Accept the default of Retrieve from the local machine. Click Next.
Next select an Auditing Method. Select Strong Password Audit. Click Next.
Brute Force 315
Accept the default Reporting Style. Click Next.
LC5 is ready to begin auditing. Click Finish.
316 Practical Hacking Techniques and Countermeasures
LC5 will start running the hashes through the known algorithm until a
match is made. The password to create each hash will be displayed.
In order to Import a captured Pwdump file, select the Import button from
the toolbar.
The Import Wizard will appear. Select Import from file.
Brute Force 317
Select From PWDUMP file. Click Browse.
Browse to and select the Pwdump file created by the FGDump application
(Lab 54) and click Open.
318 Practical Hacking Techniques and Countermeasures
Click OK.
Accept the warning about starting the audit session over. Click Yes.
Brute Force 319
The Pwdump file will be imported into the LC5 application. The usernames
from the target will be displayed.
Click the Start button on the toolbar.
LC5 will grind against the usernames until each password has been identified
and displayed.
*Note: I began using L0phtcrack when it was still in version 3 (LC3). The speed of
this application has increased drastically and is a proven, rock-solid application
to break Windows password hashes. If you can afford the full version,
I highly recommend it.
320 Practical Hacking Techniques and Countermeasures
As you may have noticed during the initial wizard, there are other options
to collect Windows password hashes.
Pages:
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134