Understanding Windows Hash Dumpers and Crackers
Windows Hash Dumper programs are both auditing and hacking tools. For auditing, they are used to detect poor passwords. As a hacking tool, they are also used for detecting poor passwords that can be broken and used for compromising systems or used directly to login to systems.
Windows hash dumping tools are often spotlighted as hacker tools that can somehow magically extract windows hashes and allow an intruder access to a system. In actuality, the hashes are there, in memory and on disk, where any admin or system level user can get at them. The tools just grab and print them out. This paper describes how Windows hashes are created, how the hash dumpers get at them, and what can be done with the hashes.
467 views
Good paper but...
This is a good whitepaper but not too clear, I think that it lacks of some vital informations and the examples are hard to follow. IMHO, it could be better.
Post new comment