Close

http://www.passcape.com

Password Recovery Software

The best programs to recover lost and forgotten passwords
Control panel
Home > Products > Windows Passwords > Windows Password Recovery > Screenshots > Loading hashes
Loading pasword hashes into the program
04.05.2012
Windows Password Recovery v5.1
Now with GPU support
09.04.2012
New blog post
Using passwords from the Bible
13.03.2012
DPAPI secrets
New article has been submitted
20.02.2012
Auditing 32 mln. RockYou passwords
Brief analysis of 32 mln. passwords

Articles and video

You may find it helpful to read our articles on Windows security and password recovery examples. Video section contains a number of movies about our programs in action

Windows Password Recovery - loading password hashes

 
User passwords in Windows systems are converted to special values - hashes. Hashes have a fixed size - 16 bytes - and can be stored in two repositories: SAM - for the regular accounts and Active Directory - for domain accounts.

The regular accounts that contain user name, password and other auxiliary information are stored in the Windows NT registry; precisely, in the SAM (Security Account Manager) file. That file is located on the hard disk, in the folder %windows%\system32\config. For example, С:\Windows\System32\Config\SAM.

Another way to access the SAM file is to launch a special program from a boot disk and then copy the file. Anyway you need a physical access to the computer with password hashes.
User passwords or, to be accurate, hashes are additionally encrypted with the SYSKEY utility, which stores its service data in the SYSTEM registry file. Thus, to extract hashes from SAM, you would also need the SYSTEM file, which is located in the same folder as SAM, and optional SECURITY file.

 Domain accounts are stored in the Active Directory database. Usually, the Active Directory database is located in the file %Windows%\ntds\NTDS.DIT. The way user hashes are encrypted here is a bit different than that is in SAM, but the recovery would also require the SYSTEM file.

Windows Password Recovery support several ways of loading hashes into the program.

 


Import local hashes

Load hashes of the local computer.
More information...
read hashes of the local PC


Import hashes from system restore folders

Extract password hashes from system restore/repair/backup folders or from volume shadow copies.
More information...
Import hashes from system restore folders


Import hashes from project/text files

Load hashes into the program by importing them from other projects/applications.
More information...
Load hashes from other projects




Print   E-mail