Download pwdump 1.4.2 and fgdump 1.3.4 – Windows Password Dumping

Use Netsparker


New versions of the ultracool tools pwdump (1.4.2) and fgdump (1.3.4) have been released.

Both versions provide some feature upgrades as well as bug fixes. Folks with really old versions of either program should definitely look at upgrading since there are numerous performance improvements and full multithreading capabilities in both packages.

Download pwdump 1.4.2 and fgdump 1.3.4 - Windows Password Dumping


If you don’t know..what are pwdump6 and fgdump?

pwdump6 is a password hash dumper for Windows 2000 and later systems. It is capable of dumping LanMan and NTLM hashes as well as password hash histories. It is based on pwdump3e, and should be stable on XP SP2 and 2K3. If you have had LSASS crash on you using older tools, this should fix that.

fgdump is a more powerful version of pwdump6. pwdump tends to hang and such when antivirus is present, so fgdump takes care of that by shutting down and later restarting a number of AV programs. It also can dump cached credentials and protected storage items and can be run in a multithreaded fashion very easily. I strongly recommend using fgdump, especially given that fgdump uses pwdump6 under the hood! You’ll get everything pwdump6 gives you and a lot more.

Darknet definitely DOES recommend fgdump, super cool update of the old favourite pwdump.

fgdump was born out of frustration with current antivirus (AV) vendors who only partially handled execution of programs like pwdump. Certain vendors’ solutions would sometimes allow pwdump to run, sometimes not, and sometimes lock up the box. As such, we as security engineers had to remember to shut off antivirus before running pwdump and similar utilities like cachedump. Needless to say, we’re forgetful sometimes…


So fgdump started as simply a wrapper around things we had to do to make pwdump work effectively. Later, cachedump was added to the mix, as were a couple other variations of AV. Over time it has grown, and continues to grow, to support our assessments and other projects. We are beginning to use it extensively within Windows domains for broad password auditing, and in conjunction with other tools (ownr and pwdumpToMatrix.pl) for discovering implied trust relationships.

What is fgdump for?

fgdump is targetted at the security auditing community, and is designed to be used for good, not evil. :) Note that, in order to effectively use fgdump, you’re going to need high-power credentials (Administrator or Domain Administrator, in most cases), thus limiting its usefulness as a hacking tool. However, hopefully some of you other security folks will find this helpful.

You can download pwdump here:

pwdump6 2.0.0-beta no source

Or read more here.

And you can download fgdump here:

fgdump 2.1.0 no source

Or read more here.

Posted in: Hacking Tools, Password Cracking

,


Latest Posts:


Acunetix v12 - Pause & Resume Acunetix v12 – More Comprehensive More Accurate & 2x Faster
Acunetix, the pioneer in automated web application security software, has announced the release of Acunetix v12 - more comprehensive, accurate & 2x faster.
CloudFrunt - Identify Misconfigured CloudFront Domains CloudFrunt – Identify Misconfigured CloudFront Domains
CloudFrunt is a Python-based tool for identifying misconfigured CloudFront domains, it uses DNS and looks for CNAMEs which may be allowed to be associated with CloudFront distributions.
Airbash - Fully Automated WPA PSK Handshake Capture Script Airbash – Fully Automated WPA PSK Handshake Capture Script
Airbash is a POSIX-compliant, fully automated WPA PSK handshake capture script aimed at penetration testing, it is compatible with Bash and Android Shell.
XXEinjector - Automatic XXE Injection Tool For Exploitation XXEinjector – Automatic XXE Injection Tool For Exploitation
XXEinjector is an XXE Injection Tool that automates retrieving files using direct and out of band methods. Directory listing only works in Java applications.
Yahoo! Fined 35 Million USD For Late Disclosure Of Hack Yahoo! Fined 35 Million USD For Late Disclosure Of Hack
Ah Yahoo! in trouble again, this time the news is Yahoo! fined for 35 million USD by the SEC for the 2 year delayed disclosure of the massive hack, we actually reported on the incident in 2016 when it became public.
Drupwn - Drupal Enumeration Tool & Security Scanner Drupwn – Drupal Enumeration Tool & Security Scanner
Drupwn is a Python-based Drupal Enumeration Tool that also includes an exploit mode, which can check for and exploit relevant CVEs.


7 Responses to Download pwdump 1.4.2 and fgdump 1.3.4 – Windows Password Dumping

  1. qsin October 31, 2006 at 5:06 am #

    i lost my admin password for my pc standalone win xp..please i need help to recover my password or clear or reset…if there is a good software or advice on this i would really appreciate ..

  2. Vlarol November 13, 2006 at 6:14 am #

    2qsin
    See a nice tool at
    http://home.eunet.no/pnordahl/ntpasswd/

  3. r4v3n December 13, 2006 at 12:10 am #

    Cool, but when is there a 64-bit version available? I haven’t been able to extract any hashes from Windows 2003 x64 so far. Is that a safe system or am I just missing the right auditing tools?

  4. Darknet December 13, 2006 at 2:40 am #

    r4v3n: I suggest you download the pwdump2 source code and compile it for 64 bit architecture (It’s not too hard to find). Good luck :)

  5. Peter December 13, 2006 at 9:02 am #

    Does anyone understand these instructions on how to use it? I dont…. Could anyone please help me? I would love to try it try it out on my brothers pc… :p
    I have pwdump 4 and 6. If anyone could help me out it would be great

    thx in advance,
    Peter

  6. School Hacker March 4, 2009 at 8:20 pm #

    Mwahahahahahahahaha!

  7. zaman June 3, 2009 at 6:36 am #

    it true