Wednesday, July 25, 2007

Security Tool Critique

The Tool that I am going to critique is called: PasswordNT_XPCrack.ZIP. As the name suggests, this program can crack and reset windows NT/XP passwords. My experience with this tool was very pleasant. Finding the tool, on the other hand, was much more difficult. Going to Google and searching for a windows password crack is probably one of the better ideas if you want to get some type of spyware and adware installed on your computer. Secondly, finding software that actually works and does what it says is an entirely different story. When I finally found this tool I was very surprised. It is a small file and is only 1.31 MB is total.

The setup for the machine I was trying to crack was a laptop that was running Windows NT. The old laptop’s user had changed jobs and their password was still loaded onto the computer.

To perform the crack I needed a 1.44 MB floppy disk. Surprisingly, in today’s age, they are not as easy to find as they once were. After I had unzipped the file, I ran a batch program that writes information to the 1.44MB floppy. The floppy disk is now bootable and contains an extremely small OS. After a restart with the floppy disk loaded into the disk drive, the OS boots up. Then a menu appears and asks the user what actions they want to perform. After navigating the OS to the correct location of the SAM files, windows password files (for more information you can go here: http://en.wikipedia.org/wiki/Security_Account_Manager) it asks which user account you would wish to modify. After selecting which user’s password you want to modify, it asks if you would like to either reset or crack their password. For my use, I only needed to reset a forgotten password, so I chose to reset. In a few seconds, the change was made. After I restarted the computer and loaded windows, I could access users account without any problems.

There are two aspects of the program that I would have loved to tried out. That is if the crack would work on an XP system and also, if the program could correctly crack the passwords.

Using the program I was very pleased. The actual use took about 5-10 minutes and that mainly was due to distractions and the unfamiliarity with the program. There were not any parts of the program that were confusing or difficult to perform. As mentioned earlier, it took much longer finding the program that it actually did to run. I was very happy with the program and would use it again if needed.

No comments: