Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 23 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Cracking Active Directory Passwords
EH-Net
May 25, 2013, 01:02:05 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Cracking Active Directory Passwords  (Read 18694 times)
0 Members and 1 Guest are viewing this topic.
tekt
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: April 13, 2009, 07:31:41 AM »

I am trying to figure out how to crack a users cached active directory password. I need to load a forensic image in a VM and log in as the user to show exactly what he see's.

A Windows tool is preferred because I am not that familiar with Linux. I have tried Cain and Able with not much luck in trying to figure it out. I think the same person wrote that user guide that wrote the manual for EnCase.

Does anyone know where to get a set of rainbow tables with the .rt extension?

Thanks!

-=T=-
Logged
LSOChris
Guest
« Reply #1 on: April 13, 2009, 08:29:57 AM »

i dont know of any rainbow tables for cached passwords.  you'll have to use either Cain or John the Ripper
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #2 on: April 13, 2009, 09:17:20 AM »

Have you already extracted the cached LM hashes?   I would love to know how you can do that from a forensic image.   I am aware of techniques of extracting hashes from RAM, and possibly SWAP file, such as this:

http://www.governmentsecurity.org/SecurityHackingNews/Dumping_Memory_to_Extract_Password_Hashes

Cain is very easy to use.   Your best bet is not Rainbow tables however.  I would dump every usable word and phrase in either EnCase or FTK and use that as your word list.   The password has to be cached somewhere.   In Cain, just hit the little Plus icon from the Cracker tab to import your hashes Then right-click to set option and crack away.  You will want to use a Dictionary attack in this case with your custom wordlist.

I think that an alternate option could be using WinLockPwn.  It allows you to bypass authentication using a firewire DMA attack.  This doesn't work well on Vista, but does work on XP sp2 and sp3, the later with a modification of the script.

Logged

~~~~~~~~~~~~~~
Ketchup
CadillacGolfer
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #3 on: April 13, 2009, 03:44:18 PM »

Use fgdump which should export the cached credentials (note, you do need to run fgdump against the machine with admin privs), then use John The Ripper or your favorite password cracker.
Logged
tekt
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #4 on: April 15, 2009, 07:46:08 AM »

I used network password recovery wizard to extract the hashes from the system and security registry files. I exported the files from a forensic image using FTK Imager.

I have the hash values... I just need to crack them... I continue to play with Cain and Able but I don't have 37 years to wait for them to crack. :-)
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #5 on: April 15, 2009, 09:27:39 AM »

You really need that wordlist.   Your AD password should be in the SWAP file or somewhere in drive free space.
Logged

~~~~~~~~~~~~~~
Ketchup
kennut
Newbie
*
Offline Offline

Posts: 46


CISA, C|EH, CISM


View Profile
« Reply #6 on: April 19, 2009, 10:00:52 AM »

Ok, here's the trick, I've been cracking AD password for donno how many companies I've worked for here's the rule of thumb:

1) You need administrator priviledges, make sure you got that in hand.

2) use fgdump.exe on the local system (it will save it to a text.file), ensure that any anti-virus is disabled first (trend micro will zapped it before you'll able to copy it to c: drive of the server).

3) if the AD password hashes contains a list of users with their histories enabled, you need to use Excel to remove all those users with their histories before you start to crack (so use Find->Replace-> *.history* to remove the redundant histories password hashes.

4) search for torrent for the Rainbow crack files, the one I have for alphanumeric (which is good enough), however the full table is around 34gb which is huge! -> http://rainbowtables.shmoo.com/

5) load up either John the Ripper , or google for the now defunct symantec lophtcrack 5.0, I think the *.exe file is still around somewhere. (however, do note that John the ripper cannot differenciate between upper and lowercase).

6) crack the file with the rainbow tables which should take you less than 15-30mins depends how many AD users are there in the AD.

Hope that helps.

kennut Smiley
« Last Edit: April 19, 2009, 10:02:38 AM by kennut » Logged

Done all 3 certs, now going for CISSP.....
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.