Penetration Testing mailing list archives

Re: Copying secret windows file


From: "Shreyas Zare" <shreyas () technitium com>
Date: Mon, 24 Dec 2007 14:49:14 +0530

Hi,

SAM file can be accessed only by SYSTEM user. The file is locked out
and cannot be copied when the system is running. So you would need to
get SYSTEM privilege for the program thats need to access it.

Regards,

On 12/21/07, Clone <c70n3 () yahoo co in> wrote:
Hello All

What is the most sensitive file you could remotely
copy from a Windows 2003 server in case you have a
remote access available to entire file system through
an exploit? I tried copying SAM file from windows
system root but that isn't happening. It says being
used by some other process. Is there any other way to
get this file? The SAM repair file is old and doesn't
have my domain password cached(well does that really
happens?).

Good day!


      Now you can chat without downloading messenger. Go to http://in.messenger.yahoo.com/webmessengerpromo.php


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------





-- 
("Computers are useless. They can only give you answers." - Pablo Picasso)

Shreyas Zare
Co-Founder, Technitium
eMail: shreyas () technitium com

..::< The Technitium Team >::..
Visit us at www.technitium.com
Contact us at theteam () technitium com

Technitium Personal Computers
We believe in quality.
Visit http://pc.technitium.com for details.

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: