Windows NT 4.0 password cracker

darkamulets

Senior member
Feb 21, 2002
784
0
76
i recently got a job, they run a older NT 4.0 server but the original tech moved out with all the paperwork so no one knows the administrator password, any password crackers that anyone can suggest? or tricks to extracting the password from the system, i have physical access to the system, but i cant login as a administrator most i can do is login as a normal user. plz help ASAP
 

gaidin123

Senior member
May 5, 2000
962
1
0
I believe l0pht has an old NT password cracker..Look up info on:
Lophtcrack, ntcrack, and pwdump

Gaidin
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
There is also a linux bootfloppy that will allow you to change the password on NT 4 systems. Do a search on NT 4 in OS forum and a link to it should be there.
 

Goosemaster

Lifer
Apr 10, 2001
48,775
3
81
Then, according to that, it must be harder than making K. Ley tell the truth to secure an NT 4 box:Q
 

SaigonK

Diamond Member
Aug 13, 2001
7,482
3
0
www.robertrivas.com
If you have access to NTFSDOS Pro you can load it up from a floppy then go find the SAM file ..(.look under c:\winnt\system32\drivers\etc...) think thats it....
Delete the SAM file and all will go back to normal..be wary though..it resets EVERYTING...so all other user profiles on the box will go bye bye
 

Daniel

Diamond Member
Oct 10, 1999
3,813
0
76
If you are gonna bother getting the sam file why not just copy it and run Lophtcrack so you don't ruin everything? That or as was suggested use that linux boot disk I hear it works well.
 

BooneRebel

Platinum Member
Mar 22, 2001
2,229
0
0


<< hope this works, if it does i make money if it don't ugh, well thx anyhow people >>



Are you going to share?
 

Abzstrak

Platinum Member
Mar 11, 2000
2,450
0
0
theres an easier way on NT4, just make an ERD off an NT box that U know the passwords too, then boot off the nt cd on the box with unknown passwords and do a repair but only replace security information, when prompted for an ERD use the one from the other machine. Then boot into windows, it'll have the passwords of the box you made the erd from.

When U do this the boxes should have the same service pack level.... all in all it takes about 5 - 10 minutes and is REALLY easy