Have you ever tried to log into a Windows computer for a few minutes and you finally realize that you forgot the password?
There’s a way to crack the password and it doesn’t involve reformatting and reinstalling Windows.
The solution is called @stake LC4 (formerly L0phtCrack), however since Symantec stopped development of L0phtcrack, I’m going to let you in on a program called LC5.
Just like L0phtCrack, LC5 attacks your Windows machine with a combination of dictionary and brute force attacks.
LC5 can crack almost all common passwords in seconds. More advanced passwords with numbers and characters takes longer.
The main purpose of the LCP program is user account passwords auditing and recovery in Windows NT/2000/XP.
I haven’t tested it against Windows Vista yet, so I’m not sure if it will work. Your mileage may very either way.
How it works:
Windows NT, 2000 and XP passwords are stored as encrypted hashes. LC5 attacks these hashes with hundreds of passwords per minute.
Eventually the correct password will be sent and then displayed to the screen.
Good intentions:
- System administrators can find weak passwords within minutes. Sys admins can then change the passwords to make them more secure.
- LC5 can be used to access computers of users who forget passwords.
- In companies, it can be used to access computers of employees who have left the company.
Bad intentions:
- Hackers can use LC5 to sniff passwords over networks.
- Hackers can install this application onto a primary domain controller and steal hundreds of passwords within minutes.
Please note that I am not the author of this software. Be advised that if you use this software, you do so at your own risk without any warranty expresses or implied by Geek With Laptop.
Download LC5 (v5.04):
- English version (with installer) - 2.29 MB
- English version (without installer, ZIP) - 1.86 MB
- English version (without installer, RAR) - 1.66 MB
Software License: LCP is a freeware program. The program may be distributed under condition of saving all files contents and structure of installation package.









August 20th, 2008
44 Comments at "Crack Windows Passwords"
Interesting article. When I used to work in a large advertising agency the staff were often shocked when they found out that the IT staff could easily hack their passwords. They seemed to think they owned all the info on the company owned computers that they used.
This sounds pretty interesting. We used a similar software at my tech support job a few years ago. It is funny how people never consider that their computers aren’t as secure as they think they are!
Thanks! I’ve been searching Google for a while now, trying to find direct downloads of an LC5 trial.
However, the program you provided isn’t actually LC5. It’s similar to LC5, but it isn’t from @stake (now part of Symantec). I think the proper name for it is LCP or LCP 5.04. Nevertheless, I want to thank you for introducing me to this FREE program. It’s definitely better than the last version of LC that @stake created.
This post rocks!
[...] dairytis priemonių, radau Geek with Laptop rašinį apie LC5, kuri kilo iš anksčiau mano naudotos L0phtCrack. LC5, kaip ir daugelis tokių programų, [...]
Simpler solution is ERD 2000, boots up on a cd rom, one click password reset from outside of windows, no need to “crack” the password, which can take a while if it’s a complex one. We use it at work all the time, takes .25 seconds
I’m guessing the above method is just for XP Professional, most XP Home editions are very easy to ‘un-lock’ as I’ve found, (I repair PC’s as a part time job and I found this method when a person who shall not be named forgot their login password)
As many of you will probably know, the Administrator account will not appear on the Login screen of XP Home, and most (non-technically orientated) users will not even be aware it exists, but when loading the computer, if you enter safe mode (By pressing F8 during startup), the Administrators account appears on the login list, you can then easily log into this account (It will usually not have a password), when logged in go into Control Panel, and then users. Once in here click ‘Change Password’ for the user that is ‘locked-out’. If you leave all the fields blank and hit ‘Ok’ then it will remove the password and allow the user back in again.
Again this may be ’staring-you-in-the-face’ kind of obvious for most users, I just havn’t seen this method posted anywhere before, thought I’d share
[...] [via:geekwithlaptop] Social Bookmarking (Digg, Delicious, Reddit, StumbleUpon…) Doesn’t want to miss latest tips? Subscribe Full Feed Here Related Posts:Password Generator and Checker SecurePassword.info [...]
Can I use this safely on my computer, if I’m the only one who knows about it? Do I have to worry about hackers on the Net?
Matt says: “Simpler solution is ERD 2000, boots up on a cd rom, one click password reset from outside of windows, no need to “crack” the password, which can take a while if it’s a complex one. We use it at work all the time, takes .25 seconds”
Matt, if anybody has encrypted data on their computer using windows security, you just made recovering it a task that would take a team at the NSA an entire week to accomplish. Just FYI.
That’s cool, thanks. Im going to make up the insane-est, hardest password ever just too see how long it takes to crack. Got an over-under on it?
An even simpler solution, that is FREE and open (unlike ERD) is:
Offline NT Password and Registry Editor , located here:
http://home.eunet.no/pnordahl/ntpasswd/
Bootable (live) image, removes Administrator password. Works like a charm.
Note: If the user has used the Encrypted File System (EFS) you won’t be able to read those files, but should be able to login as them with no problem at all.
