|
Message-ID: <1359339056.25720.YahooMailNeo@web125901.mail.ne1.yahoo.com> Date: Sun, 27 Jan 2013 18:10:56 -0800 (PST) From: Chris McGinley <cemcginley@...oo.com> To: "john-users@...ts.openwall.com" <john-users@...ts.openwall.com> Subject: Re: Hash from a Windows 7 What version of PWDump7 are you using? I attended a presentation at DEF CON 20 that described something similar to what you are experiencing. Here are the slides from that presentation -> https://media.defcon.org/dc-20/presentations/Reynolds/DEFCON-20-Reynolds-Stamp-Out-Hash-Extraction.pdf The issue was supposed to be fixed in PWDump7 v7.1 according to their research. Find the 'Stamp Out Hash Corruption! Crack All Things!' preso on this page for more details - https://www.defcon.org/html/links/dc-archives/dc-20-archive.html >________________________________ > From: Rich Rumble <richrumble@...il.com> >To: john-users@...ts.openwall.com >Sent: Sunday, January 27, 2013 7:13 PM >Subject: Re: [john-users] Hash from a Windows 7 > >On Sun, Jan 27, 2013 at 1:16 PM, <madfran@...-ezine.org> wrote: >> Yes. I know,... but this is the data that I obtain from pwdump7. >> >> As I said in other mail, I am trying to report the issue to Tarasco. >It may not be removing the SYSKEY encryption like it should. I'd try >Cain&Abel from oxid.it. Also if your AV is picking up on gesecdump and >not pwd7 then maybe it won't pick up on cain, but most AV's do. >Security tools are often dual purpose, if you make an exception for >Cain or another tool, it's not the end of the world, just make sure >you remove the exception. You don't have to turn AV completely off, >most allow you to make exceptions. If you have a machine you can >install cain on, and remove your HD, you can then point cain to the >system and sam file's so it can get the boot key and decrypt the sam's >syskey and then dump the hashes. >-rich > > >
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.