Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Password hash domain controller 2003
EH-Net
May 20, 2013, 12:55:42 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Password hash domain controller 2003  (Read 7439 times)
0 Members and 1 Guest are viewing this topic.
impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« on: February 10, 2011, 02:29:53 PM »

Guys:

How can you get the hashes from a Windows 2003 domain controller server? I am in front of the the domain controller, so there is not need run any exploit. I do not have the administrator password.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
knwminus
Full Member
***
Offline Offline

Posts: 100



View Profile WWW
« Reply #1 on: February 10, 2011, 07:53:13 PM »

How do you plan to log into the server locally? Couldn't you just change the password?
Logged

A+ N+ CCNA CCNA:S CNSS 4011 Security+

Next Up: CCNP CCNP:S
impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #2 on: February 10, 2011, 10:12:18 PM »

The password had change and nobody is responsible, so I did this:

1. I used a password reset cd and reset the administrator in the SAM (remember is a domain controller and use AD).
2. I restarted the server and press F8 and choose Directory Services Restore Mode (domain controller only).
3. Follow the instructions in this site: http://www.petri.co.il/reset_domain_admin_password_in_windows_server_2003_ad.htm

I tried first in a virtual machine and worked so I did live. In the beginning I tried to obtain the hash to crack the password, but I could not do it. I took me 5 hours but it worked.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #3 on: February 14, 2011, 01:31:11 AM »

any reason a PW cracker wouldnt have worked? Clear the PW?
Logged

impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #4 on: February 14, 2011, 08:23:38 AM »

I do not know what is PW cracket is?
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #5 on: February 14, 2011, 05:24:14 PM »

This is one program, http://www.petri.co.il/forgot_administrator_password.htm#1 I think we have used the vista version at work.
Logged

impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #6 on: February 14, 2011, 08:47:35 PM »

I used one similar to reset the local account, but remember I needed to reset active directory administrator password and this kind of tools does not do it
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.061 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.