Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 54 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow HELP!!! NT Hash needs decoding
EH-Net
May 23, 2013, 12:17:18 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: HELP!!! NT Hash needs decoding  (Read 19031 times)
0 Members and 1 Guest are viewing this topic.
23ant23503
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: August 31, 2009, 11:35:59 AM »

Hello,

    I am really new to this site but I thought that it was a very good place to start to solve the dilemna that I have.  I have a laptop running on windows vista platform and it was lent out a little while back to one of my cousins.  At the time, there was no password stored to log into the cp.  Now that I have gotten my cp back, it is now asking for a password and noone seems to know the password.  I am not sure if someone came over and was fooing around with it and stored a password on purpose or accident but I do know that I can no longer log into the cp at all.  I do not want to use the disk that came with the software because this would cause me to lose alot of information that I have stored on the cp so I am really looking to alternatives for this problem.  I have gotten the NT hash for the password but have not been able to decode it.  If there is any way that someone can help me to decode this hash, it would be extremely appreciated.  Thanks in advance to anyone that can help me out.

NT hash:

5230099e9b837e353c5bc814ae94d394

Thanks again,
Anthony
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4167


Editor-In-Chief


View Profile WWW
« Reply #1 on: August 31, 2009, 11:50:51 AM »

If it's just getting back onto the machine, cracking the hash is not necessary. I will give you a few ideas to get you going in the right direction.

- First of all, use some kind of bootable Linux CD to change the password.
http://home.eunet.no/pnordahl/ntpasswd/

- Next... watch this video. It's simplistic, but it may help:
http://www.howcast.com/videos/226372-How-To-Retrieve-a-Lost-Windows-Password

- Then if you really want to get the actual password, then try rainbow tables on the hash value using something like Ophcrack.

Hope this helps,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
23ant23503
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #2 on: August 31, 2009, 12:33:35 PM »

Thanks for the information you gave.  I was considering the boot disk option at one point but I found out that If I had encrypted informatin on the cp, it will or may be lost.  I was more so hoping that you or someone on your team could help and just crack the NT hash that I provided.  I did burn the Ophcrack program but when it ran, it told me that the password was not found and I do not have the monies to get the rainbow tables or too familiar with how to work them.  If it is at all possible, can someone just crack the hash and provide me with the password??
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4167


Editor-In-Chief


View Profile WWW
« Reply #3 on: August 31, 2009, 12:57:50 PM »

I'm sorry, but we don't do that here.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #4 on: September 01, 2009, 12:49:40 AM »

Don already supplied you with a few possibilites you have. In terms of rainbow tables, which is again not absolute necessary in this scenario, there are also free ones available. If you are not satisfied with the free ones, there is also the possibility to generate them by yourself.

Maybe asking your cousin could solve the problem too..
Logged
joshconsulting
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #5 on: September 01, 2009, 08:23:20 PM »

The password is "tempest7".  Your welcome   Wink

EDIT: Is it against the rules to crack hashes for people?  Moderators can remove my post if so, just trying to be helpful.
« Last Edit: September 01, 2009, 08:25:23 PM by joshconsulting » Logged
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #6 on: September 07, 2009, 12:48:35 AM »

If you weren't able to access the box with enough permissions to change the password how were you able to dump the hash?
Logged

twitter.com/timmedin | http://blog.securitywhole.com
shachola
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #7 on: October 03, 2009, 04:16:58 AM »

Thanks for you effort
Can u Please Decode this NT hash for me?
I forget the vista password that's y i need it urgently.
Regards
Shanavas

- <Password>
  <Username>admin</Username>
  <Uid>1001</Uid>
  <Sid>Unknown</Sid>
  <LMHash />
  <NTHash>2094797B3DE5DDE90CC905FF81CFBC43</NTHash>
  </Password>
  <info>mounted /sys/block/sda/sda3</info>
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #8 on: October 03, 2009, 06:51:26 AM »

Thanks for you effort
Can u Please Decode this NT hash for me?
I'm sorry, but we don't do that here.

Don

If you need access to the system urgently take a look for any of several good and easy to use/find tools to reset the pass. For legit usage you don't need the password, just access right?
Logged

chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #9 on: October 04, 2009, 04:42:11 PM »

shachola, why do you need admin access to your office laptop?

If you're job will not allow you to change your admin password, that tells me your employer(s) decided that you do not need admin access to do your job.

I would suggest talking to your manager, or calling the help desk for help.
Logged

OSWP, Sec+
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #10 on: October 04, 2009, 04:58:48 PM »

This is an excellent way to get fired for something silly.   My advice would be to leave it alone, it's not worth losing your job over.
Logged

~~~~~~~~~~~~~~
Ketchup
plan2000
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #11 on: October 05, 2009, 07:27:58 AM »

i guess some other way to be a hero like saving rainforests etc. is more ethical Smiley
if you still need that kind of fame i'll suggest using several widely available online ntlm password "decrypting" sites
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #12 on: October 05, 2009, 08:07:16 AM »

I thought it is vey simple to get it. If you could not help me to get it.. leave this.
But if I got it I will be a hero in our office circle which I will enjoy in my life.
Thanx for your reply.

You still haven't said exactly why you want the password. I'm going on the assumption that you're not in the IT department. Which means you're trying to by pass your company's security policy. If you really want to impress your co-workers and be a real hero, make a business case as to why you need the software you think you do.

Those are not your personal computers, they don't belong to you.

(I've had to deal with problems like this at work recently, so I'm a little bitter).
Logged

OSWP, Sec+
jimbob
Guest
« Reply #13 on: October 05, 2009, 10:41:00 AM »

This thread is an example of why we should not service these requests in the forum. It didn't take long for a "Me too!" request to appear in the thread, did it?

Jimbob
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.077 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.