Skip to main content
Primer on Password SecurityNagareshwarTalekarwww.SecurityXploded.comtnagareshwar@gmail.com
Contents   Part I   - Operating System, Cryptography & Password Recovery
   Part II  - Password Cracking/Recovery Techniques
   Part III – Advanced Password Stealing Methods
   Part IV -  Why they are after you and Tips for Protection !2www.SecurityXploded.com
Part  I Operating System, Cryptography & Password Recovery3www.SecurityXploded.com
Windows Login Password SecretsWindows 98 used to store the user account passwords in .PWL files in Windows directory.
  Windows NT onwards stores the login password into registry hive files named 'SYSTEM' and 'SAM' at following locationC:\Windows\System32\Config4www.SecurityXploded.com
Windows Login Password Secrets  These password files are highly protected and not accessible while Windows is running even for the administrator.
SAM hive file refers to registry location HKEY_LOCAL_MACHINE\SAMSYSTEM hive file refers to registry location HKEY_LOCAL_MACHINE\SYSTEM  These registry locations (user accounts related content) are visible only from ‘System Account’
Login Passwords are encrypted using one way hash algorithm known as LM/NTLM
   Code Injection technique is used to dump these password hashes from System Process - LSASS.EXE5www.SecurityXploded.com
Windows Login Password Recovery - I   Live Password RecoveryDumping the LM/NTLM password hashes of users using pwdump/lc5/cain&abel toolsRecovering the password using Online/RainbowCrack/BruteForce method.Offline Password Recovery - Resetting the PasswordBoot via Backtrack, mount the system partition and use chntpw tool to reset password. Offline Password Recovery - Retrieving the original password Boot from BackTrack or any Live CDCopy SYSTEM & SAM files from \\Windows\System32\Config folderNow on another system, use Cain&Abel/LC5 tool to get LM/NTLM hashes from these filesFinally get the original password using Online/RainbowCrack/BruteForce method.6www.SecurityXploded.com
Windows Login Password Recovery - II   Screenshot - Dumping Local password hashes using Cain & Abel Tool7www.SecurityXploded.com
Windows Login Password Recovery - IIIBypass Windows Authentication using Kon-Boot
Login to any windows system without entering password using Kon-Boot
It dynamically modifies Windows kernel to bypass authentication
Remote System Password Recovery
Use pwdump tool to remotely dump the password hashes from live system
Then recover the password using Online/RainbowCrack/BruteForce Method
 You need to know admin password of remote system.8www.SecurityXploded.com
Linux Login Password Secrets & Recovery  Linux stores user login information in /etc/password & /etc/shadow files
  /etc/password contains only user login related info and encrypted password is actually stored in /etc/shadow file.
  Contents of /etc/password    smithj:x:561:561:Joe Smith:/home/smithj:/bin/bash  Contents of /etc/shadowsmithj:Ep6mckrOLChF.:10063:0:99999:7:::  Use "John the Ripper" to crack Linux passwords9www.SecurityXploded.com
Operating System & Cryptography   Each OS provides built-in cryptography store & library for Secure storage of Secret/Sensitive Data
   User Login credentials are used to keep it isolated and protected from other users.
   Makes it easy & transparent for any application to use it.
   Apps do not have to worry about security of sensitive data.
   Windows  -  DPAPI & Credential Store
   Linux
KDE => Kwallet
GNOME => Keyring
   MAC  -  KeyChain10www.SecurityXploded.com
Windows Cryptography InternalsDPAPI -  Data Protection Technology
Uses strong Triple-DES algorithm, SHA-1 algorithm and PBKDF2 password-based key derivation routine
Uses large secret sizes to greatly reduce the possibility of brute-force attacks to compromise the secrets
  Only Logged in user can decrypt his/her previously encrypted data
  It is possible to recover password from the disk if that user's login credential is known.
  Using DPAPI from Your Application [user specific]
CryptProtectData - Encrypt your Password
CryptUnprotectData - Decrypt your Password11www.SecurityXploded.com
Windows Cryptography Internals   Other useful DPAPI functions