Administrator passw...
 
Notifications
Clear all

Administrator password cracked but still can't get in....

7 Posts
6 Users
0 Reactions
582 Views
BornToWriteBlock
(@borntowriteblock)
Active Member
Joined: 17 years ago
Posts: 15
Topic starter  

Good morning all,

We have a client with a server running Server 2003 that an employee changed the Admin login password before he left. I have obtained the password with four seperate password cracking tools and the results are all the same. However the password does not let us log in. Has this happened to anyone? Thoughts?


   
Quote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Have you recovered a local machine password or domain password?


   
ReplyQuote
BornToWriteBlock
(@borntowriteblock)
Active Member
Joined: 17 years ago
Posts: 15
Topic starter  

Frankly, I'm not sure. We have been working with the SAM file from the config folder located in the windows-system 32 folder. Are we looking in the wrong place?


   
ReplyQuote
(@sjors)
Active Member
Joined: 17 years ago
Posts: 18
 

Think bithead is pointing in the right direction.

I guess the employee changed the domain admin and you most likely (almost sure) retrieved the local admin.

Haven't been busy with this subject lately, but recovering a domain password is alot harder as rainbow tables are useless and this will mean a bruteforce must do it. (not totally sure though)


   
ReplyQuote
(@infern0)
Trusted Member
Joined: 17 years ago
Posts: 54
 

You could use fgdump on the former admins system to retrieve the potentially cached PW and then crack it rather easily (if LM hash is enabled). Will be cached if the former admin ever logged in to test it (last 5 by default are cached).

Only 1 domain admin exists?


   
ReplyQuote
mstew
(@mstew)
Active Member
Joined: 18 years ago
Posts: 6
 

Sounds like you have cracked the local machine password, which is good, but you probably need to change the domain password which can be done by following these steps.

http//www.petri.co.il/reset_domain_admin_password_in_windows_server_2003_ad.htm


   
ReplyQuote
_nik_
(@_nik_)
Trusted Member
Joined: 19 years ago
Posts: 93
 

Also sometimes when you crack a password that is longer than 14 characters, the cracking tools just give you the first 14.


   
ReplyQuote
Share: