DO NOT TRY THIS AT HOME : Rotteneggs.com text files and message bases are for INFORMATIONAL PURPOSES ONLY. DO NOT undertake any project based upon any information obtained from this or any other web site.We are not responsible for, nor do we assume any liability for, damages resulting from the use of any information on this site.
(38 votes) Published: Apr 14, 2006 10:09 a.m. In 1 Favorites Lists Viewed 127 times
Firstly, this is an easy way which dosent involve linux live booting, and you may have seen this on jinx by me (im BSX there)
well, hackers like me and more experienced pc users will understand, this is how you get the password from windows xp computers which are very well protected:
remember guys only do this if you have lost YOUR password, its probably illegal in schoolio or somewhere else.
start:
few things first:
google for pwdump2 (most reliable version) and extract it to c:\(or whatever your drive name is) so it become c:\pwdump2
youll need to be on an administrator username, so boot into safe mode and load up the administrator.
now load up a command prompt, start>run>cmd
type "cd c:\pwdump2" and press enter
now it should say summin like c:\pwdump2
now minimize that for a min.
press ctrl alt delete and click processes
click view and select columns, and check the pid(process identifier)
go back to processes and look for "lsass.exe" and write down the pid, in this case its 148
go back to your command prompt and type "pwdump2.exe 148 >hashes.txt" and press enter
now go to c:\pwdump2 (not through cmd, through explorer)
and there will be your hashes.txt open it and youll have your hashes and theyll be something like:
now go to www.plain-text.info and submit your hash without the administrator bit(so its like :500:E52CAC67419A9A224A3B108F3FA6CB6D:8846F7EAEE8FB117AD06BDD830B7586C::smile.gif
then soon (pretty quick usually your hash will be cracked and youll have your password, the final thing will look like this:
ID Submitter Algorithm Hash Value HexValue Status Benchmarks Submited
924 legion lm e52cac67419a9a22 PASSWOR 50415353574F52 cracked 0:5:25 2005/07/21 20:08:30
there yall go, easy way without booting from gnoppix or something biggrin.gif
btw the thing under hexvalue is the pw (its sometimes different) and in this case it could be passwor or password
oh ya, if your super dumb the sam files are the un-openable whilst running files which contain usernames and password hashes of a windows box