You are aware that you need local admin access to access that? There is no security in Windows when you are logged in as an admin (the book of Windows NT 3.1 already says this). So where exactly is the security risk now? It's like saying a safe is insecure for a person that already has the key or the code.
@@Lofotewhile it is saved as a hash, it is an unsalted md4 hash which means you can just run it through a rainbow table (aka a hash database as he calls it) to get the original password
@@hyperkiko good point, but to my understanding, this is about the security questions, not getting the original passwordd, which should be saved as a hash only. Or do you mean something else?
@TheRealMangoDev everything is vulnerable when you login as admin. If someone has root access there is no protection barrier anymote, it is vulnerable to everything
@@SketchyB_YT How? (Just to clarify: I am talking about a well configured system, with user having no admin rights, a good admin password and BitLocker against offline attacks for example via USB stick (which requires physical access however).
@@gmddolbaeb2191 yep! Can even automate it by creating your own WinPE bootable environment with a custom program that runs the cracker. The entire registry is stored as reg.dat so it really is as simple as finding that file.
@@gmddolbaeb2191 Thats why on a secure system BitLocker (or similar) is required, if you also want to block people that have physical access to the machine. If you can hinder people from physically access (or access via IPMI), e.g. servers in a locked down room, you can skip that.
@@Lofote this is if you already have access but want to know the users password, most people use the same password for a lot of services so it would be helpful to know their password so you can try it on other services
thats not the point, the point is you can get the original password, setting it to something else never gives you the original password. Also you could just boot on a usb drive instead to get the sam file or use the recovery bug if its windows 10 1907 or earlier@@Lofote
@@guilhermemestre4 Yes, I understand that, but the security flaw is already there then. The thing is (the major rule, how Microsoft security is implemented): if someone or something has admin rights, it can do whatever it want. There is no security anymore then. This is the same on Linux: if you run something as root, you are "inside", there is nothing the operating system will prevent then. :)
@Lofote in the last enderman video, he explained how to access these reg files. you need a specific account in addition to the administrator one. but some third-party services have these privileges, that's the problem. if I'm not mistaken, he explains this in the previous video
When windows is running, only the NT AUTHORITY\SYSTEM internal user has read access to the SAM hive by default. (so the login stuff can read the hash data) Unless someone has offline access to the drive (or the system was tampered with), this is not a serious security risk.
The way passwords work in recent years is it goes through an irreversible algorithm, then the result is stored. Anytime a password needs to be compared, it gets put through the same algorithm and the result is compared, so only you know your password. The problem is when that algorithm isnt one way, then people can get your original password from the hash.
Damn, it's crazy that a big company like Microsoft can't use a newer, better hash function
25 likesYou are aware that you need local admin access to access that? There is no security in Windows when you are logged in as an admin (the book of Windows NT 3.1 already says this). So where exactly is the security risk now? It's like saying a safe is insecure for a person that already has the key or the code.
79 likesReplies (18)
@@Lofotewhile it is saved as a hash, it is an unsalted md4 hash which means you can just run it through a rainbow table (aka a hash database as he calls it) to get the original password
0 likes@@mortn_yt and have the same full acces if you login as root. Exactly same thing
0 likes@@hyperkiko good point, but to my understanding, this is about the security questions, not getting the original passwordd, which should be saved as a hash only. Or do you mean something else?
0 likes@TheRealMangoDev you see, if you leave your safe open, you cant blame the manufacturer when stuff is stolen from it.
0 likes@TheRealMangoDev everything is vulnerable when you login as admin. If someone has root access there is no protection barrier anymote, it is vulnerable to everything
0 likesAnd..? Its still vulnerable.
0 likesOr you can use linux
0 likes@@Lofote you can change C:/system32 sethc to cmd.exe
0 likes@@SketchyB_YT How? (Just to clarify: I am talking about a well configured system, with user having no admin rights, a good admin password and BitLocker against offline attacks for example via USB stick (which requires physical access however).
0 likes@@gmddolbaeb2191 yep! Can even automate it by creating your own WinPE bootable environment with a custom program that runs the cracker. The entire registry is stored as reg.dat so it really is as simple as finding that file.
0 likesNo, but he doesn’t have to be a local admin for that to happen. Hackers can do that easily.
0 likes@Lofote Lookup the Dunning Kruger effect
0 likes@@gmddolbaeb2191 Thats why on a secure system BitLocker (or similar) is required, if you also want to block people that have physical access to the machine. If you can hinder people from physically access (or access via IPMI), e.g. servers in a locked down room, you can skip that.
