Penetration Testing mailing list archives

Re: [PEN-TEST] PWDump3


From: "Thibodeaux, Mark" <Mark.Thibodeaux () ENRON COM>
Date: Wed, 24 Jan 2001 15:20:54 -0000

PWDUMP3 works, but it still needs refinement. It seems to be limited in
the number of users it can dump, probably because it is using the
registry to transfer the dumped passwords. During a test on a Windows
2000 Domain Controller with some 20,000 users it quit about halfway
through. It also did not successfully remove itself from the target
machine in this test. It worked fine on a Windows 2000 Professional
workstation.

                 -----Original Message-----
                From:   Penetration Testers
<PEN-TEST () SECURITYFOCUS COM>@ENRON
[mailto:IMCEANOTES-Penetration+20Testers+20+3CPEN-TEST+40SECURITYFOCUS+2
ECOM+3E+40ENRON () ENRON com]  On Behalf Of "Cintron, Jose"
<jcintron () IMSIDC COM>
                Sent:   Tuesday, January 23, 2001 5:36 PM
                To:     PEN-TEST () SECURITYFOCUS COM
                Subject:        Re: [PEN-TEST] PWDump3

                I downloaded it and tried it...  Now you can Dump the
Passwords from a
                remote machine (assuming you have enough privileges).
That's all I've seen
                so far, but trust me it does work.

                


Current thread: