OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: SAM encrypted with syskey

From: Vladimir Katalov (vkatalovelcomsoft.com)
Date: Thu Feb 17 2005 - 02:36:00 CST


In-Reply-To: <F36BC027FD4D7E4FB9EA59EFAF86BAAD11AEE4mex0010mf01.na.xerox.net>

>Does any one knows a method to retrieve the password for the SAM
>(NT/W2K) that has been encripted with syskey? Or bypass the system
>startup password?

Proactive Windows Security Explorer allows that:

http://www.elcomsoft.com/pwsex.html

It is able to dump password hashes from SAM and SYSTEM files (created in any system from Windows NT4 to Windows Server 2003).

Next version will be also able to get password hashes directly from Active Directory database (ntds.dit).

--
Sincerely yours,
  Vladimir

Vladimir Katalov
Managing Director
ElcomSoft Co.Ltd.
Member of Association of Shareware Professionals (ASP)
Member of Russian Cryptology Association
mailto:vkatalovelcomsoft.com
http://www.elcomsoft.com (Corporate site)
http://www.crackpassword.com (Password Recovery Software)