Options

how to crack windows 2003 server ?

itdaddyitdaddy Member Posts: 2,089 ■■■■□□□□□□
hey guys
I hate to ask this but I need to crack the admin password of a VM.
It is a windows 2003 stnd server. It is stand alone vm. It is not a domain
server else I could get into it. My boss as you know was terminated.
And I am not suppose to talk with him due to company policy.
Crap now what. Do you know of any solution to crack it.
I need to get into it to troubleshoot some services it has we use.

help!icon_redface.gif

Comments

  • Options
    dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
  • Options
    neuropolneuropol Member Posts: 34 ■■□□□□□□□□
    use l0phtcrack on the password hashes. May take a while(days).

    l0phtcrack
  • Options
    RobertKaucherRobertKaucher Member Posts: 4,299 ■■■■■■■■■■
    dynamik wrote: »
    That rocks!

    I have used Reset lost Windows passwords with Offline Registry Editor | Microsoft Windows | TechRepublic.com and it works flawlessly, if you follow the instructions.
  • Options
    dalesdales Member Posts: 225
    depends if you need to crack it or just change it, I find trinity rescue kit works pretty well with windows vm's. It will allow you to blank out the password straight away so there's no wait for a password crack.

    I'm sure that this is available in loads of different linux distro's but this one does the job so I'm sticking with it

    Trinity Rescue Kit | CPR for your computer
    Kind Regards
    Dale Scriven

    Twitter:dscriven
    Blog: vhorizon.co.uk
  • Options
    arwesarwes Member Posts: 633 ■■■□□□□□□□
    dynamik wrote: »

    Tempted to download this just for the sole reason that Kon is awesome.
    [size=-2]Started WGU - BS IT:NDM on 1/1/13, finished 12/31/14
    Working on: Waiting on the mailman to bring me a diploma
    What's left: Graduation![/size]
  • Options
    DevilsbaneDevilsbane Member Posts: 4,214 ■■■■■■■■□□
    neuropol wrote: »
    use l0phtcrack on the password hashes. May take a while(days).

    l0phtcrack

    I've used this several times on XP. I beleieve that 2k3 non DC's are the same as XP.

    Speak with someone higher up in your company. You could likely have someone from HR contact him and get the password. Unless he wants to hold out and end up in jail like that guy out in California.
    Decide what to be and go be it.
  • Options
    arwesarwes Member Posts: 633 ■■■□□□□□□□
    Devilsbane wrote: »
    I've used this several times on XP. I beleieve that 2k3 non DC's are the same as XP.

    You are correct. I used l0phtcrack on a SQL server that was set up for us and the guy forgot the local admin password.
    [size=-2]Started WGU - BS IT:NDM on 1/1/13, finished 12/31/14
    Working on: Waiting on the mailman to bring me a diploma
    What's left: Graduation![/size]
  • Options
    Bl8ckr0uterBl8ckr0uter Inactive Imported Users Posts: 5,031 ■■■■■■■■□□
    arwes wrote: »
    Tempted to download this just for the sole reason that Kon is awesome.

    Yes he is lol. He needs more screen time.
  • Options
    dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    There's no reason to try to crack hashes or brute-force authentication when you have physical access and control over the machine.
    arwes wrote: »
    Tempted to download this just for the sole reason that Kon is awesome.

    I've emailed the author and told him he gets bonus points for creating Bleach-themed tools icon_cool.gif
  • Options
    itdaddyitdaddy Member Posts: 2,089 ■■■■□□□□□□
    OMG!! i LOVE KON BOOT OMG!!!!!!!!!!!!!

    YOU GUYS ROCK! THANK YOU WOW YOU SAVED MY JOB!

    HAHA
    WOWOWOWOOW!
  • Options
    erpadminerpadmin Member Posts: 4,165 ■■■■■■■■■■
    I have never heard of kon-boot prior to this thread. I have used l0phtcrack, and the methods Robert described though as well as Winternals ERD Commander '07 (locksmith).

    Based on itdaddy's response, sounds like this tool should be on the next iteration of Security+.....lmao.
  • Options
    itdaddyitdaddy Member Posts: 2,089 ■■■■□□□□□□
    false alarm hitting F12 on boot is the key thing wow
    konboot got me right in the best tool i have ever seen next to

    BOOTPE and kon boot best tools out there

    man this is a life savior man!
  • Options
    DevilsbaneDevilsbane Member Posts: 4,214 ■■■■■■■■□□
    itdaddy wrote: »
    man this is a life savior man!

    In your hands, yes. Remember that an attacker will use the same tools, which is why restricting physical access is so important.

    Glad to hear that it worked out for you. I'm going to have to download this and play with it!
    Decide what to be and go be it.
  • Options
    itdaddyitdaddy Member Posts: 2,089 ■■■■□□□□□□
    devils bane
    you are right at our CU we have locks on all server rooms.

    but it saved my butt.
    1. I couldnt call the old fired boss
    2. our IT vendor didnt want to crack it
    3. i was like yikes this is a major server and services were down yikes

    but man great feeling bam! whhooooooohhhooo!
  • Options
    earweedearweed Member Posts: 5,192 ■■■■■■■■■□
    I just added Kon Boot to my toolkit. I've been trying to find something that did that.
    No longer work in IT. Play around with stuff sometimes still and fix stuff for friends and relatives.
  • Options
    Paul BozPaul Boz Member Posts: 2,620 ■■■■■■■■□□
    I can't tell you how many pentests I've used Konboot on. If the client says attacking physical machines is in-scope I'd just hit people's computers while they're at lunch.
    CCNP | CCIP | CCDP | CCNA, CCDA
    CCNA Security | GSEC |GCFW | GCIH | GCIA
    pbosworth@gmail.com
    http://twitter.com/paul_bosworth
    Blog: http://www.infosiege.net/
  • Options
    phoeneousphoeneous Member Posts: 2,333 ■■■■■■■□□□
  • Options
    DevilsbaneDevilsbane Member Posts: 4,214 ■■■■■■■■□□
    phoeneous wrote: »
    internet-high-five.jpg

    I so just left you hanging.
    Decide what to be and go be it.
  • Options
    AhriakinAhriakin Member Posts: 1,799 ■■■■■■■■□□
    devilsbane wrote: »
    i so just left you hanging.

    lmao :)
    We responded to the Year 2000 issue with "Y2K" solutions...isn't this the kind of thinking that got us into trouble in the first place?
  • Options
    miller811miller811 Member Posts: 897
    a vendor shared this site/disc with me, that has tons of utilities and is continously updated.

    Hiren's BootCD 11.0 and All Other Versions - HTTP Download
    I don't claim to be an expert, but I sure would like to become one someday.

    Quest for 11K pages read in 2011
    Page Count total to date - 1283
  • Options
    DevilsbaneDevilsbane Member Posts: 4,214 ■■■■■■■■□□
    miller811 wrote: »
    a vendor shared this site/disc with me, that has tons of utilities and is continously updated.

    Hiren's BootCD 11.0 and All Other Versions - HTTP Download

    I have version 9.8 of it and used to use it tons. Lots of tools packed into a single cd. I might have to upgrade.
    Decide what to be and go be it.
Sign In or Register to comment.