LCP

For beginners, flames not allowed...(just by the staff :P)
Post Reply
User avatar
Nerdz
The Architect
The Architect
Posts: 1127
Joined: 15 Jun 2005, 16:00
18
Location: #db_error in: select usr.location from sucko_member where usr.id=63;
Contact:

LCP

Post by Nerdz »

Hi guys, I want to use this program bcz I have read somewhere on this forum that we can get back password. So I'm trying it on my box and I read all the help file on the theory about pass files.

If I get the point, I can't get my password on my box bcz I don't have a second OS or a botting floppy of linux. Which is required to copy the sam file and then importing it in the LCP program.

After I tried with the examples that come with LCP and it was very nice... So I got pwdump2 and it says it need lsaas.exe. I ran a Search and can't find it.

So is there any way to get pwd on my box( I'm the only user with admin right)



SRY I played around and problem solve...

However, I can't understant this part... well I can't do it bcz it always say that I can't change the name for cmd.exe bcz it already exist.

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

In case you do not have administrative privileges at the local computer, it is possible to use a vulnerability of Windows NT/2000/XP/2003 operating systems, which in fact allows to change a screen saver, launched in case of logon absence for the particular amount of time (it is 15 minutes for Windows NT/2000 and 10 minutes for Windows XP/2003 by default) to a different program. To perform this, you need to change %SystemRoot%\system32\logon.scr to desired executive file (cmd.exe for example), which will be launched by the operating system instead of screen saver with system privileges. This change can be done by method used to copy a SAM file. You can get an access with write capability to a NTFS disk by NTFSDOS Professional or NTFS for Windows 98 programs. After this you need obtain hashes by pwdump2 or pwdump3/pwdump3e methods.

masterdriverz
forum buddy
forum buddy
Posts: 16
Joined: 23 Sep 2005, 16:00
18

Post by masterdriverz »

Its fairly straightforward. Rename a program to logon.scr to run it with System privileges (needed to rape SAM file)

User avatar
Nerdz
The Architect
The Architect
Posts: 1127
Joined: 15 Jun 2005, 16:00
18
Location: #db_error in: select usr.location from sucko_member where usr.id=63;
Contact:

Post by Nerdz »

what you mean?
Give a man a fish, you feed him for one day.
Learn a man to fish, you feed him for life.

masterdriverz
forum buddy
forum buddy
Posts: 16
Joined: 23 Sep 2005, 16:00
18

Post by masterdriverz »

Find a program; eg, cmd.exe, copy it to system32 (in this example its already there, but you still need a copy) and rename it to logon.scr. When Windows tries to start the default screensaver, cmd.exe (or wotever program you put there) will be run with system privileges.

Post Reply