Understanding Windows Hash Dumpers and Crackers

Windows Hash Dumper programs are both auditing and hacking tools. For auditing, they are used to detect poor passwords. As a hacking tool, they are also used for detecting poor passwords that can be broken and used for compromising systems or used directly to login to systems.

Windows hash dumping tools are often spotlighted as hacker tools that can somehow magically extract windows hashes and allow an intruder access to a system. In actuality, the hashes are there, in memory and on disk, where any admin or system level user can get at them. The tools just grab and print them out. This paper describes how Windows hashes are created, how the hash dumpers get at them, and what can be done with the hashes.


Good paper but...

This is a good whitepaper but not too clear, I think that it lacks of some vital informations and the examples are hard to follow. IMHO, it could be better.

Post new comment

  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h1> <quote> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.