AtYourService
Member
- Reaction score
- 12
- Location
- CT
As some of you know I offer password recovery services at my shop
i get a customer come in and ask about cracking a password for a laptop,said his wife died, and he didnt know the password etc, couldnt pay the bills online because she knew all the info,so he brings the laptop in,its got his name as the other user,but hes not admin so he cant do anything to reset the other password. So he leaves the laptop with me to crack it and has to get to a doctors appointment. The reason why I'm cracking it and not just resetting it because the password could have been used somewhere else for her online billing etc, also if you reset the Windows password it renders the saved Internet explorer passwords useless because theyre hashed with the user password and if you remove it the saved passwords will be removed.
So i quickly get his SAM hash for the other user
And it takes me less than a minute to crack it with a wordlist
Ntlm Hash:20656d90b8889f01121827540adecda3 hex:6469766f726365 passwd:divorce
So here's my question, upon seeing this , what would you do?
Yea suspicious right? Well I call him to let him know its finished without letting him know the password. He says Ok ill see you on Monday.
So now I got time to contemplate, I quick do some online searches and verify she is indeed deceased. Now what do I tell him the password is? Do I tarnish her last image for him?
i get a customer come in and ask about cracking a password for a laptop,said his wife died, and he didnt know the password etc, couldnt pay the bills online because she knew all the info,so he brings the laptop in,its got his name as the other user,but hes not admin so he cant do anything to reset the other password. So he leaves the laptop with me to crack it and has to get to a doctors appointment. The reason why I'm cracking it and not just resetting it because the password could have been used somewhere else for her online billing etc, also if you reset the Windows password it renders the saved Internet explorer passwords useless because theyre hashed with the user password and if you remove it the saved passwords will be removed.
So i quickly get his SAM hash for the other user
And it takes me less than a minute to crack it with a wordlist
Ntlm Hash:20656d90b8889f01121827540adecda3 hex:6469766f726365 passwd:divorce

So here's my question, upon seeing this , what would you do?
Yea suspicious right? Well I call him to let him know its finished without letting him know the password. He says Ok ill see you on Monday.
So now I got time to contemplate, I quick do some online searches and verify she is indeed deceased. Now what do I tell him the password is? Do I tarnish her last image for him?
Last edited: