Its pretty easy to get the hashes with pwdump or gsecdump.exe and run through ophcrack or John the Ripper.
Scripting a password change, can be done with the windows 2000 resource kit tool cusrmgr.exe... Z Edward Ziots Network Engineer Lifespan Organization MCSE,MCSA,MCP+I, ME, CCA, Security +, Network + [email protected] Phone:401-639-3505 ________________________________ From: James Rankin [mailto:[email protected]] Sent: Thursday, October 22, 2009 9:12 AM To: NT System Admin Issues Subject: Re: Hmmm....anyone have any thoughts on this? Cheers for that clarification. Time to script a password change! 2009/10/22 Ken Schaefer <[email protected]> Getting the domain admin NTLM hashes out of memory on the remote machine. You have to copy the tools across to the machine where the Domain Admin is logged into. That requires access to one of the Admin shares (usually workstations don't have any other shares), and it would also involve running the tool as a local admin of that remote workstation. If all the local admin passwords are the same, then the local admin password you got from lophtcrack on your machine would be the same as the remote workstation Cheers Ken From: James Rankin [mailto:[email protected]] Sent: Thursday, 22 October 2009 8:05 PM To: NT System Admin Issues Subject: Re: Hmmm....anyone have any thoughts on this? I was thinking along the lines of the randomization of local admin passwords....luckily we only have about fifty actual workstations, the rest are thin clients. I'm not familiar with the tools used in the attack (apart from psexec) - can anyone explain to me which part of it requires that all the local admin passwords be the same (apologies if I am missing something painfully obvious)? Cheers, 2009/10/22 Ken Schaefer <[email protected]> * Secure physical access * Don't allow people to boot alternate OSes * Do your workstations need to have $ shares enabled? Or available (e.g. block with firewall/router) *if* these are admin workstations * Randomize local Administrator passwords * Do not login locally to workstations with Domain Admin credentials. Login with normal credentials. Use other tools (e.g. RDP) with admin credentials to secured jump box or servers * Etc, etc Cheers Ken From: James Rankin [mailto:[email protected]] Sent: Thursday, 22 October 2009 7:56 PM To: NT System Admin Issues Subject: Hmmm....anyone have any thoughts on this? http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx Or mitigating against it, specifically....although I am not sure how effective an attack this is. I would think blocking USB access and maintaining application whitelists would be my personal first step -- "On two occasions...I have been asked, 'Pray, Mr Babbage, if you put into the machine wrong figures, will the right answers come out?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question." http://raythestray.blogspot.com ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
