We are in the process of attempting to enforce "complex passwords" on our domain.
It's a long history as to why we don't already - suffice to say high management see them as a "pain" rather than a level of security we should embrace.
I want to "hack" our own AD and attempt to get a list of our user's passwords - to show management just how easy some of these passwords would be to brute force or guess.
Back in the day you could extract the SAM and run a free brute force program on it.
What would the process be these days - what tools are there out there?
This is now a Server 2008 R2 domain and I want to achieve the same result - a list of my user's passwords.
I know this could be seen as a "dodgy" request.
All I can say is this is for our own internal information - there is nothing "dodgy" going on here at all.
It's a long history as to why we don't already - suffice to say high management see them as a "pain" rather than a level of security we should embrace.
I want to "hack" our own AD and attempt to get a list of our user's passwords - to show management just how easy some of these passwords would be to brute force or guess.
Back in the day you could extract the SAM and run a free brute force program on it.
What would the process be these days - what tools are there out there?
This is now a Server 2008 R2 domain and I want to achieve the same result - a list of my user's passwords.
I know this could be seen as a "dodgy" request.
All I can say is this is for our own internal information - there is nothing "dodgy" going on here at all.