Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 15 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow fgdump v2.0.0 Released
Ethical Hacker Community Forums
September 06, 2008, 08:18:47 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: fgdump v2.0.0 Released  (Read 2569 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2242


Editor-In-Chief


View Profile WWW
« on: May 02, 2008, 04:35:53 PM »

Just in case you didn't know, fgdump is now the tool to use for dumping password hashes from Windows systems.

Quote
04/25/2008:

I love having time to update tools.

I got around to adding 64-bit support to pwdump (1.7.0) and cachedump (technically referring to it as 2.0), which means I needed to build a new version of fgdump. At the same time, I rolled out a few new features which I've either been sitting on, or have been talking about for awhile. And of course, as is typical with new releases, most AV is blind at least for a bit. Smiley Here's a list of things that have changed:


- fgdump will now detect 64-bit targets and report them as such
- 64-bit pwdump and cachedump will be used when the target is detected as 64-bit
- Fixed a problem when connecting to some Samba servers where RegQueryValueEx would not behave as expected
- fgdump will now generate a session ID during each run - used to correlate failed logs and regular logs
- Added command line to log file
- Added session ID to log file
- Created a new file with the format (session-id).failed which contains greppable data on failed hosts
- A log file is always generated of the format (session-id).fgdump-log
- -l will now override the default log name (see above)
- Added -a option to prevent tampering with AV. This is useful if you know AV is not picking it up, you want to tamper with the target as little as possible

A couple of notes about the log files. First off, a log file will ALWAYS be generated now, and will contain the date and time of the run. You can override this using -l if you want it to be named something specific. fgdump will now also generate a .failed file, which will contain a list of hosts that were unsuccessful. This file contains greppable records so you can quickly identify what hosts failed, why, and if there are still processes running on the host. This should help during the cleanup phase. The fields in this file are as follows (all separated by "|" characters):

1. Host IP/name
2. Windows error number (e.g. 5 for access denied)
3. 1 if processes are still (possibly) running on the target, 0 if everything should be cleaned up
4. Text of the error, if available

Additionally, the command line used to invoke fgdump is stored in the log file now. This means, if you pass the password on the command line, IT WILL BE RECORDED IN THE LOG FILE! If this bothers you, please omit the -p parameter and simply provide the password when fgdump asks for it. Please also note that this version has quite a number of changes in it and, while I'm releasing it as non-beta, there is a higher-than-normal chance for bugginess. As usual, please report any issues you find.

Get  it here:
http://swamp.foofus.net/fizzgig/fgdump/downloads.htm

Don
Logged

CISSP, MCSE, CEH, Security+ SME
RoleReversal
Sr. Member
****
Offline Offline

Posts: 399


View Profile WWW
« Reply #1 on: May 03, 2008, 04:04:39 AM »

Cheers Don,

I'm about to do some work in the windows domain so I'll add the updated version to my toolbox.
Logged

A little bit of sanity:
http://www.infosanity.co.uk
rdkumarj
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #2 on: June 18, 2008, 10:45:07 PM »


Hi

   Thanks for this tool , Such a Nice One...
Logged
BanDx
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #3 on: June 26, 2008, 12:42:56 PM »

If I run fgdump from my PC to dump from a remote server that is a domain controller is anything installed on the remote server? Is there any risk to the domain controller?

Here is a sample of the command I want to run:
fgdump.exe –h 192.168.0.10 –k -u administrator –p password

Thanks in advance.
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 982


View Profile WWW
« Reply #4 on: June 26, 2008, 12:57:21 PM »

i dont remember is fgdump installs itself as a service or just does dll injection to dump the hashes, it should be in the documentation though.

keep in mind, anytime you start playing with those types of tools there is the "possibility" of messing something up, usually not permanently though.  a reboot usually fixes it, but that might suck for a DC.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.054 seconds with 23 queries.
 
Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.