how to HACK a password // Windows Edition
Вставка
- Опубліковано 29 чер 2023
- Create passwords I can’t hack with Dashlane (unlike Michael): dashlane.com/networkchuck50 (50% off) with code NETWORKCHUCK50
It is surprisingly easy to hack a password on Windows. In this video, NetworkChuck will demonstrate how you can grab a password hash from a Windows computer and reveal the passwords with a tool called impacket secrets dump. Once we have the hash, we can use a password cracking tool called Hashcat (a popular tool in Kali Linux), to crack the password.
VIDEO HELP
---------------------------------------------------
Mitigation Techniques: attack.mitre.org/techniques/T...
SECURITY MEASURES YOU NEED TO DISABLE TO USE ALL FEATURES IN THIS VIDEO
-Disable “DisableRestrictedAdmin” (this allows winrm and rdp access with a hash): reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
-Turn off Windows Firewall
-Enable RDP and add user to RDP users group
🔥🔥Join the NetworkChuck Academy!: ntck.co/NCAcademy
**Sponsored by Dashlane
SUPPORT NETWORKCHUCK
---------------------------------------------------
➡️NetworkChuck membership: ntck.co/Premium
☕☕ COFFEE and MERCH: ntck.co/coffee
Check out my new channel: ntck.co/ncclips
🆘🆘NEED HELP?? Join the Discord Server: / discord
STUDY WITH ME on Twitch: bit.ly/nc_twitch
READY TO LEARN??
---------------------------------------------------
-Learn Python: bit.ly/3rzZjzz
-Get your CCNA: bit.ly/nc-ccna
FOLLOW ME EVERYWHERE
---------------------------------------------------
Instagram: / networkchuck
Twitter: / networkchuck
Facebook: / networkchuck
Join the Discord server: bit.ly/nc-discord
AFFILIATES & REFERRALS
---------------------------------------------------
(GEAR I USE...STUFF I RECOMMEND)
My network gear: geni.us/L6wyIUj
Amazon Affiliate Store: www.amazon.com/shop/networkchuck
Buy a Raspberry Pi: geni.us/aBeqAL
Do you want to know how I draw on the screen?? Go to ntck.co/EpicPen and use code NetworkChuck to get 20% off!!
fast and reliable unifi in the cloud: hostifi.com/?via=chuck
- Password cracking techniques
- How to hack a password on Windows
- Cybersecurity vulnerabilities
- Cyberattacks and network security
- Kali Linux for password hacking
- Hashcat and CUPP for password cracking
- Pass the Hash attack
- NTLM and RDP security
- WinRM for remote access
- Ethical hacking for information security
- IT security and password protection
- NetworkChuck's password cracking tutorial
- Learn password cracking on NetworkChuck
- Understanding cybersecurity and password hacking
- Protecting against password hacking
- Information security and password protection
- IT security best practices for passwords
#passwordhacking #passwordcracking #windows - Наука та технологія
Create passwords I can’t hack with Dashlane: dashlane.com/networkchuck50 (50% off) with code NETWORKCHUCK50
VIDEO HELP
---------------------------------------------------
Mitigation Techniques: attack.mitre.org/techniques/T1003/002/
SECURITY MEASURES YOU NEED TO DISABLE TO USE ALL FEATURES IN THIS VIDEO
-Disable “DisableRestrictedAdmin” (this allows winrm and rdp access with a hash): reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
-Turn off Windows Firewall
-Enable RDP and add user to RDP users group
🔥🔥Join the NetworkChuck Academy!: ntck.co/NCAcademy
**Sponsored by Dashlane
:)
My parents won’t let me and I got hacked plz help me ):
Hy I'm just a kid interested in coding and I kinda need your help
How not to hack a password. CLS
You forgot to close the CMD/Powershell window on his PC so unless he's not used to your antics yet he knows something is up lol
Next time be sure to close the cmd window with your commands and delete the files you saved. Many hackers caught by not covering their tracks. Watch the clip you forgot this.
Yup, he did 🤔
LOL saw that too😂
Hahaha hilarious to see that we all noticed it 😂
I’m pretty sure if he was doing it for real he would do all of that
relax and chill bro, it's staged. he knows whats he is doing
“He doesn’t even know”
Also CMD open: 😂
I just found your channel two hours ago and you’ve already answered dozens of my questions across 3 videos. You’ve got my attention 😂
What blows me away is someone created hash cat, someone created CUPP, there are truly some brilliant minds out there that are on a level which is almost incomprehensible
I've had the feeling BTC would be going to 3k as well. Clearing out all my Alts going into BTC and MA230FH only, maybe a little BNB.
