.facebook.com/theprohackers2017
Join FB Group: www.facebook.com/groups/group.prohackers/
Watch us on: www.youtube.com//channel/UCcyYSi1sh1SmyMlGfB-Vq6A

More Related Content

What's hot

Veeam Software : Sauvegarde et protection moderne des données
Veeam Software : Sauvegarde et protection moderne des données Veeam Software : Sauvegarde et protection moderne des données
Veeam Software : Sauvegarde et protection moderne des données
Microsoft Technet France
 

What's hot (20)

Website #01: HTML cơ bản
Website #01: HTML cơ bảnWebsite #01: HTML cơ bản
Website #01: HTML cơ bản
 
Sql injection demo - it-slideshares.blogspot.com
Sql injection   demo - it-slideshares.blogspot.comSql injection   demo - it-slideshares.blogspot.com
Sql injection demo - it-slideshares.blogspot.com
 
XSS & SQL injection
XSS & SQL injectionXSS & SQL injection
XSS & SQL injection
 
Tường lửa ip cop
Tường lửa ip copTường lửa ip cop
Tường lửa ip cop
 
luan van thac si tim hieu cong cu nessus trong phat hien lo hong bao mat tren...
luan van thac si tim hieu cong cu nessus trong phat hien lo hong bao mat tren...luan van thac si tim hieu cong cu nessus trong phat hien lo hong bao mat tren...
luan van thac si tim hieu cong cu nessus trong phat hien lo hong bao mat tren...
 
Xử lý ảnh theo phương pháp âm bản, nhị phân, hàm số mũ
Xử lý ảnh theo phương pháp âm bản, nhị phân, hàm số mũXử lý ảnh theo phương pháp âm bản, nhị phân, hàm số mũ
Xử lý ảnh theo phương pháp âm bản, nhị phân, hàm số mũ
 
Spring framework
Spring frameworkSpring framework
Spring framework
 
Local File Inclusion to Remote Code Execution
Local File Inclusion to Remote Code ExecutionLocal File Inclusion to Remote Code Execution
Local File Inclusion to Remote Code Execution
 
Hacking Oracle From Web Apps 1 9
Hacking Oracle From Web Apps 1 9Hacking Oracle From Web Apps 1 9
Hacking Oracle From Web Apps 1 9
 
Chứng thực ldap trên firewall fortigate
Chứng thực ldap trên firewall fortigateChứng thực ldap trên firewall fortigate
Chứng thực ldap trên firewall fortigate
 
Sql injection with sqlmap
Sql injection with sqlmapSql injection with sqlmap
Sql injection with sqlmap
 
SQL Injection
SQL InjectionSQL Injection
SQL Injection
 
Veeam Software : Sauvegarde et protection moderne des données
Veeam Software : Sauvegarde et protection moderne des données Veeam Software : Sauvegarde et protection moderne des données
Veeam Software : Sauvegarde et protection moderne des données
 
Linux06 nfs
Linux06 nfsLinux06 nfs
Linux06 nfs
 
Pwning the Enterprise With PowerShell
Pwning the Enterprise With PowerShellPwning the Enterprise With PowerShell
Pwning the Enterprise With PowerShell
 
Tấn công sql injection sử dụng câu lệnh select union
Tấn công sql injection sử dụng câu lệnh select unionTấn công sql injection sử dụng câu lệnh select union
Tấn công sql injection sử dụng câu lệnh select union
 
Chuong 3 windows forms
Chuong 3   windows formsChuong 3   windows forms
Chuong 3 windows forms
 
luan van thac si phat hien lo hong bao mat trong mang lan
luan van thac si phat hien lo hong bao mat trong mang lanluan van thac si phat hien lo hong bao mat trong mang lan
luan van thac si phat hien lo hong bao mat trong mang lan
 
A Quick Introduction to Linux
A Quick Introduction to LinuxA Quick Introduction to Linux
A Quick Introduction to Linux
 
SQL injection
SQL injectionSQL injection
SQL injection
 

Similar to Dumping and Cracking SAM Hashes to Extract Plaintext Passwords

Power point on linux commands,appache,php,mysql,html,css,web 2.0
Power point on linux commands,appache,php,mysql,html,css,web 2.0Power point on linux commands,appache,php,mysql,html,css,web 2.0
Power point on linux commands,appache,php,mysql,html,css,web 2.0
venkatakrishnan k
 
Exploit Frameworks
Exploit FrameworksExploit Frameworks
Exploit Frameworks
phanleson
 
Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011
Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011
Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011
camp_drupal_ua
 

Similar to Dumping and Cracking SAM Hashes to Extract Plaintext Passwords (20)

55 best linux tips, tricks and command lines
55 best linux tips, tricks and command lines55 best linux tips, tricks and command lines
55 best linux tips, tricks and command lines
 
Chapter 1: Introduction to Command Line
Chapter 1: Introduction  to Command LineChapter 1: Introduction  to Command Line
Chapter 1: Introduction to Command Line
 
Chapter 1: Introduction to Command Line
Chapter 1: Introduction to  Command LineChapter 1: Introduction to  Command Line
Chapter 1: Introduction to Command Line
 
Wamp & LAMP - Installation and Configuration
Wamp & LAMP - Installation and ConfigurationWamp & LAMP - Installation and Configuration
Wamp & LAMP - Installation and Configuration
 
Matlab m files
Matlab m filesMatlab m files
Matlab m files
 
Installing Hortonworks Hadoop for Windows
Installing Hortonworks Hadoop for WindowsInstalling Hortonworks Hadoop for Windows
Installing Hortonworks Hadoop for Windows
 
Post exploitation using powershell
Post exploitation using powershellPost exploitation using powershell
Post exploitation using powershell
 
Install websphere message broker 8 RHEL 6 64 bits
Install websphere message broker 8 RHEL 6 64 bitsInstall websphere message broker 8 RHEL 6 64 bits
Install websphere message broker 8 RHEL 6 64 bits
 
Linux
Linux Linux
Linux
 
Power point on linux commands,appache,php,mysql,html,css,web 2.0
Power point on linux commands,appache,php,mysql,html,css,web 2.0Power point on linux commands,appache,php,mysql,html,css,web 2.0
Power point on linux commands,appache,php,mysql,html,css,web 2.0
 
Linux presentation
Linux presentationLinux presentation
Linux presentation
 
OpenNMS - My Notes
OpenNMS - My NotesOpenNMS - My Notes
OpenNMS - My Notes
 
linux installation.pdf
linux installation.pdflinux installation.pdf
linux installation.pdf
 
Bc0056 unix operating system
Bc0056   unix operating systemBc0056   unix operating system
Bc0056 unix operating system
 
THE BASIC TOOLS
THE BASIC TOOLSTHE BASIC TOOLS
THE BASIC TOOLS
 
Java Programming
Java ProgrammingJava Programming
Java Programming
 
202110 SESUG 49 UNIX X Command Tips and Tricks
202110 SESUG 49 UNIX X Command Tips and Tricks202110 SESUG 49 UNIX X Command Tips and Tricks
202110 SESUG 49 UNIX X Command Tips and Tricks
 
Exploit Frameworks
Exploit FrameworksExploit Frameworks
Exploit Frameworks
 
Linux week 2
Linux week 2Linux week 2
Linux week 2
 
Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011
Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011
Sergei Stryukov.Drush.Why it should be used.DrupalCamp Kyiv 2011
 

More from Vishal Kumar

More from Vishal Kumar (20)

Threat Hunting Procedures and Measurement Matrice
Threat Hunting Procedures and Measurement MatriceThreat Hunting Procedures and Measurement Matrice
Threat Hunting Procedures and Measurement Matrice
 
The Complete Questionnaires About Firewall
The Complete Questionnaires About FirewallThe Complete Questionnaires About Firewall
The Complete Questionnaires About Firewall
 
E-mail Security Protocol - 2 Pretty Good Privacy (PGP)
E-mail Security Protocol - 2 Pretty Good Privacy (PGP)E-mail Security Protocol - 2 Pretty Good Privacy (PGP)
E-mail Security Protocol - 2 Pretty Good Privacy (PGP)
 
E-Mail Security Protocol - 1 Privacy Enhanced Mail (PEM) Protocol
E-Mail Security Protocol - 1 Privacy Enhanced Mail (PEM) ProtocolE-Mail Security Protocol - 1 Privacy Enhanced Mail (PEM) Protocol
E-Mail Security Protocol - 1 Privacy Enhanced Mail (PEM) Protocol
 
Privileges Escalation by Exploiting Client-Side Vulnerabilities Using Metasploit
Privileges Escalation by Exploiting Client-Side Vulnerabilities Using MetasploitPrivileges Escalation by Exploiting Client-Side Vulnerabilities Using Metasploit
Privileges Escalation by Exploiting Client-Side Vulnerabilities Using Metasploit
 
Exploiting Client-Side Vulnerabilities and Establishing a VNC Session
Exploiting Client-Side Vulnerabilities and Establishing a VNC SessionExploiting Client-Side Vulnerabilities and Establishing a VNC Session
Exploiting Client-Side Vulnerabilities and Establishing a VNC Session
 
Auditing System Password Using L0phtcrack
Auditing System Password Using L0phtcrackAuditing System Password Using L0phtcrack
Auditing System Password Using L0phtcrack
 
