恢复windows密码的rainbow table(time-space trade-off)的介绍

http://securityxploded.com/rainbowcrack.php

Recover Windows Passwords Using Rainbow Crack
 
 
 
See Also
 
 
 
 
About Rainbow Crack
 
Gone are the days when we have to wait for the days together to recover the Windows account password. Thanks to the  rainbow crack technology, now we can crack the passwords in few seconds with 100% success rate.

This Rainbow cracking technology works on simple concept. Instead of computing the hashes for each password dynamically and comparing with the correct one during cracking, password hashes are computed in advance for all character sets. These hashes are then stored in datasets called rainbow tables. 

So cracking involves just comparing the current password hash with the pre computed hashes within the rainbow tables and get the associated plain text password. Hence it takes very less time compared to the traditional method of brute force cracking. Setting up the rainbow table for various character sets is just one time activity and may take days or months based on the character set and speed of the machine. Once the rainbow tables are ready, you can feed the password hash to it and get your password cracked in seconds.
 
rainbow crack
 
 
 
Recovering Windows Account Password
 
In order to recover your Windows user password, first you have to get the LM hash for the target user account. This can be done in many ways. You can use any of the tools such as pwdumpcain&abel or  LC5. You need to have administrator privileges to dump the hashes using these tools. If you have lost administrator password itself, then you can boot the system using BackTrack live cd or Windows restore CD and then copy the SAM & SYSTEM hive files (which is located in c:\windows\system32\config folder. Note that your system drive may be different). Next feed these files to  Cain & Abel tool to get the LM hashes for the target account.
 
Here is the screenshot of retrieving LM hash for users using the Cain&Abel tool
 
LM Hash from Cain_Abel
 
Once you have collected the LM password hash, you can start the password cracking operation using the rcrack tool (part of the  RainbowCrack Project) with the rainbow tables that you have already created for certain character sets. 
 
Note that with Vista onwards Windows no longer stores LM hashes (unless under certain configurations)  as it was susceptible to easy brute force cracking. In such cases, you can as well use the NTLM hash to recover password with RainbowCrack.
 
Ideally setting up the rainbow tables takes huge amount of disk space and lot of computing time to generate the tables. Hence its not practical for anyone to create such an setup on the home system.
 
 
 
Online Rainbow Cracking
 
To make the game eaiser,  lot of websites ( including free as well as commericial ) offer free online rainbow cracking service. These organizations have setup huge database of rainbow tables for all keysets on their high end machines which makes the cracking possible in few seconds. Also these services offer password cracking for different type of hashes such as LM, NTLM, SHA, MD5 etc. 

For FREE services you may have to wait for some time based on the load and incoming requests. However you may also look for commercial services for quick results at smaller cost.
 
If you are an organization who needs this kind of password recovery service frequently then you can consider buying precomputed rainbow tables for reasonable price and perform the password cracking operation using rcrack tool.
 
 
If you find good online hash cracker links let us know, we will update it here.
 
Now you don't have to wait for days together with half hope to get back your lost password :)
 
 
 
References
 
  1. RainbowCrack: Fast method of recovering Windows password. 
  2. pwdump: Tool to dump hashes of Windows user accounts.
  3. Cain & Abel: Multi purpose security tool.  
  4. BackTrack Live CD : Linux live CD distribution for Pentesting.
  5. LC5 : Tool to dump hashes and recover passwords for windows users.
 
 
 
See Also
 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
简介: AdvancedWinServiceManager 对Windows服务进行更智能分析的专门软件. AllInOnePasswordDecoder 可以用不同的编码算法快速恢复受保护的密码. AsteriskPasswordSpy 显示Windows应用程序中星号背后隐藏密码的工具. AutorunFileRemover 自动执行文件清理工具. BrowserHistorySpy 查看IE,firefox,chrome等浏览器的历史记录. BrowserPasswordDecryptor 查看浏览器保存的各种网站登录密码. BrowserPasswordRemover 移除浏览器保存的各种网站登录密码. DirectoryScanner 识别网络上运行的目录服务器的类型. EncryptedFileScanner 加密文件扫描工具,扫描计算机中是否存在着加密文件. HashGenerator 哈希值生成校验工具,用于文件完整性检测. HashKracker 用来恢复和破解多个类型的哈希散列密码的哈希密码破解工具. HiddenFileFinder 快速查找文件库里的隐藏文件,定位隐藏文件,对隐藏文件进行操作. InstantPDFPasswordProtector PDF密码工具. InstantPDFPasswordRemover 解除PDF密码的限制. LDAPSearch 远程搜索目录服务器的活动目录等. MACAddressScanner 远程扫描并查找本地网络上所有系统的MAC地址. MD5SaltedHashKracker MD5哈希值密码破解恢复. MysqlPasswordAuditor MySQL密码恢复和审计软件. NetDatabaseScanner 远程检测网络上运行数据库服务的类型. NetShareMonitor 防止未经授权的访问共享文件,加强保护共享文件. OraclePasswordAuditor 恢复Oracle数据库密码,检测到Oracle数据库存在的一些安全配置问题. PcproxRFIDReader RFID阅读器是读取RFID/HID卡ID. ProcNetMonitor 监视所有正在运行的系统进程中的网络活动. SaltedHashKracker 恢复salted哈希密码使用字典暴力破解. SimpleWebsiteBlocker 可以在电脑上屏蔽掉你指定的任何网站. SocialPasswordDecryptor 恢复一些如Facebook,Twitter,google plus等SNS社区的密码. SpyBHORemover 删除流氓软件对浏览器的BHO劫持. SSLCertScanner 扫描在任何主机上的SSL证书. VirusTotalScanner 采用了哈希校验算法来检测文件并即时显示结果. VistaUACMaker 为目标程序加载UAC权限. WiFiHotspotScanner 扫描和发现你周围的无线热点设备,并显示每个热点的详细信息. WiFiNetworkMonitor 扫描并发现Wi-Fi网络潜在的入侵者. WiFiPasswordDecryptor 可以恢复本机连接过的Wi-Fi账号登录名和密码. WiFiPasswordDump 命令行下恢复本机连接过的Wi-Fi账号登录名和密码. WiFiPasswordKeyGenerator Wi-Fi密码生成器. WiFiPasswordRemover 解密并删除无线密码. WindowsLicenseKeyDump 恢复您的微软软件密钥,以及无数其他应用程序的产品密钥. WindowsPasswordKracker 恢复丢失或遗忘的Windows密码. WindowsUSBBlocker 轻松地禁用所有USB端口. WindowsUserManager Windows 用户管理程序. WindowsVaultPasswordDecryptor 迅速恢复Windows凭据管理器所有的存储密码. WinSCPPasswordDecoder WinSCP密码解码器允许您快速地找到WinSCP配置文件中的所有存储的密码.
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值