Cain and Abel: Windows password recovery utility

posted Sep 10th 2009 6:00am by
filed under: downloads hacks

cain

As far as password recovery utilities go, Cain & Abel is by far one of the best out there. It’s designed to run on Microsoft Windows 2000/XP/Vista but has methods to recover passwords for other systems. It is able to find passwords in the local cache, decode scrambled passwords, find wireless network keys or use brute-force and dictionary attacks. For recovering passwords on other systems Cain & Abel has the ability to sniff the local network for passwords transmitted via HTTP/HTTPS, POP3, IMAP, SMTP and much more. We think it is quite possibly one of the best utilities to have as a system administrator, and definitely a must have for your toolbox.



66 Responses to Cain and Abel: Windows password recovery utility

  • Erik says:

    I think it’s a great application, however my virus scanner goes berserk every time I run it, which means I have to turn it off and that’s something I don’t like.

  • Thedudefrommiamivice says:

    I feel like 1998 just punched me in the face.

  • Caleb Kraft says:

    @Thedudefrommiamivice,
    I shouldn’t encourage you, but I almost shot coffee out of my nose when I read your comment.

  • Franklyn says:

    @Thedudefrommiamivice

    I get that feeling every time i look at the site.I guess thats just what its all about.

  • YAAAAYYYYYY

    That’s what i’m calling news ;)
    Erm no okay. I know there are people out there who dont know software like this even if it’s old.

    New serious people: Use this as a !password recovery tool!

    Other new people: If u are teh 1337 h4x0r then u5 d4 t001 4nd u w!11 b3 d4 k!n6 0f 411 1337 h4x0rx!!! !mpre55 411 ur m473s with d0!n6 n0th!n 8u7 4 c1!ck.

    Yeehaw ;)

  • Tomasito says:

    Now at hackaday, discover the newest password cracking tool called “John The Ripper”.

  • Bob says:

    Don’t forget, some of the easiest to use arp spoofing tools for sniffing traffic on switched networks…

    You might want to be careful leaving this lying around on your work laptop. It is most certainly a hacking tool. If anything exciting goes down and they find this on your laptop, fingers may be pointed.

  • nebulous says:

    Since this story is pretty good to make a general statement… there are capital letters here. Awesome! When did that happen?

  • Jim says:

    I’ve used this tools when Abel was still a RAT. Ahh the good old days. The comments on how old it is made me LOL.

  • Akoi Meexx says:

    Stealthmonkey, the leet…. it buuuuurns us!
    But seriously, when did HaD-9000 start doing retro posts?

  • Decius says:

    @Thedudefrommiamivice

    HA! That made my morning :)

    Nether the less it’s still a better program than the one I was currently using :P

  • Tim says:

    Horray! Behold my correctly capitalised prose. Tremble in fear as ambiguous cases are crushed beneath my might shift key.

    :-)

  • rbz says:

    i dont get it. its been available for years, why now?

  • redbeard says:

    @Thedudefrommiamivice & @Decius

    For real. I mean, I remember fucking around with this nigh on a decade ago. I’m too lazy to click on the link. Please tell me there is at least a new release and not just providing fodder for script kiddies too lazy to google this.

  • Eddie says:

    It does not say how i run this on my arduino?

  • bb says:

    oooh, oooh, I’m soo cool. I’m soo cooler than everyone else. Like. So. Totally. Like. Awesome. Yah, haww! I mean. For real. Ya know?

  • Alan says:

    Yes. Awesome.
    This is the same program I used in 10th grade to crack my teacher’s passwords on the NT box’s they logged into.
    I remember laughing when my English teacher’s password was ‘book’
    Great program.
    I’m happy to see its still being updated after all this time.

    I think a google search would have been more appropriate than an article on hackaday.com .

  • zetsway says:

    What’s up with all the crappy comments. Yeah, it may not be the newest tool to use but for new ppl I think it’s good.

  • Sharky says:

    I love this stuff. I have a couple of master keys and some bump keys. Being able to enter almost any room makes you feel so empowered. So does this program.

    Now remember: With great power comes great responsibility.

  • monkeyslayer56 says:

    @stealthmonkey
    should i be worryed if i can read the lower part of your post….

    also ophcrack is a good windows password cracking utility….

  • the_twiz says:

    Back Orifice 2000 FTW

  • O Mattos says:

    If you want an easy-to-use version of this for login passwords, try this:

    http://www.loginrecovery.com/

    It’s basicly the same, but is all automated, and will work much faster than C&A on a single computer. As an added bonus, you don’t have to download large liveCD’s or fiddle with moving a hard disk to another computer to get the password from it.