ALLHACKZEB help you aloot ❤❤❤
I quite enjoyed the suspense, drama and all the fun you had. You are definitely not a boring computer nerd !
youre vids are very well made and make learning white hats stuff very interesting, I'm a beginer and the more I watch your stuff the more it makes me want to learn keep up the good work
Thank you for the update MA230FH is done right, and waiting is part of the process,
I know this is for educational purposes but most system now add salt to the password before it's hashed and also re hash it many times which mean the complexity is way too high to crack via brute forcing or rainbow table. I'm a developer and this is how we store password in the DB with some good library and I'm perplexed that window use MD4 while SHA256 is the most secure Hash function. Anyway good stuff like always haven't been on here in a minute your charismatic is what I came out here for and hoping I can grow my patches beard to your level 😀
very cool. Have watched a few of your videos. Question: what software are you using to write/draw on screen when doing the videos?
I'm in a software engineering school right now. I think you just helped me affirm my major choice. Thanks lmao
Would that be Cyber Security? I'm curious what type of degree or work this can translate to. It peaked my interest and I'd like to do something career-wise that involves this! Just want to make sure I recognize the proper track and stay on it! :)
I love this "educational" content. You're the best
Nice. I had to break into a Windows system, once upon a time, when our vendor lost their password list for our site. Used the ol' "crash it over and over until it lets you boot into cmd/"DOS", replace the accessibility tools with a copy if cmd.exe, and manually modify the registry via the command prompt Windows launches instead of text-to-speech type stuff after a reboot" method.
Works, but is a replacement for existing passwords rather than a data pull, so it's super obvious after the fact.
You can actually do this without being logged in. If you exploit CMD to be open on the login screen, it still works if you replace something like accessibility with CMD with a windows repair drive or if you do it by holding shift plus restart and going into cmd
Love that T-shirt! I missed the affiliate link for that one :)
Hey man, please post videos frequently,
We miss you ❤
Great stuff as usual, I love your videos Chuck you are a great cybersecurity teacher and specialist. I enjoy your videos a lot and learn a lot from you. You are the best
@elenaalice4391 Thank you for the tip I'll definitely check them out
The way you approached my request in getting back my account added so much to it. It’s great to see how your unique perspective contributed to the outcome. The role you play on your job *Web back doors* is crucial. I really appreciate the constructive feedback you give to me regularly. Thank you for taking the time to work with me on this. It helped me get so much and also got my account back.
Love your videos!!! Quick side note/observation/comment and a pretty much rhetorical question, its not so much of a "hack" when having to disable firewall, add user and possibly enable RDP and disable restricted admin, is it?? I dont know you may have addressed that at the start of the video, your pretty thorough so i would assume that you mentioned that, which makes me ponder the fact that i am writing this right now, past the point of return!!!! Thanks for the hours of entertainment AND KNOWLEDGE (more importantly) you have provided!!
" He doesn't even know... What a sucker 😈"
*left with the command prompt open with all the command history*
One of your top coolest videos Chuck! I learned a lot :)
Fewer problems, more solutions - keep working like this and nothing will be able to stop you from reaching the top. Good job *Web back doors* , Even the smallest of jobs well done will take you one step closer to the success you have always dreamed about. Keep it up Mate
FYI, for domain users it's not the SAM hive but rather the SECURITY registry hive. The mistake that is often made is allowing end users to be local administrators on their endpoints within a domain. If an unknowingly system administrator then logs on to the PC with a domain administrator account or an account with local administrator on a domain member server, you're basically screwed if the endpoint is hacked. Even if the end user is not local admin, it's still really bad practice as there are other ways to elevate privileges depending on software used, Windows up-to-dateness etc.
Hey Chuck! Love your videos, they are super entertaining
Frankly I’m just concerned with what Michael is doing in the bathroom. That’s a long break 😂
who in the world would leave their computer ON without security where there is someone like chuck
Great video thanks for this really interesting video on hashs
"He doesnt even know" *leaves cmd on* XD all jokes aside this is good information and I will try it out on my system as well for fun. Thanks chuck :)
After some time, I managed to actually make an USB that when you put on a pc and run a file, gravs those saves files from reigstry, also does other stuff like get the user name, ect, (to get something to make the passwords list later), it's pretty insane how actually it's so easy, but also hard, to hack people
And before you say, yes, I tested it but I'm not using it to hack anyone else without him knowing.
Anyway, I love this video, and this channel!
