ÊµÕ½ÆÆ½âWinVistaBeta2µÄ±¾µØÃÜÂë

¡¶ÊµÕ½ÆÆ½âWinVistaBeta2µÄ±¾µØÃÜÂë¡·ÕªÒª£º ÈËÃdz£³£Óöµ½ÆÆ½â±¾µØWindows 2000/XPÃÜÂëµÄÎÊÌ⣬¿É²Î¿¼µÄ×ÊÁÏÈ´·Ç³£ÉÙ¡£ÕâЩÄêÀ´£¬ÎÒÔÚÕâ·½Ãæ×öÁËЩ¹¤×÷£¬ÎªÁ˸üºÃµØÀí½â±¾ÎÄËù½²ÊöµÄÄÚÈÝ£¬Äú¿ÉÒÔͨ¹ýÕâЩÁ´½ÓÀ´²Î¿¼Îı¾×ÊÁϺÍÊÓÆµ×ÊÁÏ¡£ Ρ­

¡¡¡¡ÈËÃdz£³£Óöµ½ÆÆ½â±¾µØWindows 2000/XPÃÜÂëµÄÎÊÌ⣬¿É²Î¿¼µÄ×ÊÁÏÈ´·Ç³£ÉÙ¡£ÕâЩÄêÀ´£¬ÎÒÔÚÕâ·½Ãæ×öÁËЩ¹¤×÷£¬ÎªÁ˸üºÃµØÀí½â±¾ÎÄËù½²ÊöµÄÄÚÈÝ£¬Äú¿ÉÒÔͨ¹ýÕâЩÁ´½ÓÀ´²Î¿¼Îı¾×ÊÁϺÍÊÓÆµ×ÊÁÏ¡£

¡¡¡¡Îı¾:

¡¡¡¡http://www.irongeek.com/i.php?page=security/localsamcrack ;

¡¡¡¡http://www.irongeek.com/i.php?page=security/localsamcrack2

¡¡¡¡ÊÓÆµ:

¡¡¡¡http://www.irongeek.com/i.php?page=videos/samdump2auditor

¡¡¡¡http://www.irongeek.com/i.php?page=videos/LocalPasswordCracking ;

¡¡¡¡ÌåÑéWindows Vista Beta 2µÄʱºò£¬ÎÒÏë¿´¿´ÆÆ½â±¾µØÕ˺ÅÃÜÂëµÄÄÇЩÀϹ¤¾ßÊÇ·ñÈÔ¾ÉÆð×÷Ó᣿´ÆðÀ´£¬Î¢ÈíºÃÏñ¸Ä±äÁËVistaÖÐÔËÐеÄSAMÎļþºÍSYSKEY£¬ÕâÑùÒÔǰÓÃÔÚNT 4/2000/XPÉÏµÄÆÆ½â·½·¨¾Í²»ÔÙÆð×÷ÓÃÁË¡£ºÜ¿ì£¬ÎÒ·¢ÏÖ´ó¶àÊýÏÖÓеŤ¾ß¶¼²»ÔÙÆð×÷ÓÃÁË£¬±ÈÈç˵£¬Ophcrack 2.3¡¢Cain 2.9¡¢SAMInside 2.5.7.0¡¢Pwdunp3µÈ¡£¿´µ½°²È«¼¶±ðµÄÌáÉý£¬ÎÒÃǵ±È»·Ç³£¸ßÐË£¬µ«ÆÆ½â±¾µØÃÜÂë×ÜÊDZȽÏÓÐȤµÄÊÂÇ飬²¢ÇÒÓÐʱҲÊÇÓÐÓõġ£µ±ÎÒÊÔͼ´ÓSAMºÍSYSKEYÎļþµÄ¸´¼þÆÆ½â±¾µØÃÜÂëʱ£¬ÎÒÓöµ½ÁËÒÔÏ´íÎóÌáʾ:

¡¡¡¡Ophcrack:

¡¡¡¡"Error: no valid hash was found in this file"

¡¡¡¡Cain:

¡¡¡¡"Couldn’t find lsa subkey in the hive file."

¡¡¡¡ËäÈ»ÏñSala’s Password RenewÕâÑùµÄ¹¤¾ß¿ÉÒÔͨ¹ýBart’s PE boot CD¸Ä±äVistaµÄÃÜÂ룬»òÕßÊÇ´´½¨È«ÐµĹÜÀíÔ±Õ˺ţ¬µ«ÓÐʱ£¬ÄãÐèÒªÖªµÀµ±Ç°µÄ¹ÜÀíÔ±¿ÚÁî¡£ÓÐÒÔÏÂÈý¸öÔ­ÒòÐèÒªÄãÖªµÀµ±Ç°µÄ¹ÜÀíÔ±¿ÚÁî¶ø²»ÊǸıä³ÉеĿÚÁî:

¡¡¡¡1.ºÚ¿Í²¢²»Ï뱻ϵͳ¹ÜÀíÔ±·¢ÏÖ¡£Èç¹û¹ÜÀíÔ±·¢ÏÖÔ­À´µÄ¿ÚÁî²»ÄܽøÈëϵͳ£¬ÄÇôËûÃǻỳÒɵġ£

¡¡¡¡2.ͬÑùµÄ¿ÚÁî¿ÉÄÜ»¹ÒªÓÃÔÚÍøÂçÉÏµÄÆäËüϵͳ¡£Èç¹ûºÚ¿ÍÆÆ½âһ̨»úÆ÷µÄ¹ÜÀíÔ±¿ÚÁ¿ÉÄÜËûÓÃͬÑùµÄ¿ÚÁî¾Í¿ÉÒÔ·ÃÎʾÖÓòÍøÉÏÆäËüµÄ»úÆ÷ÁË¡£

¡¡¡¡3.ΪÁË·ÃÎÊÓÃWindows EFS(Encrypted File System)¼ÓÃܵÄÐÅÏ¢¡£¸Ä±äÕ˺ŵĿÚÁî¿ÉÄܻᵼÖÂÕâЩÐÅÏ¢µÄ¶ªÊ§£¬²»¹ýÎÒ¾õµÃSalaµÄ¹¤¾ß¿ÉÄÜ¿ÉÒÔ×öÕâÏ×÷¶ø²»»á¶ªÊ§¼ÓÃÜÃÜÔ¿£¬ÒòΪËüÊÇÓÃÒ»ÏîWindows·þÎñÀ´¸Ä±ä±¾µØ¿ÚÁîµÄ¡£

¡¡¡¡ÁíÍâÐèҪעÒâµÄÊÇ£¬Vista Beta 2ĬÈϵÄLM¹þÏ£´æ´¢Ã»Óм¤»î£¬ËùÒÔÄãËùÄܹ»µÃµ½µÄÖ»ÊÇNTLM¹þÏ££¬ºóÕß±ÈǰÕßÄÑÆÆ½âµÃ¶à¡£»¹ÓÐWindows VistaеÄBitLockerÌØÐÔ£¬Èç¹ûÕâÒ»¹¦ÄÜ¿ªÆô£¬±¾ÎÄËù½²ÊöµÄËùÓа취¶¼½«ÎÞ¼ÃÓÚÊ£¬Õâ¸öÎÒÃÇÒÔºóÔÙ̸¡£

¡¡¡¡Æð³õ£¬ÎÒ¾õµÃ񻮮½âVistaµÄÃÜÂ룬ϣÍû»¹ÕæÊDz»´ó¡£µ«¾­¹ýÔÚÍøÉÏËÑË÷ºó£¬ÎÒ·¢ÏÖÈç¹ûÓкõŤ¾ß£¬»¹ÊÇ¿ÉÒÔÆÆ½â±¾µØÃÜÂëµÄ¡£Elcom SoftµÄÔ±¹¤ÒѾ­¼ÓÈëÁ˶ÔVista SAMºÍSYSTEMµÄÖ§³Ö£¬ÌåÏÖÔÚËûÃǵēProactive Password Auditor 1.61”¹¤¾ßÖС£ºÜ²»ÐÒ£¬PPAÊÇÒ»¸öÉÌÒµÓ¦ÓóÌÐò£¬²»¹ýËûÃÇÌṩһ¸ö60ÌìµÄʹÓð档¼ÈÈ»ElcomÒѾ­Ñо¿³öÁËÔõÑù×ö£¬ÎÒÏàÐÅ£¬ÔÚ²»¾ÃµÄ½«À´£¬ÏñCainºÍOphcrackÕâÑùµÄÃâ·Ñ¹¤¾ßÒ²¿ÉÒÔ×öͬÑùµÄÊ¡£ÏÂÃæÎÒÃǽ«½éÉÜÓÃPPAÆÆ½â±¾µØWindows Vista Beta 2ÃÜÂëµÄ¾ßÌå²½Öè¡£

¡¡¡¡ÄãÐèÒªÄܹ»¶ÁÈ¡Windows Vista°²×°µÄÇý¶¯¡£¶ÔÓÚNTFSÇý¶¯£¬ÎÒÓÃKnoppix (http://www.knoppix.org/)ºÍPE Builder(http://www.nu2.nu/pebuilder/)ÊÔ¹ý£¬ÒѾ­È¡µÃÁ˳ɹ¦¡£µÚÒ»²½ÊÇ´Ó¹âÇýÆô¶¯£¬°ÑC:\WINDOWS\system32\configĿ¼ÏµÄSAMºÍSYSTEMÎļþ¿½×ß(Ò²ÐíÄãÓöµ½µÄÊDZȽÏÀ´µÄ°æ±¾£¬ÄÇôĿ¼¿ÉÄÜÊÇC:\WINDOWS\config\RegBack£¬ÁíÍâÐèҪעÒâµÄÊÇ£¬ÏµÍ³Ò²Ðí²¢²»°²×°ÔÚCÅÌ£¬ÄǾͰÑCÌæ»»³ÉÕýÈ·µÄÇý¶¯Æ÷µÄ×Öĸ°É)¡£

¡¡¡¡½ÓÏÂÀ´¿ªÆôPPA£¬²¢°´ÒÔϲ½ÖèÖ´ÐÐ:

¡¡¡¡1.Ñ¡ÖйþÏ£±êÇ©ÏÂÃæ±êÓГRegistry files (SAM£¬ SYSTEM)”µÄµ¥Ñ¡¿ò£¬È»ºóµã»÷dump¡£

¡¡¡¡2.Ñ¡ÔñÄ㽫ҪÓõ½µÄSYSTEMºÍSAMÎļþ£¬È»ºóµã»÷“Dump”°´Å¥¡£

¡¡¡¡3.ÔÚDump½×¶Î£¬PPA×Ô¶¯×öÒ»¸ö¼òµ¥µÄ±©Á¦¹¥»÷£¬Ò²ÐíÔÚÕâÒ»²½£¬ÄãµÄÃÜÂë¾ÍÒѾ­±»ÆÆ½âÁË¡£Èç¹û»¹Ã»ÓÐÆÆ½â£¬ÄÇôѡÔñ¹¥»÷ÀàÐÍ£¬°Ñ¹þÏ£ÀàÐÍ»»³É“NTLM attack”£¬ÒòΪûÓÐLM¹þÏ£¡£ÎÒÑ¡Ôñ×ֵ乥»÷£¬µã»÷“Dictionary list…”°´Å¥¡£

¡¡¡¡4.È·±£ÄãÏë񻮮½âµÄÕ˺ű»Ñ¡ÖС£

¡¡¡¡5.ÏÖÔÚ¾ÍÖ»ÐèÒªµã»÷²Ëµ¥ÉϵēRecovery->Start recovery”£¬È»ºóµÈ×Å£¬ºÃµÄ½á¹ûÂíÉϾͻá³öÏÖ¡£

¡¡¡¡Èç¹ûÃÜÂë×ã¹»¼òµ¥£¬ÄãÓ¦¸Ã¾Í¿ÉÒÔÓÃÆÆ½âµÄÃÜÂë½øÐÐÏÂÒ»²½µÄ¹¤×÷ÁË¡£²»¹ýÐèÒªÀμǵÄÊÇ£¬²»Äܱ£Ö¤¿ÉÒÔ¹¥ÆÆËùÓеÄÃÜÂë¡£Èç¹ûÃÜÂë²»ÔÚÄãµÄ×ÖµäÖУ¬ÄÇôÄãÐèÒªÇóÖúÓÚ±©Á¦¹¥»÷¡£

ÄãµÄλÖ㺵çÄÔ¹ÊÕÏÍø >> ²Ù×÷ϵͳ >> Vista >> ÊµÕ½ÆÆ½âWinVistaBeta2µÄ±¾µØÃÜÂë