Its pretty easy to get the hashes with pwdump or gsecdump.exe and run
through ophcrack or John the Ripper. 

 

Scripting a password change, can be done with the windows 2000 resource
kit tool cusrmgr.exe...

 

Z

 

Edward Ziots

Network Engineer

Lifespan Organization

MCSE,MCSA,MCP+I, ME, CCA, Security +, Network +

[email protected]

Phone:401-639-3505

________________________________

From: James Rankin [mailto:[email protected]] 
Sent: Thursday, October 22, 2009 9:12 AM
To: NT System Admin Issues
Subject: Re: Hmmm....anyone have any thoughts on this?

 

Cheers for that clarification. Time to script a password change!

2009/10/22 Ken Schaefer <[email protected]>

Getting the domain admin NTLM hashes out of memory on the remote
machine.

 

You have to copy the tools across to the machine where the Domain Admin
is logged into. That requires access to one of the Admin shares (usually
workstations don't have any other shares), and it would also involve
running the tool as a local admin of that remote workstation. If all the
local admin passwords are the same, then the local admin password you
got from lophtcrack on your machine would be the same as the remote
workstation

 

Cheers

Ken

 

From: James Rankin [mailto:[email protected]] 
Sent: Thursday, 22 October 2009 8:05 PM


To: NT System Admin Issues

Subject: Re: Hmmm....anyone have any thoughts on this?

 

I was thinking along the lines of the randomization of local admin
passwords....luckily we only have about fifty actual workstations, the
rest are thin clients. I'm not familiar with the tools used in the
attack (apart from psexec) - can anyone explain to me which part of it
requires that all the local admin passwords be the same (apologies if I
am missing something painfully obvious)?

Cheers,

2009/10/22 Ken Schaefer <[email protected]>

*         Secure physical access

*         Don't allow people to boot alternate OSes

*         Do your workstations need to have $ shares enabled? Or
available (e.g. block with firewall/router) *if* these are admin
workstations

*         Randomize local Administrator passwords

*         Do not login locally to workstations with Domain Admin
credentials. Login with normal credentials. Use other tools (e.g. RDP)
with admin credentials to secured jump box or servers

*         Etc, etc

 

Cheers

Ken

 

 

From: James Rankin [mailto:[email protected]] 
Sent: Thursday, 22 October 2009 7:56 PM
To: NT System Admin Issues
Subject: Hmmm....anyone have any thoughts on this?

 

http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx

Or mitigating against it, specifically....although I am not sure how
effective an attack this is. I would think blocking USB access and
maintaining application whitelists would be my personal first step

 

 

 

 




-- 
"On two occasions...I have been asked, 'Pray, Mr Babbage, if you put
into the machine wrong figures, will the right answers come out?' I am
not able rightly to apprehend the kind of confusion of ideas that could
provoke such a question."

http://raythestray.blogspot.com

 

 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to