ERD blows if you’re trying to maintain an anonymous profile. i’ve spent some time messing around with ophtcrack and it is awesome just do a google search for it. i used it during my last password audit of my organization.
Would it be easier to use knoppix to access the pc content as long the bios is open to run the live cd?
Hash “marks”? You mean like “######”? Wrong kind of hash…
This doesn’t work with Vista. Win NT/2000/XP by default used the weak LM hash for compatability in conjunction with the strong NTLM hash - which is much harder to crack. Vista uses only the NTLM v2 hash. Its crackable but I doubt you want to sit around and wait for it.
McAfee throws up a big flag on installation of this program
Oh can anybody please tell me how can I use this tool to recover passwords of other computers on my network? Thanks
[...] Windows Passwords: Cracked [...]
[...] read more | digg story [...]
Very good find. Thanks for sharing this useful piece of software.
[...] solution is called @stake LC4 (formerly L0phtCrack), however since Symantec stopped development of L0phtcrack, I’m going to let you in on a program called [...]
About the no-password Administrator account:
You don´t have to enter safe mode; is you press Ctrl+Alt+Del, release and press again Del (Ctrl+Alt still pressed) at the normal mode login screen, it takes you to the Windows 2000-like login screen, there you can type in Administrator and leave the password blank… Easier, is it not?
[...] LC5 - Windows password cracker link [...]
#13 When you bruteforce you don’t care about the encryption
“McAfee throws up a big flag on installation of this program”
Vlad: McAfee is detecting the samdump.dll file which is used to dump the user password hashes. The file could be used maliciously, but not in this case.
[...] read more | digg story [...]
OPHCrack is a Diagnostic tool I use regularly for cracking windows passwords, it’s a linux bootcd that uses a similar cracking method as LCP. I like OPHCrack because it cracks most Windows OSs (2000/XP/Vista/etc..). Also because it’s not changing anything it doesn’t lock you out of your encrypted files. Usually only takes a couple minutes to crack and it lets you remove doesn’t have to deal with windows at all.
Try it, I think you’ll like it…
-Audrais
[...] Link: Geek With Laptop [...]
It should work on vista too because the SAM file is still in c:\windows\system32\config\SAM and its still the same encryption.
I downloaded LC5 and works great. How do i use it to crack a password on a computer when I am not logged in on that computer?
Thanks for the tool
Hi I’m trying to crack a window vista password.i used ophcrack and i got this : JR:1003:aad3b435b51404eeaad3b435b51404ee:37c088d8d1e18c245c25483c5fd5314d/empty/:
But i cant crack it.Shouldnt be a long passwrd but maybe got some number.i used cain&abel and johntheripper but nothing.is it possible can be uncrackable?
I’m Just wanna ask if i could do this on a school computer?
i’ve used the ophcrack on 2 computers and it did not work, got error saying could find executable rhcommand. so if i download the lc5 do i have to burn it to a disc or how does it work?? i have my 15 year old daughters computer i want to check without her knowing it. but i can’t login into it she has a user password on it??
What if the computer has the administrative passworded in safe mode? Am I out of luck? Please help. Thanks
I’ve tried to crack the NThash password on windows vista using ophcrack. Does anyone know how to make it work? I’ve forgotten my password, right now im trying everything, even making boot disks to try to overwrite it.
i have been a comp with an admin password, but the passwork won,t login anymore (just switched on the machine and the same password won,t login) how do i reset or recover password from a non admin account - which cannot allow me to install any programs
Could any one help with product key for Microsoft Office 2007.
hey,
i love the post.
but how do i use the program?
i dont see any image anywhere to put on a cd,, and i downloaded and installed the program..
You guys are mostly all morons.
LCP works great.
The only problem is if you trying to find a admin password from another pc than the one LCP is installed on.
To do that you have to copy the SAM and SYSTEM file from the other pc.
To do so I boot the other pc with a Linux boot disk which gives you total access to all files on the drive. Copy SAM and SYSTEM to a USB drive and then go the pc with LCP on it and crack away.
Took about 5 minutes to find the admin account username and password on a work pc joined to a domain.
Can any one help me with cracking a password for Windows Vista?
OK my parents changed my password, which is really annoying, and I’m trying to get it back. My computer is Win XP and I tried the ctrl+alt+del+del thing but it says it can’t do it because of ‘account restrictions’. For some reason the downloads aren’t working, either.
Can anyone help?
PS: to the mom trying to look at her kid’s computer, LEAVE IT. I felt like smashing my mom when she invaded mine.
LCP works fine, and yes most of these posts are moronic. Like Tasha - so you don’t like your parents controlling things that are their responsibility (like you)? What about the computer they probably bought for you? that you use with the electricity they pay for? that’s in the house that they provide you?
Play by their rules, or move out when old enough. Else shut up and quit crying.
By your argument, the governments should have full control over the people they are responsible for. And we know how well, historically, totalitarian governments have fared (and how well they’ve been liked).
There’s a difference between controlling and being responsible for.
Although this isn’t really the proper place for that kind of discussion. This is a forum for computer problems, not criticizing others’ opinions. So tell me how to get around this, or, um, shut up.
Comment Now!