little_drive
New Member
Hello,
I got a network and somebody broke into it. The person that broke into my network had physical acces to it. But I am sure the person didn't had admin rights. The passwords on my network are stored on a computer that the person that broke into my network didn't had acces to.
- I install latest updates
- The account the person could use couldn't execute any files. (.exe)
- However it could start batch files.
- Got antivirus scan.
- No virus/spyware/keyloggers or something.
Now I got the following questions.
- How did the person knew which computer has all the passwords stored in it?
- How did he copied those files? (SAM and System)
I tried to redo his actions so I know how he did that and secure my network.
- I tried on one of those computers that didn't had the password files stored in it.
- Bootdisk (method; start a bootdisk and copy the SAM and System files, it failed)
- www.loginrecovery.com (method; it failed cause the passwords aren't stored in it)
- Started knoppix, but couldn't copy the SAM and System files)
Those are all the SAM and System files on the local computer so this couldn't be the way the person could broke into my network.
- How did he find the computer with the passwords stored in it?
The network operating systems are all the same: Windows XP Professional with the latest updates.
Greetz Little drive
I got a network and somebody broke into it. The person that broke into my network had physical acces to it. But I am sure the person didn't had admin rights. The passwords on my network are stored on a computer that the person that broke into my network didn't had acces to.
- I install latest updates
- The account the person could use couldn't execute any files. (.exe)
- However it could start batch files.
- Got antivirus scan.
- No virus/spyware/keyloggers or something.
Now I got the following questions.
- How did the person knew which computer has all the passwords stored in it?
- How did he copied those files? (SAM and System)
I tried to redo his actions so I know how he did that and secure my network.
- I tried on one of those computers that didn't had the password files stored in it.
- Bootdisk (method; start a bootdisk and copy the SAM and System files, it failed)
- www.loginrecovery.com (method; it failed cause the passwords aren't stored in it)
- Started knoppix, but couldn't copy the SAM and System files)
Those are all the SAM and System files on the local computer so this couldn't be the way the person could broke into my network.
- How did he find the computer with the passwords stored in it?
The network operating systems are all the same: Windows XP Professional with the latest updates.
Greetz Little drive