    Downside is it costs $$$, but you get what you pay for.

  • r3nrut says:

    It’s old but it works and is still maintained. Whatever became of their client for Windows Mobile?

  • overslacked says:

    @zetsway – Until a certain level of brain development, children believe any knowledge they have, everyone else also has. The dissonance introduced to such an immature system, when exposed to information they’ve already received but is presented as news, causes all higher-level cerebral function to halt completely, resulting in the comments you observed.

  • Thedudefrommiamivice says:

    @overslacked:
    Main Entry: news
    Pronunciation: \ˈnüz, ˈnyüz\
    Function: noun plural but singular in construction
    Usage: often attributive
    Date: 15th century

    1 a : a report of recent events b : previously unknown information c : something having a specified influence or effect
    2 a : material reported in a newspaper or news periodical or on a newscast b : matter that is newsworthy

    C&A hardly meets the definition. Or should the users of this site stand by and allow the site to delve into mediocrity, maybe its already there. I was under the impression this site was for hackers. Not sure about you but wouldn’t a hacker be in possesion of even the most basic of skills such as using google. Now if cain and able had a feature added to it that allowed it to do something new and impressive then I would be all for the post but it doesn’t.

    Hey guys we added wep cracking…… what do you mean the simpsons have already done it?

  • Thedudefrommiamivice says:

    Oh and if the site was continually cluttered with information that someone new to the “scene” didn’t know it would become pretty pointless. There is always going to be people who don’t know about , thats why search engines exist. Give me something new, something that hasn’t been seen before, I dunno maybe a hack. What an odd concept eh?

  • John says:

    @Thedudefrommiamivice

    you sir made my evening

  • cyberpunk64bit says:

    this is by far the greatest program! i have used it for years!!

  • frolix says:

    i believe the reason antivirus apps flag c&a is because part of the installation provides a back door to other c&a users on the network. hence the name. a tool that also betrays you…
    i used to have a little batch script that would move the offending file out of the system folder and back again. i think it was a .dll, can’t remember cause its been years ha

  • jake says:

    this is now on here epic fail this prog is OLLLLDDDD

  • juicy jim says:

    i have known about this for a few years lol…but its still a decent program

  • OrderZero says:

    SO I JUST FOUND THIS NEW INVENTION ITS CALLED THE NINTENDO ENTERTAINMENT SYSTEM I CANT WAIT TO PLAY PONG ON ITS EPIC GAME CARTRIDGES!

  • zetsway says:

    @Thedudefrommiamivice

    I agree with what you saying but there is no need to dis the site. Maybe HAD just found out about C&A. Who knows??

    Maybe if ppl stop complaining about articles on arduino we wouldn’t have articles like this.

    Just saying…..

  • Jordan says:

    HaHaHa Back in high school I had this on a floppy disk……

  • rmf says:

    Yeah, this is very retro. It’s probably worth noting that l0phtcrack 6 is also available for password cracking^W “recover.” And that actually IS new and updated software. Though it doesn’t have the handy dandy MITM features Cain does, it’s better.
    LC6. Better. Srsly.

  • therealnewbe says:

    Jebas hackaday… The site is called “Hackaday” not, “it was a slow news day so here’s a write up on a program that even me, without hardly a clue in the world about password cracking, heard about YEARS ago.”

    I used to defend this site from the nay-sayers who would claim this site is going down the tubes, but my god I was wrong… RIP Hackaday I knew and loved. Welcome shitty engadet clone…

    Sad sad stuff, and just after eliot left too

  • yuppicide says:

    I wouldn’t touch this. Virus scanner seems to go crazy. I also have no way to bypass the virus scanner. It’s on a server that I don’t have access to.

  • drewg says:

    Well, since the “Abel” component is essentially a backdoor service, I wouldn’t be surprised that antivirus programs flag it.

  • Damn says:

    I have installed it on my arduino, great program.

  • fuckyou says:

    YUP if you remove the able.exe from the directory youre virus scanner schould be content,

    P.S.
    Youre chery list is tires old hacker bullshit

  • James says:

    @rmf C&A actually is updated as well, he releases updates almost monthly.

    As far as people being unhappy about seeing hacking “non-news”, maybe hackaday needs to add some content silently, so that it doesn’t show up on the main page, but so that it shows up on the appropriate category.

  • Muu haa haaaaa my wonderful toys :) i love them so because the data tells me so

  • draeath says:

    I never was able to get ARP poisoning to work. It just did… nothing. Every time I tried.

