苹果MAC操作系统破解密码

来源:互联网 发布:mac mount samba 编辑:程序博客网 时间:2024/04/19 08:20
Crack Password Hashes in OS X Lion

This guide will NOT WORK with Mountain Lion 10.8. Please view our new, updated guide for Cracking Passwords in Mac OS X Mountain Lion

This guide is an updated version of our extremely popular guide, Decrypt OS X User Account Passwords. The guide has been updated to work with Lion 10.7.
Requirements

        Physical access to the machine.

If you need to crack passwords on Tiger, Leopard, or Snow Leopard, please use our tried-and-true Decrypt OS X User Account Passwords guide.
Procedure
1. Gain Root OR Admin Access

If you don’t have access to an administrator already, you need to acquire root access.

If you don’t have admin access, boot the computer into Single-User Mode by holding CMD+S on startup, mount the drive, and type the command:

开机启动时按 CMD+S ,进入命令行模式.

输入以下命令:

/sbin/mount -uw /

Followed by:

下一条命令:


launchctl load /System/Library/LaunchDaemons/com.apple.opendirectoryd.plist


And finally:
最后输入命令passwd,之后输入两次新密码,密码将被重置.
passwd


Then, enter your new root password when prompted twice. After the password has been reset, type:
输入以下命令重启电脑:
restart

And hit return/enter.
2. Log In

Log into an administrator account that you have access to on the computer, or, if you don’t have access to one, select “Other” in the Login Window (only if you have User Account Pictures enabled), and enter “root” as the username, and then the password that you just set.

用系统管理员登录,如果没有账号可以登录,请点击"Other",账号输入:root,密码输入前面重置的密码.

3. Download Utility
后面这一段是暴力破解密码,有兴趣者自我研究.
For 10.7, we’ll be using the DaveGrohl utility to both crack the password and extract the hash.

The utility works by extracting the hash from the User Profile, which is located in:

/private/var/db/dslocal/nodes/Default/users/.plist

Withreplaced with the name of the target user. It pulls the hash from the ‘ShadowHashData’ field and begins cracking.

NOTE: It appears that the usual download link isn’t working, so we’ve put up a mirror:

Download the DaveGrohl 10.7 cracking utility (MIRROR).
4. Open Up Terminal and Open the Directory

Once you’ve downloaded the utility, open up Terminal and type:

cd Downloads/DaveGrohl
5. Crack The Password

Type the following to begin cracking the password:

sudo ./dave -u

Replacing with the shortname of the target user and entering your password when prompted (it will not prompt you for a password if you’re logged into the root account).
That’s It!

DaveGrohl will begin cracking your password via wordlists and then continue with brute-forcing until it gets the password.

It can take quite a bit of time, depending on the complexity of the password, so be patient! Passwords we’ve cracked have ranged from a few seconds to several days.

When DaveGrohl has successfully cracked the hash, it’ll spit out a message like this:

-- Found password : 'banana'
-- (dictionary attack)

Finished in 0.772 seconds / 51,860 total guesses…
67,209 guesses per second.
5. Optional: Extract Hashes

If you only have a limited window of access to the target computer, DaveGrohl can give you the hash formatted for cracking in John The Ripper, so you can crack the password on a computer of your choice at your convenience. We cover how to use John in our other guide, so check that out if you’re interested.

To extract a correctly formatted hash, use this command:

sudo ./dave -j

Replacing with the target user’s shortname, and again, entering your password if prompted.

You can then copy and paste the output into a .txt file and load it into John.
Advanced Options

Here are a few advanced options that can be used when cracking passwords with DaveGrohl. Type:

sudo ./dave

before entering any of the following parameters.

-u username : Crack a user’s password.
-i : Incremental attack only.
-c chars : Specify possible characters in the password.
-m # : Specify minimum length of the password.
-M # : Specify maximum length of the password.
-v : Verbose mode. (hella slow)
-j username : Dump a user’s password hash formatted for John the Ripper.
-h : Help

Let us know in the comments if this worked for you!


其实对于Mac机,特别是MacBook来说,其组合键能构成相当丰富的功能。在这里编辑仅作为抛砖引玉,为大家介绍一些:
·启动时按住 C 键——从可启动 CD 或 DVD 光盘启动,如随机附带的 Mac OS X 安装光盘。
·启动时按住 D 键——如果插入1号安装盘,则启动为 Apple Hardware Test (AHT)。
·按住 Option-Command-P-R 键直至听到两声嘀嘀声——重置 NVRAM。
·启动时按住 Option(也就是Alt键) 键——启动进入 Startup Manager,您可以选择从一个
Mac OS X 宗卷启动。 注意:按住 N 键可显示出第一个可启动网络宗卷。
·按住 Eject、F12 键,或者按住鼠标键(/触控板)——推出所有移动介质,如光盘。
·启动时按住 N 键——试图从兼容的网络服务器(NetBoot)启动。
·启动时按住 T 键——启动为 FireWire 目标磁盘模式。
·启动时按住 Shift 键——启动为安全模式并且暂时关闭登录项。
·启动时按住 Command-V 键——启动为 Verbose 模式。
·启动时按住 Command-S 键——启动为单用户模式。
·启动时按住 Option-N 键——使用默认启动镜像从 NetBoot 服务器启动。

原创粉丝点击