Fundamental of Secure Socket Layer (SSL) | Part - 2
Fundamental of Secure Socket Layer (SSL) | Part - 2 Fundamental of Secure Socket Layer (SSL) | Part - 2
Fundamental of Secure Socket Layer (SSL) | Part - 2
 
The Fundamental of Electronic Mail (E-mail)
The Fundamental of Electronic Mail (E-mail)The Fundamental of Electronic Mail (E-mail)
The Fundamental of Electronic Mail (E-mail)
 
Fundamental of Secure Socket Layer (SSl) | Part - 1
Fundamental of Secure Socket Layer (SSl) | Part - 1Fundamental of Secure Socket Layer (SSl) | Part - 1
Fundamental of Secure Socket Layer (SSl) | Part - 1
 
The Fundamental of Secure Socket Layer (SSL)
The Fundamental of Secure Socket Layer (SSL)The Fundamental of Secure Socket Layer (SSL)
The Fundamental of Secure Socket Layer (SSL)
 
Hawkeye the Credential Theft Maalware
Hawkeye   the Credential Theft MaalwareHawkeye   the Credential Theft Maalware
Hawkeye the Credential Theft Maalware
 
Deep understanding on Cross-Site Scripting and SQL Injection
Deep understanding on Cross-Site Scripting and SQL InjectionDeep understanding on Cross-Site Scripting and SQL Injection
Deep understanding on Cross-Site Scripting and SQL Injection
 
Owasp top 10 security threats
Owasp top 10 security threatsOwasp top 10 security threats
Owasp top 10 security threats
 
Exploiting parameter tempering attack in web application
Exploiting parameter tempering attack in web applicationExploiting parameter tempering attack in web application
Exploiting parameter tempering attack in web application
 
Mirroring web site using ht track
Mirroring web site using ht trackMirroring web site using ht track
Mirroring web site using ht track
 
Collecting email from the target domain using the harvester
Collecting email from the target domain using the harvesterCollecting email from the target domain using the harvester
Collecting email from the target domain using the harvester
 
Information gathering using windows command line utility
Information gathering using windows command line utilityInformation gathering using windows command line utility
Information gathering using windows command line utility
 
Introduction ethical hacking
Introduction ethical hackingIntroduction ethical hacking
Introduction ethical hacking
 
Social engineering
Social engineeringSocial engineering
Social engineering
 

Recently uploaded

Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi EscortsRussian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Monica Sydney
 
一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理
F
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
gajnagarg
 
一比一原版奥兹学院毕业证如何办理
一比一原版奥兹学院毕业证如何办理一比一原版奥兹学院毕业证如何办理
一比一原版奥兹学院毕业证如何办理
F
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
ayvbos
 
Abu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu DhabiAbu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Monica Sydney
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
pxcywzqs
 
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
JOHNBEBONYAP1
 
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
ayvbos
 

Recently uploaded (20)

Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi EscortsRussian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
 
一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
 
Local Call Girls in Seoni 9332606886 HOT & SEXY Models beautiful and charmin...
Local Call Girls in Seoni  9332606886 HOT & SEXY Models beautiful and charmin...Local Call Girls in Seoni  9332606886 HOT & SEXY Models beautiful and charmin...
Local Call Girls in Seoni 9332606886 HOT & SEXY Models beautiful and charmin...
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
 
一比一原版奥兹学院毕业证如何办理
一比一原版奥兹学院毕业证如何办理一比一原版奥兹学院毕业证如何办理
一比一原版奥兹学院毕业证如何办理
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
 
Abu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu DhabiAbu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
 
Call girls Service in Ajman 0505086370 Ajman call girls
Call girls Service in Ajman 0505086370 Ajman call girlsCall girls Service in Ajman 0505086370 Ajman call girls
Call girls Service in Ajman 0505086370 Ajman call girls
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
 
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
Ballia Escorts Service Girl ^ 9332606886, WhatsApp Anytime Ballia
Ballia Escorts Service Girl ^ 9332606886, WhatsApp Anytime BalliaBallia Escorts Service Girl ^ 9332606886, WhatsApp Anytime Ballia
Ballia Escorts Service Girl ^ 9332606886, WhatsApp Anytime Ballia
 
Best SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency DallasBest SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency Dallas
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
 