0 likesUSB from bootable media command prompt
2 likes@@Lofote this is if you already have access but want to know the users password, most people use the same password for a lot of services so it would be helpful to know their password so you can try it on other services
3 likesthats not the point, the point is you can get the original password, setting it to something else never gives you the original password. Also you could just boot on a usb drive instead to get the sam file or use the recovery bug if its windows 10 1907 or earlier@@Lofote
43 likes@@guilhermemestre4 Yes, I understand that, but the security flaw is already there then. The thing is (the major rule, how Microsoft security is implemented): if someone or something has admin rights, it can do whatever it want. There is no security anymore then. This is the same on Linux: if you run something as root, you are "inside", there is nothing the operating system will prevent then. :)
7 likes@Lofote in the last enderman video, he explained how to access these reg files. you need a specific account in addition to the administrator one. but some third-party services have these privileges, that's the problem. if I'm not mistaken, he explains this in the previous video
28 likesWhen windows is running, only the NT AUTHORITY\SYSTEM internal user has read access to the SAM hive by default. (so the login stuff can read the hash data) Unless someone has offline access to the drive (or the system was tampered with), this is not a serious security risk.
13 likesReplies (3)
@@txicatedbeast386The problem is you need some bug in Windows (which security updates patch out) or admin access for this.
0 likes@@txicatedbeast386still need admin
0 likesI guess you'll are the ones who don't know the risk getting NT Authority elevated CMD is as easy pancakes.😅
1 likeOnce you have a CMD with full power, aka NT authority system power, then you can easily get access to these keys (in theory).
I don't know that Google captha use an image of a Gojek driver in other country 😂
23 likesReplies (4)
@@276- 😁
0 likeschange the profile picture. NOW!! ⚡️🌩️
0 likeswow never thought anyone would see the gojek driver 😂
0 likes@@Fauxed nah, i though i was mistake when saw the gojek driver
0 likesI think they are doing this to save your password. I use a txt file to save my reminder batch file data
3 likesReplies (1)
The way passwords work in recent years is it goes through an irreversible algorithm, then the result is stored. Anytime a password needs to be compared, it gets put through the same algorithm and the result is compared, so only you know your password. The problem is when that algorithm isnt one way, then people can get your original password from the hash.
0 likesYeah it begged the question
4 likesalways when i get a virus or some shit i always get redirected to your youtube channel
0 likesMy latest video makes Windows in the Recycle Bin use UWP normally. I don't know how.
0 likesBig man and that HEY IS GREAT MATE❤❤❤❤❤
0 likesHold on, can you make a longer video about this? Or can you at least explain better how you extract the hash from the dword?
0 likesEnderman different languages
1 like[EN] Enderman
[PL] Kresostwór
[ES] Criatura
[FR] Créature
[RU] Существо
[TR] Yaratık
Replies (1)
it's not true in all languages it's Enderman (becaus it's a minecraft mob)
2 likesWhat's the website
0 likesWindows "security":
0 likesReplies (2)
@@pronounjow Oh my bad lol I fixed it
1 likeAt least spell "security" correctly...
0 likesyeah, for me pretty safe
0 likesso would many people with laptops say
guys please buy me a thinkpad t480
Useful
1 likewho's ashley
0 likesOr is it…?
0 likesBrilliant
0 likesAleast i use Linux mint, so i am safe?
1 likeReplies (5)
@@256odeon well Linux user is so lows that hacker don't wasted their time for small fish
1 like@@256odeon in Linux mint the passwords are salted. So it's way more different to get them.
1 like@@CookieXD1998 so he is safer from a windows exploit in linux? 😂😂
2 likesObviously not (being completely safe is impossible, you are safer.)
4 likes??????? obviously yeah
0 likesis it the same in windows 10?
0 likesReplies (2)
@@stysan i am disaapoimted in the microsft
0 likesyes
1 likeTherr us a tornado RN in a lot of stated
0 likesFirst and nice🎉🎉
0 likesHello
0 likesnice now i know that microaodt will know that my favorite move was 1#*! And my frist child was ahsjsk
0 likesyeah wth Microsoft
0 likesa
0 likesOk
1 likeWindows is not safe
0 likesbro telled us how to get admin passwords
0 likessomeone password: ==-#djj121*
1 likewhat the fuck microsoft
0 likes