pen-test
[Top] [All Lists]

RE: Retrieving Cached Domain Credentials from Vista

To: "'Ben Nell'" <enemy.cow@gmail.com>, "'pen-test'" <pen-test@securityfocus.com>
Subject: RE: Retrieving Cached Domain Credentials from Vista
From: "Paul Melson" <pmelson@gmail.com>
Date: Mon, 16 Apr 2007 10:29:01 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:from:to:references:subject:date:message-id:mime-version:content-type:content-transfer-encoding:x-mailer:in-reply-to:x-mimeole:thread-index; b=nm7da6dtOaI3cmiEWQBSvxqEWre+1e21A5iL2d/Q0vj/TPSoZizWIso7q//wJD6YwjZsNMiQOFOXy0FN5JhApn5LdIAq1Fq1fH4ezkIpeHDWNY2o32fNviZXYoN0zUEwXWN/j8DdfF8tLQYfnH0OgSpU0OUYHTnkn0oT/OSf+5g=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:from:to:references:subject:date:message-id:mime-version:content-type:content-transfer-encoding:x-mailer:in-reply-to:x-mimeole:thread-index; b=Fz9ME0f1eKUIrW6C80bIpeqX8sEa66Gne4AIE81/yGG6MQMBUcn6wVX9GoJsPE/YlRGj0VsTzitPIgmID+kl1EWopM1Ep5L6tFa76S/6+3cqSj4EZ1m1Ez1VQoDmvRomsWJEz1e5A9A4PtYEUN4yjcoc6KFXi0wQwWW4uKqBFgE=
In-reply-to: <9cf39d60704140630h5d388b01y2e248345bd035c9d@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <9cf39d60704140630h5d388b01y2e248345bd035c9d@mail.gmail.com>
Resent-date: Mon, 16 Apr 2007 17:41:03 -0600 (MDT)
Resent-from: pen-test-return-1078483978@securityfocus.com
Resent-message-id: <20070416234103.99E3D15FCA7@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thread-index: Acd+03Wg2Q1J+PitQ+iVh1JpLA0vcABX30Hw
> Has anyone been able to successfully retrieve cached domain credentials
off of a Windows Vista machine?  
> Cachedump crashes on me and I was hoping there was a more effective tool
for Vista.

I know that recent versions of Cain & Abel can dump SAM & LSA from Vista.  I
haven't tried MSCACHE hashes on Vista, but it's worth a try for sure.

PaulM


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>