Windows Password Recovery
How to recover lost or forgotten Windows user account passwords
There are a multitude of reasons as to why somebody would want to gain access to a computer when they have lost, forgotten or simply don’t know the correct authentication credentials. Not knowing or forgetting a user account’s authentication credentials such as the correct user logon name and password is the most common reason for needing to conduct a password recovery procedure.
Regular user absenteeism is another situation whereby the person who normally uses that machine is unavailable as they may be on holiday, sick or no longer employed or associated with the organization and there are important files that need to be accessed.
Malicious intent is yet another common reason. Some malwares change or modify user authentication credentials in order to elude detection or to prevent security updates and procedures that may detect them.
Password Location – Windows passwords are stored in a SAM file which is usually located in the Windows directory (C:\windows\system32\drivers\etc\lmhosts.sam)
Password Encryption – Recent versions of the Microsoft Windows operating systems store all passwords in an encrypted format. The algorithm used to encrypt passwords is usually the secure hash standard. If the passwords were to have been stored in an unencrypted format they would be readily available for use once you had located the SAM file where they are stored. Many other applications also store passwords encrypted using the secure hash standard.
Brute Force – One of the easiest to implement methods of “cracking” an encrypted password is by a technique known as “brute force”. The brute force approach essentially tries every possible combination of characters and numbers until it finds a password that works. Modern computers can typically succeed in cracking an encrypted password using a brute force attack within a matter of seconds for passwords of less than 6 characters and a day or so for medium length passwords. Longer more complex passwords will take longer to crack/recover.
Password Recovery Options
There are a number of different strategies that can be employed to recover lost, forgotten or unknown passwords and authentication credentials including:
Network Administrator/Help Desk - In a client/server network environment you are best advised to go to your network administrator or help desk and apply for a new password. Within a Windows domain an authorized person can access Active Directory and reset your password for you. They will also tell you about any other procedures that you may need to perform in order to complete the process.
Using another Account - If there is another account to which you do know the password then you can use this to log onto the machine. The Guest or Anonymous accounts will do fine if they have not been disabled. Once logged on all you need to do is to use some password cracking software to recovery the lost passwords. If the alternative account that you use to access the machine does not have sufficient user privileges then locate and copy the SAM file for cracking on a machine that does.
Multi Boot Systems - If you cannot log onto the machine and you have another operating system to which you know a valid logon account then reboot the machine into the other OS. Once the machine has finished booting and your alternative desktop environment becomes available you can browse your machine and locate the Windows user account password file. This is the SAM file which I mentioned above and it is usually located in the Windows directory (C:\windows\system32\drivers\etc\lmhosts.sam).
You may find that the drive letters are different since you are in another operating system but don’t worry just located the installation of the OS from which you need to recover the passwords and then drill down its directories to locate the above mentioned SAM file. Once located make a copy of it onto removable media. You can then use the copy to recover the passwords from by using a brute force password cracking tool such as Cain and Abel or LCP.
No Accessible Local Machine User Accounts Available
If you cannot logon to the machine using another account then you will need to boot the machine using a “Live” media such as a DOS boot disk or CD-ROM boot disk such as one with Knoppix or Mini-PE. There are also many other utility discs that will do the job. Once the machine has booted using this media you will need to locate the SAM file mentioned above and copy it to removable media (usually C:\windows\system32\drivers\etc\lmhosts.sam).
Another option is to install a new blank hard disk and install an operating system on it. You can then use this OS to browse to the SAM file you need to recover the passwords from. Copy it to your new hard disk and run the password cracking/recovery software and wait till the passwords have been recovered. Note that many network administrators will have just such a hard drive already prepared for occasions like this.
It is also possible for a user with network administrator privileges to access the SAM file via the network. However; there are still some situations when this can’t be done. For example if the SAM file was created using local users and groups rather than domain network parameters (Active Directory and Group Policy).
Password Recovery Software
As mentioned there are a number of password cracking/recovery software applications out there that can do the job. Cain and Abel is a long standing very robust and reliable application that comes with a large range of features and capabilities. LCP is one of the easiest to use. Other possibilities include John the Ripper, THC Hydra, Brutus, RainbowCrack, Pwdump and many others that have additional features such as packet sniffing capabilities.
LCP Password Recovery on Target Machine
To recover passwords on the target machine using LCP you will need to load LCP and select Import/Import from local computer. A list of user accounts and hashes should appear. Now select the brute force attack button and select Session/Begin audit. Now for the sometimes long wait for the program to find the right password.
LCP Password Recovery from SAM File
To recover passwords from the SAM file using another machine simply take the SAM file once you have located and copied it to removable media to the machine with LCP installed. Now copy the SAM file directly into the LCP directory. Start LCP and select Import/Import from SAM file. This will load the hashes and then you will be able to execute a brute force attack on them to recover your lost or forgotten passwords.
Nothing Found!
Why not submit your own content? Signup here.
-
How to run Windows on a Mac | By koopalo | in Computers
There are some real differences between Windows and Mac. Windows is better-suited for certain tasks like programmi...
-
How to Get Free Computer Help | By Romian1 | in Computers
If you have a computer problem and don't have an active warranty or service contract, you have other resources to s...
-
How to Remove Computer Viruses Easily | By Romian1 | in Computers
It's mandatory that computers have some type of computer virus protection whether connected to the internet or not....
-
Get a Discount on the New Apple iMac | By 1How | in Computers
If you're new to buying Apple computers, you're probably paying full price. While it's true that Apple's iMac line ...
-
How do I convert FLAC from a CD on a Mac? | By 1How | in Computers
FLAC is a type of lossless audio format. Unlike mp3, files encoded in FLAC don't are 100% identical to their CD ve...
-
Cream Cheese and Egg Dip | By techdoc | in Appetizers
Cream cheese and egg dip is one of the simpler party favorites to prepare and its popularity can be measured by the...
-
Savory Mince | By techdoc | in Recipes
Savory mince can be used in so many different recipes that it is essential to have your own custom base recipe from...
-
Super Succotash | By techdoc | in Recipes
This budget friendly easy recipe is nearly as old as the human race and yet it never fails to titillate and tantali...
-
Southern Style Chicken Seasoning | By techdoc | in American Cooking
Here is how to make a wonderful Southern Style Chicken Seasoning that has KFC in its sights....
-
About War Driving | By techdoc | in Computers
Discuss war driving and wireless networking hacking, their differences and countermeasures....








Long time ago , I confronted with the password problem. Finally , my friend Jane introduce the Windows password Reset.
It helps me access windows. It’s worth a try!
http://www.resetwindowspassword.com
There are a lot of Windows password revealers and crackers available, but I’ve found that Windows Password Recovery Tool is the most effective.:
it not only supports XP, 2000, and NT, I have personally tested it with Vista Home Premium and Ultimate. It works perfectly to reset any local user account to a blank password
You can use the ISO to burn a boot CD. Follow these instructions:
1. Download ISO file from http://www.windowspasswordsrecovery.com Windows Password Recovery Tool
2. Burn to a CD using a CD burning tool such as Nero or Roxio or MagicISO
3. Insert CD into drive and reboot.
4. You may have to select an option in the BIOS to get the computer to boot from the CD.
Booting up and clearing a password takes a minute or two works like a charm.