 |
 |
Home > Step 2: Tools you should use |
 |
 |
 |
Step 2: Tools you should use |
 |
| 13 Dec 2005 | SearchWindowsSecurity.com |
 |


|
In the past, testing for Windows-based password weaknesses was somewhat difficult if not downright painful. However, new tools and cracking techniques have emerged in both freeware and commercial applications recently that help streamline the process and actually make it kind of fun.
In order to effectively accomplish the tasks outlined in the methodology above, it takes various tools. The following tools should at least be on your radar if not in your security toolbox:
- Brutus for e-mail, telnet, etc. passwords (an absolute must)
- Cain & Abel for LM- and NTLM-hashed Windows passwords, Wireless Zero Configuration passwords, PWL files, RDP files, SQL hashes, and more
- Effective File Search for searching passwords in network files (i.e. searching for "password" in .txt, .doc, .xls, etc. files)
- John the Ripper for LM-hashed Windows passwords
- Microsoft Baseline Security Analyzer (MBSA) for missing and weak passwords
- NetBIOS Auditing Tool for Windows share passwords
- Proactive Password Auditor for LM- and NTLM-hashed Windows passwords and rainbow tables support
- Proactive System Password Recovery for RAS, PWL files, service accounts, and more
- pwdump3e for dumping Windows password hashes
- pwdump4 for dumping Windows password hashes
- TSGrinder for Terminal Services passwords
Using these tools in an ethical hacking methodology to find weak passwords on your Windows-based network is both an art and a science. I encourage you to check out the free password hacking chapter from my book Hacking For Dummies for more specifics.

Cracking network passwords

Home: Introduction
Step 1: Ethical hacking methodology
Step 2: Tools you should use
Step 3: What good are your findings?
| ABOUT THE AUTHOR: |
|
Kevin Beaver is an independent information security consultant, author and speaker with Atlanta-based Principle Logic LLC. He has more than 17 years of experience in IT and specializes in performing information security assessments. Beaver has written five books, including Hacking For Dummies (John Wiley & Sons, Inc.), the brand new Hacking Wireless Networks For Dummies and The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach Publications). He can be reached at kbeaver@principlelogic.com.
Copyright 2005 TechTarget
|
|
');
// -->

|
 |
|
 |
 |
 |
| TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of . |
|
| | |
All Rights Reserved, , TechTarget |
|
|
|
|
|