Your work speaks volumes of the kind of man you are - efficient, organized and result-oriented. Well done MetaspyClub Best Social Media Expertise Within you is the absolute power to rise above any situation or struggle, and transform it into the strongest and the most beautiful version of you ever.
in one day i think i whatched all ur videos, good videos.
Years ago I used a Linux package called "chntpw" to forcibly reset the local Admin password on Windows machines. It's available in basically all Linux distributions and you just have to be able to mount the drive in question.
Right.. or just boot from a nix distro and copy the windows files ..
Anyone notice how Chuck left open the command prompt window with the commands in it on his employees computer? xD
The way I used to do it was my own way I had loads of netbooks from ebay that had xp and vista on them so I fired up kali linux live installed chntpw looked in system 32 files for configuration folder then looked for SAM files put in a few commands and I got full access to the hdd.
Is there a 100% Windows version (i.e., non-Linux) to do this? Love your energy!
03:58 you left the CMD window open for Michael to see
Oh no don't! Don't give me hope...
Chuck: "He doesn't even know"
Also Chuck: Leaves CMD window WITH COMANDS USED open and Saved files in folder.
Yea, noticed it.
Any advice would be appreciated, I did all the steps in your video but hash-cat keeps saying EXHAUSTED. I even changed my password to something super simple and even WROTE it on the .txt, still says exhausted. Please help?
Bro was fighting for his life in that toilet😂😭
leet mode is for leet text. Leet or 1337 is a way of writing used on the internet, in which the usual letters that are used to spell a word are replaced by numbers or special characters
could you get the files from outside the OS, for example a linux bootable drive, mounting the disk with the windows partition and grabbing the file. This is possible right?
Awesome video!
Few questions.
I hope Micheal staged this pass, and it is different from his common password(lol). 2, typically, on Windows, when you rdp, it kicks the logged-in user from the machine. Is Xrdp different?
It should not be different experience. The person on the PC is locked out.
next episode, Micheal suing NetworkChuck for emotional damage.
chuck: leaves terminal opened
chuck: he doesnt even know
plot twist: the cameraman was Michael himself
Awesome! Love your content. ❤
Thats incredible i love all your video ! Keep doing good content like this !🙂
I did kind of a same thing 15 years back using telnet. My gaming friends were freaked out. Back then I only knwe to clise their running programs and shutdown the windows with a message. But that was enough. :D
Noticed he left the terminal open and michael doesnt notices it? LOL:))
FYI, leet is short for leetspeak, where you substitute numbers for letters (leet=1337) It was popular last century in IRC chat.
Micheal was fighting demons in that toilet
Here is an easier way to OVERRIDE the password on any Windows OS.
Run cmd then type :
net user %username% *
Input the new password to whatever you wish ( even blank ) and thats it.
PS: as in video, you need access to an user account with admin priviledge.
Chuck, you showed great composure, impressive experiencea! Awesome...
Wow Secretdump is like the windows version of unshadow . Very cool !
3:58 Chuck leaves the command prompt open so the guy will know what has happened.
Rooky mistake.
I remember there was a live CD that could boot window computer and then use dictionary on those hashes. So you could basically make usb drive, take it to school computer class during the break when teacher was not there and get admin password to install some games.
He barely touched that coffee mug, call ambulance! Chuck is sick! 😂
Hey @NetworkChuck you should consider creating a tutorial on how to make a pssword manager on a usb stik that encrypts your passwords. So like when you put in a password there is a rule that states A = 123 for example. I keep trying to do this but I am confused lol
Dude just use a normal password manager like keepassxc or 1password
@@Cyhawkx thats not the usual way that (i) or possibly (other programmers) do it. it's pretty fun to do, imagine making your own little lab with your own password manager. it's not for storing passwords, its for fun :D wish you luck.
Normally system folders should have administrator protection and it is not that easy to copy those files but this is a good beginner example of how to crack windows passwords
Linux does that but it forces the user to input the account password every time which is not convenient.
Hey dude
Nice video! BTW don't forget to exit the command line window at 3:59
If it's Windows 10, you can do this MUCH more easily with a cmd trick lol 😂
What trick is that? Just curious
Love you MR.chuck thanks for your content ❤❤❤
I consider you *Web back doors* to be both a professional and mentor to those in your profession. I can always rely on your feedback and thoughts. I know that the door is always open for communication with you, which makes each process we work on together so much easier to complete. You are such an incredible problem-solver. Wow. Just wow.
this brings me closer to my villain arc with each video i watch lol
00:00 Hacking Michael's Windows password using hash cracking
01:27 Obtaining system registry hash via command line
02:58 Secure your passwords with Dashlane
04:49 Extracted NTLM hashes can be cracked using password guessing tools
06:18 Hackers use dictionary attacks to crack passwords in data breaches.
