Win2k + Syskey = Encrypted SAM

Nullity

Senior member
Oct 13, 1999
837
0
0
Hey. I didn't know where else to post this question since it didn't seem to fit into any other forum.

Anyways, I have a Win2k machine and I want to test how strong the passwords are. I know I can use certain programs to directly get the hashes from the registry but you have to have admin access to use those. I use that program and it works very well. The problem is the computer is going to be in a public place where anyone can turn it on and off and use it. I know there are ways to get the SAM by using boot disk with NTFS support. My question is: If someone were to access the SAM file via boot disk, will they be able to extract the hashes from it (assuming Syskey is enabled)? Or will syskey prevent them from obtaining the hashes?

Thank you,
Null

This is the place to discuss the latest computer hardware issues and technology. Please keep the discussion ON TOPIC, and covering computer hardware ONLY.

AnandTech Moderator
 

Jhereg

Senior member
Jan 23, 2000
260
0
0
Why not just disable the floppy drive in the BIOS and password the BIOS itself ?
Create numerious accounts, rename the admin account and disbale its rights , give rights to one of the other accounts.
 

Nullity

Senior member
Oct 13, 1999
837
0
0
Well, thats the thing. The users will probably need to use the floppy. I have already set a BIOS password...but if you look hard enough, there are ways to get past it.

Null
 

bocamojo

Senior member
Aug 24, 2001
818
0
0
Turning on syskey on your win2k box won't stop "hackers" who have access to your local machine from getting to your sam, and changing the admin password. They can turn off syskey, then change the admin password (with certain programs), although I hear this "feature" is a bit buggy, and unstable (but what do hackers care, as they will either get your admin account or crash your system). You should put up a camera in the room (active or not, it should have the same effect). That should be enough of a deterrent to most... and you really should consider locking down floppy, if this is really a concern...
 

robg1701

Senior member
Feb 12, 2000
560
0
0
Just for laughs: if they need a floppy, disable the machines floppy and only let them have access to a floppy on a networked 486 box running Win95 and without any input/output devices, hehe
 

Nullity

Senior member
Oct 13, 1999
837
0
0
Hrm. I've thought about having a workstation dedicated for floppy and printer..The only bad thing about that is there are about 5 workstations which would connect to it. Also, 2 of the workstations are in different rooms.

I know of those programs you talk about. They do work..I've tested it without any problems.

I guess there isn't much I can do except hope no one will mess around with them. Maybe I can buy 3 or 4 fake cameras...but then again, wouldn't that make them feel like its invasion of privacy?

Heh, anyone else have any ideas?

Thanks,
Null
 

MedicBob

Diamond Member
Nov 29, 2001
4,151
1
0
Nullity,

It looks like you are looking for absolute security for your box. Hate to tell you, ain't going to happen. Best bet with direct access users is a background check, refrences, and prayer. Other than that there is always a way around any security mesures you place on a box.

Direct access allows any and all kinds of "issues" with a computer.

Don't give up, but don't be unrealistic either. Remove the floppy, physically that is. Remove the CD also. No access to load programs without a PW or user access then. Of course restrict all users to Guest with very limited useability and access. Then you have a pretty good secure system.

If you think it is unhackable, it isn't.
 

Nullity

Senior member
Oct 13, 1999
837
0
0
Agreed.

What are some nice programs which help lock out a Windows 2k box? Such as restricted Start Menu, no control panel, etc. Preferrably free. =D

Thanks for all the help!
Null
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |