G-Prime wrote: their has to be some way to get access to the SAM file without direct access to the server.
there'd
better not be a good way to get domain passwords of a properly secured network, or I'm out of business. Domain passwords aren't stored in the sam file--actually we don't know where the heck they're stored. (finding out has become a group project here). Best guess is spread out over numerous files--google doesn't even know. filenames and number of them probably vary by situation.
The best way:
coordinated physical attack. The human element is always the weakest link in any network. wait for admin to go to the little boys/girls room, pray the door and system are unlocked (they will be) go into the directory of users and create an account with admin rights. Have a friend further distract him for best results. This only works if admin is on site--which they probably will not be in a school.
stupid ways I've thought of so far:
1) if he's left the old net command intact (
slightly likely) you could send the admin account a keylogger. I believe you can specify destination folder, but I also think he gets notice of it (requiring him to accept the file). at best he'll say yes
for a good laugh. (you'll have to know the computername, IP or username--and it probably isn't 'Administrator'). If dropped in startup folder it should send his keystrokes when he unlocks the machine (after reboot). my net command was neutered long ago, so I can't say for sure if this would work from where I'm at.
2) we were also tossing around the idea of using a rogue machine, as ethernet generally sends all signals everywhere (with tons of exceptions), and leaves individual OS to figure out what is what. However this is grandmaster level--we don't even know how possible it is. It would require a very 'special' machine. Also for password transmission, a great deal of handshaking and encryption are involved, and the key probably changes often and relates to the specific situation. Now it is possible since school networks will not have port security (like federal networks use), but I've never really heard of any tool that does this.
also this will not work if there's anything smarter than a hub between you--which there probably is (especially since he's likely offsite).
generally speaking, almost any other password is easier to get.