Hi, i'm new to the whole pentest thing, and i was wondering how i could grab a remote password hash. i tried googling this and i looked on this forum but i couldn't find anything that helps. please be specific and no flaming please
thanks
Hi, i'm new to the whole pentest thing, and i was wondering how i could grab a remote password hash. i tried googling this and i looked on this forum but i couldn't find anything that helps. please be specific and no flaming please
thanks
Welcome to the forums.
Re-read the rules that you agreed to when you signed up. Also see the "stickied" threads at the top of the newbie section.
Also don't be afraid to search for yourself both here on the forums and google.
These things will make your stay more pleasant.
Furthermore it is your job to post in the appropriate section of the forum.
The Pentesting section is for specific topics related to legal penetration testing. Hence the title at the top of that sub-forum.
Also be aware that we that any and all help given is done so freely so there is no use in adding demands such as "specific" info and "no flaming"!
Ohh wait your thread title says "ubuntu" we don't support that here. This forum is for Back Track4.
To be successful here you should read all of the following.
ForumRules
ForumFAQ
If you are new to Back|Track
Back|Track Wiki
Failure to do so will probably get your threads deleted or worse.
You can gain privileged code execution on the target system and run a command (or sequence of commands) to extract the hashes, you can gain physical access to a machine and boot from an alternate OS to get the hashes from disk, or you can sniff the password hashes off the network.
Is my answer not specific enough for you? Well if you want a specific answer you could try asking a specific question, including details such as what type of password hash you are trying to get. Lack of specifics is possibly why you couldn't find anything using Google as well.
Googling for "password hashes" returns a nice list of pages which explain how password hashes work as well as demonstrating a few ways in which particular types of password hashes can be obtained. I suggest you read a few of these pages.
And what you are doing is not pentesting by the way...
Capitalisation is important. It's the difference between "Helping your brother Jack off a horse" and "Helping your brother jack off a horse".
The Forum Rules, Forum FAQ and the BackTrack Wiki... learn them, love them, live them.