Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

Re: Service Password

Subject: Re: Service Password
Date: Mon, 11 Jul 2005 14:19:56 -0300
John
Yes, there is. The passwords for the service accounts are managed bythe LSA. 
There is a tool called LSADUMP that can retrieve thosepasswords if you have 
admin rights on the box. Cain (oxid.it) can alsoget information protected by 
the LSA.
Personally that's why I use to say that a simple server compromisedcan lead the 
way for the whole net. Mantaining different accounts andpasswords for services 
that need to exist and run as admin in allservers is very hard. Best option to 
choose products that don'trequire this.
Regards,
Augusto Paes de Barros
On 7/11/05, John Madden <chiwawa999@yahoo.com> wrote:> Hi,> > I have a few 
concerns about windows service password.> Some services our client uses 
utilized Domain Admin> accounts.> > The servers are Windows 2003.> > Is it 
something similar to "Cache Credentials" ?> > Were are they located ?> > 
Thanks> > > > ____________________________________________________> Sell on 
Yahoo! Auctions – no fees. Bid on great items.> http://auctions.yahoo.com/> > 
---------------------------------------------------------------------------> 
---------------------------------------------------------------------------> > 

-- Augusto Paes de Barros, CISSP/ISSAPhttp://www.paesdebarros.com.br

<Prev in Thread] Current Thread [Next in Thread>