SteelToe Posted September 11, 2016 Share Posted September 11, 2016 Hey everyone. VERY new to the Rubber Ducky and am enjoying it. What is the best way to read the SAM file that saved to a report from Ducky? Like I said I am new here so please be kind :) Quote Link to comment Share on other sites More sharing options...
SteelToe Posted September 11, 2016 Author Share Posted September 11, 2016 So title says it all. First Script I have used extracts SAM for credentials. What program do I use to open this? thanks all! Quote Link to comment Share on other sites More sharing options...
Cyclo Posted September 12, 2016 Share Posted September 12, 2016 http://ophcrack.sourceforge.net/ Quote Link to comment Share on other sites More sharing options...
Mr-Protocol Posted September 12, 2016 Share Posted September 12, 2016 You will also need the SYSTEM registry file. I would recommend hashcat. Quote Link to comment Share on other sites More sharing options...
SteelToe Posted September 12, 2016 Author Share Posted September 12, 2016 Thanks guys! That is what I was figuring. Work still needed :) I played with the mimikatz tool but it returned null for all PWs :/ Quote Link to comment Share on other sites More sharing options...
Mr-Protocol Posted September 12, 2016 Share Posted September 12, 2016 Another note, if they use Windows Live login. The credentials are not stored in the SAM. Quote Link to comment Share on other sites More sharing options...
Mr-Protocol Posted September 14, 2016 Share Posted September 14, 2016 In regards to a tool to open the SAM file, you will need a program that can read Windows registry files. Quote Link to comment Share on other sites More sharing options...
SteelToe Posted September 15, 2016 Author Share Posted September 15, 2016 Thanks all for the direction. I have also successfully flashed with Twin Duck firm ware so it is also recognized as mass storage device. Anyone have a good tutorial for step by step to get Mimicatz pulling passwords on a Ducky script? I have mimikatz on my pc and attempted to run but on my windows 10 pc it only pulls Null for passwords. Quote Link to comment Share on other sites More sharing options...
Mr-Protocol Posted September 15, 2016 Share Posted September 15, 2016 https://www.hak5.org/episodes/season-21/hak5-2101-15-second-password-hack-mr-robot-style Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.