Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: forgotten admin password |
|---|---|
| Date: | Fri, 20 Apr 2007 09:16:18 -0500 |
cesar montano wrote:
mates, need your inputs badly. we have w2k3 server with a newly installed application ... unfortunately, the system staff who's in-charge for that server has forgotten the admin password he inputted in the last few weeks. any idea on how to recover it or other way to login on that server?
You could run something like Locksmith (does that run on W2K3? It's been awhile since I used it). That's the easiest, but not as much fun as the other solutions. :) Otherwise, what other sorts of services are running on it? Has it been recently patched? If it's behind in patching, exploit it using your favorite vuln o'the day (like the recent DNS vulnerability perhaps) in Metasploit, Canvas, etc. If you've got old BackupExec on it, that too is sometimes vulnerable. Many of these exploits allow you to run as System, which means you can dump the passwords and crack them. Besides, it's kind of fun and liberating breaking into your own boxes. If SQL Server is installed on the box, it's quite possible someone left an easy sa password on it, which also might mean you can execute tasks as system via xp_cmdshell. Just like vuln exploiting, dump the passwords and crack them appropriately. Admittedly, these paths are overkill, but as I said, they are more fun than simply rebooting with Locksmith or something. :) After all, this is pen-test. --f ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: forgotten admin password, Ricardo Landrau |
|---|---|
| Next by Date: | Re: forgotten admin password, Francois Yang |
| Previous by Thread: | RE: forgotten admin password, Ricardo Landrau |
| Next by Thread: | Re: forgotten admin password, Francois Yang |
| Indexes: | [Date] [Thread] [Top] [All Lists] |