LM hashes in Windows 2008 or above

Windows 2008 or above disables to store LM hashes in SAM. They can't be retrieved using password dumper programs. To enable this feature, set "Network security: Do not store LAN Manager hash" to "Disabled" under Local Policies → Security. Optionally, adjust "Network security: LAN Manager authentication level" to accept and/or send LM in addition to NTLM. (Note that this is very insecure and must be reverted after tests.)

and please note that enabling via Group Policy applies only after setting a new password, you can't change the existing password to a weak one.

ref: http://hi.baidu.com/51cmdshell/blog/item/fe9271eb41ed87dad539c932.html
ref: http://superuser.com/questions/340208/enabling-lm-hash-in-windows-7

Password dumpers
ref: http://www.tarasco.org/security/pwdump_7/
ref: http://www.foofus.net/~fizzgig/pwdump/

Comments

Popular posts from this blog

Save Settings for TeamViewer Portable

cos(π/9)*cos(2π/9)*cos(3π/9)*cos(4π/9)

Windows 7 / Windows Search 4 does NOT support UNC network location indexing