07:57 Successfully hacked into a Windows machine using a dictionary attack
09:30 Pass the hash attack allows access to Windows computer without password.
11:01 Disabling security features was necessary to detect registry keys and execute commands remotely.
Crafted by Merlin AI.
Underrated comment
Great video as always
really good explaining! You just got a like!!
Is it a good idea to use Kali Linux as my overall OS on my PC, or should I continue using VirtualBox?
You are such an inspiration to me ❤
great video just a small detail was missing during the explanation of the attack windows must have remote desktop and that it is activated for it to make the connection
just a question is this a local attack?
Micheal watching this be like: "I'm screwed"
Big shoot out to network Chuck for teaching me how to be an unethical hacker 😈
nice video as always!!
great video! so what about the wifi password . is that password you found just for windows?
Hey Chuck
can you tell us how to install PHP in kali linux in your next video?
btw I'm a huge fan of your videos and love your content.
are you doing this on the local machine or on a domain. I am assuming it is the local SAM of the desktop
Great video Chuck, but is this for local or microsoft account? or both?
But you left the cmd open on the way out with all the commands you've used... how he doesn't know as you said?
There are also some cheap pendrives that do all the work for you, you just plug it in for a short period of time and they do all the work. That’s why you want to use a different account as the administrator AND an hardware key (yubikey like)
May i ask which software ur using? I wanted to practice it but i couldn't find the software ur using
Thanks for the vid man :D
As you have said, you had to prepare a few things to get this “hacking method” to work. In a real world people use defaults, like RDP is not enabled, Windows Defender or any other security software is running. Means Windows is not better, worse compared to any other OS or software. All login systems use a similar way to store the needed hash value to check against the given password. All websites out there, where you sign up, the password gets stored in a DB with a hash value. What we should question, how easy it is to find out what it actually is.
This is amazing and I’m going to do something similar but use a rubber ducky and such. How would this would across different networks. Thinks a home firewall will stop you from connecting to a friends computer?
Great Video!
Quick and sweet
@NetworkChuck Might be a stupid question, but how do you copy/paste or transfer files onto kali linux, i can't for the life of me figure that out, it doesnt detect a USB or when I copy/paste from windows to kali. I'm running kali with TigerVNC on windows 11.
1:09 the simplest explanation of "what is hash"❤
Hi! I like your videos networkchuck and i dont miss any of them.
Can you make a video about how track location with phone number.
Hey i have a question why dont we jus get the hash and convert to password using a converter online insted od coding it is it possible?
Another mitigation would be to not use your administrator account by default. By using a general user account, Chuck would not have been able to create the hash file via CMD.
You left the cmd on. What if he saw it?
Cmd window with all the commands used... they'd definitely notice. He also forgot to delete the files he saved 😅 most "hackers" get caught because they forget to cover their tracks
That's crazy ASF that you can do that bro was literally watching bros screen from his computer 😂
Very impressive video again Chuck, is there anything like this for Apple os?
How to install every single tool that network chuck used in his videos and that probably will use in his kali linux videos:
First: make sure you have at least 10GB spare on your dev (1,2,3 and all the other that you and your system created) partition (not to be confused with the HOME partition, but if you selected the all files in one partition while installing, you shouldnt have to worry about this).
2: execute SUDO APT UPDATE -Y (-y stands for automatically allowing everything, basically you won't have to type y to agree with apt using you storage while running this specific process)
3: then SUDO APT FULL-UPGRADE -Y
3.5 (optional step): execute kali-tweaks if your system don't have the metapackage group installed yet
4: after you make sure it's completely update, do SUDO APT INSTALL KALI-LINUX-DEFAULT -y
5: then SUDO APT INSTALL KALI-LINUX-EVERYTHING -Y then go touch some grass because it's probably gonna take a considerable amount of time to completely install it
6: enjoy
Side note for new devs: do not execute those listed commands in capslock, do it normally, I simply wrote that way so people could diferenciate between regular text and the command itself
Just recently got hired as junior network engineer after passing ccna. My journey is still long ahead but networkchuck gave me this career interest path few years ago. Thank you chuck. Ok now to panic and keep studying.Bye
This so helped me a lot in my hacking journey Thank you so much 🙂🙂🙂🙂
An easier (and probably faster) way of extracting hash's from SAM would be to dump lsass (via something like task manager) and then parse through the dump.
Myself during this Bear Market only trying to focus on BTC, *VRI TOKEN* , ETH, SOL, MATIC. not losing sight of BNB and GALA. 🇨🇦