Cracking Windows 95 Share Passwords

Reported January 9, 1998 by David Ross

Systems Affected

Networks using Windows 95 clients and Peer networking

Description

It is possible to crack the share passwords on Windows 95 systems.

The passwords are found in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Network\LanMan

Within the data for each share are two registry entries: Parm1enc and Parm2enc.
Parm1enc is the "Full access" password, while Parm2enc is the "Read only" password.

Demonstration Code:

Download the SHAREPW.C file, or download the EXECUTABLE if you prefer.

Microsoft's Response:

Unknown at this time

To learn more about new NT security concerns, subscribe to NTSD.

Credit:
Reported by: David Ross
Posted here at NTSecurity.Net February 15, 1997