| I l@ve RuBoard |
URL: www.confine.com/programs/Cain151.zip
Client OS: Windows 95/98
Target OS: Windows 95/98
Price: Free
Description: On Windows 9x systems using local authentication, passwords are stored in a .pwl file in the Windows directory. Cain uses dictionary, hybrid, and brute force attacks to crack these passwords. To use Cain, you must have physical access to the target system.
Use: First, you need to gain physical access to the target Windows 9x system. Then log into the system by pressing Esc. Next, copy the .pwl files to disk. Load the .pwl file into Cain with a large dictionary and start it cracking. It is a very fast tool, attempting approximately 5,000 tries per second. Figure 15-4 contains sample output from Cain.

Benefits: Cain is an easy and very fast password cracker for Windows 9x systems. Many of the passwords stored in an organization's Windows 9x system probably work on other systems in the organization.
Con: You need to obtain physical access to the system and copy the .pwl file off onto disk.
| I l@ve RuBoard |