Hello,
This is something I'm curious about. There is a LAN consisting of Windows XP machines. There is an administrator account say admin-xyz which can be used to login to any of the machines on the network. But, when I run pwdump to get the password hashes on a machine, I dont see the admin-xyz account. I am just curious as to how the authentication happens. Can someone please shed some light on this?
Thank You.
-
Most likely it's only dumping the LOCAL hashes from the SAM, and you are looking for the domain admin account which is not stored locally.
From Dan
0 comments:
Post a Comment