Cracking Windows Passwords

Creating passwords to crack

You’ll need a Windows machine (real or virtual) with administrator access. It can run any version of Windows, XP or later, except Windows 10. If you want to use Windows Server 20xx, you’ll need to disable the "Password must meet complexity requirements" policy.

Click Start, type in CMD and press Shift+Ctrl+Enter.

If a "User Account Control" box appears, click Yes.

In the Administrator Command Prompt window, execute these commands:

net user test1 abc /add
net user test2 abcde /add
net user test3 password /add
net user test4 entrincheirado /add
net user test5 Pa$$w0rd /add
Those commands create five new system users. 

clip_image002

 

Downloading and installing Cain & Abel


Open a browser and go to http://www.oxid.it/cain.html

Scroll down and click "Download Cain & Abel v4.9.56 for Windows NT/2000/XP".

Save the installer on your PC.

clip_image004

Double-click the installer. Install the software with the default options.

NOTE: Cain & Abel will be detected as malware by your virus scanner. You will need to allow it to install, which is pretty easy if you use Microsoft Security Essentials or Defender. If you don't want to install it on your real machine, use a VM.

The installer will also ask to install WinPCap. In order to guarantee full functionality and stability, install it too.



Displaying the password hashes


Run CAIN from the Desktop shortcut, as an Administrator

If a "User Account Control" box appears, click Yes.

In the Cain window, at the top, click the Cracker tab. Move the mouse to the center right, where a blank white pane appears with a gray grid.

Right-click and select "Add to list".

clip_image006

In the "Add NT Hashes from" box, click Next.

clip_image007

The password hashes appear, as shown in the figure below. The LM hashes will all be the same if you are using Windows Vista or later, but the NT hash contains the password information.

clip_image009

 

Cracking passwords


Right-click test1, point to "Brute-Force Attack", and click "NTLM Hashes".

Note: we are cracking the NTLM hashes, not the old, weak LM hashes. The NTLM hashes are much more difficult to crack, so this attack will only be feasible for short passwords.

clip_image011

In the "Brute-Force Attack" box, click the Start button. It should find the three-letter password immediately. Close the "Brute-Force Attack" box.

NOTE: You can select different settings for the Brute Force Attack

clip_image013

Repeat the procedure for test2. The attack should find the five-letter password within a few seconds. Close the "Brute-Force Attack" box.

Repeat the procedure for test3 but, before starting the attack, choose a smaller charset only with characters, and tell CAIN to disregard all passwords shorter than 8 characters.

clip_image014

Notice that even without any complexity, a long password is hard to guess because it will take time to try all the different combinations.

After a few minutes, you should give up and be happy to have the two passwords you found, in the NT Password column of the Cain window.

clip_image015

As you saw, the Brute Force Attack is only effective for very short and simple passwords, unless you have lots of time and very powerful computation resources to try all possible combination, using all possible characters

It’s time to try a different approach; a Dictionary Attack

Right-click test3, point to "Dictionary Attack", and click "NTLM Hashes".

clip_image017

Before starting the attack, you need to add a dictionary file i.e. a wordlist containing all the words you want CAIN to test

Right-click the dictionary area and add a file.

clip_image019

CAIN has a small wordlist. Use it!

clip_image021 Notice all the possible combinations, using the words from the list.

clip_image023

Start the attack! A few seconds later…

clip_image025

Try the same thing for user test4!

clip_image026

Maybe you need a better, bigger wordlist. Go to http://bit.do/Word_Lists and download the file “wordlistPT_Small.zip”. Unpack it to any folder of your choice and add it to CAIN.

clip_image027

Launch the attack again! A few seconds later…

clip_image028

Try the same thing for user test5!

clip_image026[1]

Maybe you need an even bigger wordlist... Or a totally different kind of attack!

 

Downloading Ophcrack


Visit the website http://ophcrack.sourceforge.net/ and download the LiveCD.

clip_image030

The LiveCD is a completely self-contained, bootable version of Ophcrack 3.6.0 with rainbow tables (just a sample).

Choose the Vista/7 LiveCD.

clip_image032

On the next webpage, Ophcrack LiveCD should begin automatically downloading a single ISO file.

This file can be used to create a bootable CD or USB key that you can use it to boot your machine, physical or virtual.

Insert the Ophcrack LiveCD disc into your optical drive (or USB port) and restart your computer. After the usual POST screen, wait for the Ophcrack menu to appear.

clip_image034

At this stage you don't need to do anything because the boot process will continue automatically after the timer at the bottom of the screen expires.

clip_image036

Watch for Hard Drive Partition information to display.

clip_image038

The next screen is the Ophcrack LiveCD software itself and it will automatically attempt to recover by brute force the passwords for all Windows user accounts that it can find on your computer.

clip_image040

Surprisingly, the initial attack could not crack one of the easy passwords. Keep in mind the attack was too fast! Therefore, only short passwords were tested, maybe just up to 3 characters.

Now you’ll need to load the SAM. This is the storage for local password and is usually found in c:\windows\system32\config

Press the Load button, Choose SAM, and navigate to the appropriate folder.

clip_image042

Add the rainbow tables available in the LiveCD. Press Tables and navigate to the proper folder as shown in the picture. Keep in mind that pending on your partitions configuration, the /media/sr0 path can be different.

clip_image044

This will add the Vista tables, created for the most probable passwords.

clip_image046

clip_image048

Press Crack

After 20 minutes…

clip_image050

After 43 minutes…

clip_image052

We need something else, right? But before that, why don’t we enhance the difficulty a bit more?

Exit Ophcrack and restart your Windows OS. Let’s create some more users, shall we?

net user test6 P@ssw0rd /add
net user test7 abc123!@# /add
net user test8 pazzword123 /add
net user test9 omgqwerty /add
net user test10 qwerty7890 /add

Visit the website http://ophcrack.sourceforge.net/tables.php and download an additional set of rainbow tables, the Vista free based on a dictionary. It’s a file named tables_vista_free.zip. Unpack it to a directory of your choice inside your Windows environment.

clip_image054

Restart your machine again and boot from the Ophcrack Live CD.

Reload the SAM, install all the rainbow tables and start a new cracking procedure.

clip_image056

More passwords, a longer wait… for a very disappoint result!

clip_image058

What can we conclude from this result?

Are the previously created password really safe?

Don’t give up. Not just yet… Restart your machine to Windows.

Let’s try CAIN again with an even bigger wordlist. Go to http://bit.do/Word_Lists and download the file “rockyou.zip” file. Unpack it to any folder and notice the size of the text file.

Let’s attack all accounts at once!

clip_image059

Add the new text file to CAIN’s list of dictionary files and don’t forget to reset all dictionary files to their initial positions. clip_image060

You can even only the basic option to speed things up.clip_image061

Wait one minute…


clip_image063

clip_image065

Conclusion?

The free and small rainbow tables are useless for any real application

But with a proper dictionary file, cracking silly passwords is a walk in the park!


 

Previous post: Sniffing for Passwords with Wireshark

Next post: Cracking Windows 10 passwords

Sniffing Passwords with Wireshark

Installing the Wireshark Packet Sniffer

What you need for this task:
  • A computer with Internet access. You need administrator privileges.
  • I wrote the instructions with Windows 7
Open a Web browser and go to WireShark.org

Download and install the latest version of Wireshark. The installer will also install WinPCap.

Reboot the machine to load the WinPCap driver

Note: If you have problems with WinPCap under Windows 10, get the driver from http://www.win10pcap.org/

Starting a Packet Capture


Start Wireshark.

In the Capture menu, select Options

clip_image002

Make sure your interfaces are in promiscuous mode. Press Manage Interfaces.

clip_image004

In the Manage Interfaces windows, select the desired interface where you want to capture traffic

clip_image006

Back to the starting windows, double click on the interface to start the capture

clip_image008

You should see packets being captured and scrolling by, as shown below on this page. Every packet sent from or to your machine is shown here. But it shows a lot more information than you usually want to know.

clip_image010

Sending a password to a test site


Open a Web browser and go to:

http://testphp.acunetix.com/login.php

or

http://testasp.vulnweb.com/Login.asp?RetURL=%2FDefault%2Easp%3F

Enter a Username of YOURNAME@SOMEDOMAIN.LOCAL (using your own name, not the literal string "YOURNAME") and a password like topsecretpassword, as shown below:

clip_image011

Click the "login" button.

The login will fail but that is not important.

In the Wireshark window click on the red square button to stop the capture

clip_image013
 

Finding the password in Wireshark


In the Wireshark window, in the Filter bar, type as filter some of the text you entered as username, as shown below:

frame contains rumos.local

clip_image014

Wireshark shows an HTTP packet containing the searched text. In the upper pane of Wireshark, right-click the HTTP packet and click "Follow/TCP Stream", as shown below.

clip_image016

Expand the "Follow TCP Stream" box so that you can see YOURNAME and the topsecretpassword, as shown below.

clip_image018
 

Conclusion:


When login into plain HTTP websites, your credentials are sent in plaintext and can be easily captured and discovered.


Using a secure website


Start another packet capture by going to Wireshark’s menu bar, click Capture, Start (or click the blue fin button on the top left. A pop-up asks "Do you want to save the captured packets before starting a new capture?" Click "Continue without saving".

In a Web browser, go to http://gmail.com. Notice you are immediately redirected to https://accounts.google.com. (You can go to any safe website, it doesn’t have to be on GMail)

Enter a valid Gmail account and the same password topsecretpassword, as shown below.

Click the "Sign in" button.

clip_image019

Gmail will reject the credentials, just like the other website did.

In the Wireshark window, click Capture/Stop.
 

Searching for the password in Wireshark


In the Wireshark menu, click Edit/Find Packet.

clip_image020

In the "Wireshark: Find Packet" box, click the String button.

Enter a search string of secret, as shown below.

clip_image021

In the "Search In" section, click "Packet bytes". Click Find.

clip_image022

A message appears briefly in the status bar at the bottom of the Wireshark window, saying "No packet contained that string", as shown below. This means the password text cannot be found in any of the captured packets because the information exchange with Gmail’s website was properly encrypted.

clip_image024
 

Conclusion:

When login into secure websites, user credentials are encrypted by the SSL/TLS protocol and although the packet sniffers manages to captures the traffic, it’s virtually impossible to see the content of the encrypted information exchanged with the secure website

Previous post: Securing Virtual Machines in Windows 10

Next post: Cracking Windows Passwords