Dumping and Cracking SAM Hashes to Extract Plaintext Passwords

  • 1. “Dumping and Cracking SAM Hashes to Extract Plaintext Passwords” By: -Vishal Kumar (CEH, CHFI, CISE, MCP) info@prohackers.in Lab - 1
  • 2. “Dumping and Cracking SAM Hashes to Extract Plaintext Passwords” Pwdump7 can be used to dump protected files. You can always copy a used file by executing pwdump7.exe –d c:lockedfile.dat backup-lockedfile.dat Ophcrack is a free open-source (GPL license) program that cracks Windows password by using LM hashes through rainbow tables.
  • 3. Lab Scenario The Security Account Manager (SAM) is a database file present on Windows machine that store user account and security decryptors for users on local computer. It store user’s password in a hashes format (in LM hash and NTLM hash). Because a hashes function is one-way, this provide some measure of security for the storage of the passwords. In a system hacking life cycle, attackers generally dump operating system password hashes immediately after a compromise a target machine. The password hashes enable attackers to launch a verity of attacks on system, including password cracking, pass the hash, unauthorized access of other..
  • 4. Lab Scenario System using the same password, password analysis, and pattern recognition, in order to crack other passwords in the target environment. You need to have administrator access to dump the content of the SAM file. Assessment of a password strength is critical milestone during your security assessment engagement. You will start your password assessment with a simple SAM hash dump and running it with a hash decryptor to uncover the plaintext password.
  • 5. Lab Objective The objective of this lab is to help peoples to lean how to; • Use the pwdump7 tool to extract password hashes. • Use the Opcrack tool to crack the hash and obtain the plaintext password.
  • 6. Overview of the Lab Pwdump7 can be used to dump protected file. You can always copy a used file executing the command pwdump7.exe –d c:lockedfile.dat backup-lockedfile.dat. Rainbow table for LM hashes of alphanumeric passwords are provided free by the developers. By default, Ophcrack is bundled with table that allow it to crack passwords not longer then 14 characters using only alphanumeric characters.
  • 7. Lab Task 01:- Generate Hashes • Open the command prompt, and navigate the location the pwdump7 folder. Alternatively you can navigate from the windows explorer to the pwdump7 folder and right-click and select open Cmd Here. • Now run the command pwdump7.exe, and press Enter. This displays all the
  • 8. Lab Task 01:- Generate Hashes password hashes as shown in the above screenshot. • Now, save the hashes in a text file by issuing the command pwdump.exe >d:hashes.txt and press Enter, in this command we are saving the hashes in the hashes.txt file in the D: drive. • Now, open the D: drive and locate the hashes.txt and double- click to open the
  • 9. Lab Task 02:- Install Ophcrack • Navigate to the directory you have saved the setup od Ophcrack and double-click on the ophcrack-win32-installer-3.6.0.exe, to install the Ophcrack. You can also download the Ophcrack from the www.Ophcrack.sourceforge.net. • Ophcrack installation window opens, click next to install the application.
  • 10. Lab Task 02:- Install Ophcrack • In the choose components section, uncheck all the options, and click Next
  • 11. Lab Task 03:- Task 03:- Crack the Password • On completion the installation open the application from the Apps screen . The Ophcrack main window appears as shown in the screenshot.
  • 12. Lab Task 03:- Task 03:- Crack the Password Click the Load menu and select PWDUMP file. The Open PWDUMP file window appears. Browse the D: and select the hashes.txt which has been created through Pwdump7, and click Open.
  • 13. Lab Task 03:- Task 03:- Crack the Password • The hashes are loaded in the Ophcrack under the NT Hash column. Now, click on the Table menu, the Table Selection window appear, select Vista free and click Install. Note:- to install the Tables you need to download the tables from the internet, you can download the table from http://Ophcrack.sourceforge.net/tables.php. • The Select the directory which contains the tables window appears, brown the location where the table has been downloaded or stored. Select the folder in which the tables are stored and click Select Folder.
  • 14. Lab Task 03:- Task 03:- Crack the Password This tables_vist_free is a pre- computed tables for reversing cryptographic hash functions and recovering a plaintext password up to a certain length. The selected table_vista_free is installed under the name Vista free, which is represented by a green colored bullet. Select the table and click OK.
  • 15. Lab Task 03:- Task 03:- Crack the Password • Click Crack on the menu bar. Ophcrack begin to crack the passwords. • The cracked password are displayed in the plaintext as in the below screenshot.
  • 16. Lab Analysis We have analyze the password hashes gathered during this lab, and figured out what the password was. Tool/Utility Information Collected/Objectives Achieved Pwdump7 Ophcrack IP Address Range/target:- Windows 8.1 machine Scan Result:- •Generate the user password Hashes •Crack the password in the plaintext
  • 17. Feedback Thanks for reading this presentation Please give us your feedback at info@prohackers.in Your feedback is most valuable for us for improving the presentation You can also suggest the topic on which you want the presentation Website: www.prohackers.in FB page: www.facebook.com/theprohackers2017 Join FB Group: www.facebook.com/groups/group.prohackers/ Watch us on: www.youtube.com//channel/UCcyYSi1sh1SmyMlGfB-Vq6A

Editor's Notes

  1. 1