  • signal7 says:

    if you think system admins actually need this utility, that is an epic fail because a system admin you are not. this tool has only one use and it’s not an honest use in any sense of the word.

    i’ve been a sysadmin for over 10 years and i’ve never needed a password recovery tool. if you need to recover data, there’s a lot of tools for that that don’t require hacking the system. if you’re user loses their password, just reset it on the domain and be done with it. if you don’t have a domain, reinstall (no whining about how much easier is to use this tool to compromise your system – security takes precedence over convenience). it’s not the end of the world, people.

  • Brett Haddock says:

    A few years back I was contracted by a company who fired their admin and he had locked everything down really tightly. Reinstalling everything wasn’t an option as there was a ton of data that needed to be saved (and backups were locked on the servers as well). Using this and a couple other tools helped break everything to save the data, after which the systems were wiped clean.

  • yknalb says:

    So does this mean I can finally recover the passwords to my old porn archives?

  • Linky Wu says:

    Long time ago , I was confronted with the password problem. Finally , my friend Jane introduce the Windows password Reset.It helps me access windows. http://www.resetwindowspassword.com

  • happykaka says:

    Compare to many password recovery solutions. Windows password unlocker is highly recommended.
    1.Download Windows Password Unlocker from Password Unlocker Official site http://sn.im/wpu
    2.Decompress the Windows password unlocker and note that there is an .ISO image file. Burn the image file onto an blank CD with the burner freely supported by Password Unlocker.
    3.Insert the newly created CD into the locked computer and re-boot it from the CD drive.
    4.After launched the CD, a window pop up with all your account names(if you have several accounts); select one of the accounts that you have forgotten its password to reset it. Just one press, you have removed the password.

  • xtremegamer says:

    what about kon-boot ?

    http://www.piotrbania.com/all/kon-boot/

    you can load it up on to USB stick.

    login as adminstrator , sniff around.

    admin has the blame ^_^

    also usefull if you forgot your password :)

  • mlc says:

    About that antivirus thing…
    of course antivirus will go mad- firstly it have abel inside- trojan, working for you…
    but it is still troyan…
    antivirus wont wait until trojan gonna start his job… scan code and alert…

    and no, you dont need to turn off antivirus (except when installing).
    simply add to exception list.

  • cvs26 says:

    100% FREE Windows Password Cracking in minutes.

    Watch a live DEMO & Download the software here…

    http://cvs26.wordpress.com/2009/12/22/100-windows-xp-vista-7-password-recovery/

  • Chris says:

    You can reset windows user account password in safe mode(F8 when booting up). But if you forgot administrator password, you must reinstall windows OS or use windows password recovery disk. http://www.windowsloginrecovery.com

  • I have installed it on my arduino, great program.

  • Davi says:

    There are a lot of tools and utilities that can be downloaded and used to recover, reset, retrieve or reveal existing password. These windows password recovery utilities, free or paid, are usually a Linux boot disk or CD that able to comes with NT file system (NTFS) drivers and software that will read the registry and rewrite the password hashes, or can brute force crack the password for any user account including the Administrators. The advantage is that there is no fear of leaking your password to outsiders, while the process requires physical access to the console and a floppy or CD drive, depending on which tool you choose. And it’s not easy, although it always work!
    Below is the most famous recovery tool I found:
    Windows Password Recovery Tool 3.0 – it is the most popular Windows password cracker . It is a very efficient implementation of windows any versions. It comes with a Graphical User Interface and runs on multiple platforms.

    Password Recovery Bundle –This is a utility to reset the password of any user that has a valid (local) account on your windows system. You do not need to know the old password to set a new one. It works offline, that is, you have to shutdown your computer and boot off a floppydisk or CD. It’ll detect and offer to unlock locked or disabled out user accounts. It is also an almost fully functional registry editor.

    Windows Password Key 8.0 -It is considered as the best tool to reset local administrator and user passwords on any Windows system. It creates a password recovery CD/DVD, USB Flash Drive for home, business and enterprise. And most of all, it’s the most popular and safe solution for removing your Windows password until now.

  • killytu says:

    Some days ago, i just got a windows password recovery tool http://www.anypasswordrecovery.com/ which can bypass windows password easily,and it can be burnt onto a cd as recovery disk.If you need,then get it.

  • I perfer to use Password Recovery Bundle 2010:http://www.top-password.com/password-recovery-bundle.html, it is very simple yet useful, it is able to recover many programs passwords.

  • Josue Bautista says:

    Whit this software can I get tthe radio unlock code hidden into the eeprom by dunp?

  • Last time I forgot my password and tried everything i could do but failed, until I found this great tool Password Genius. It works great, and you can google it.you can try to google it.

  • reset windows password says:

    Here are the methods I know.

    The first thing which you check if you forget login password. When we install Windows, it automatically creates an account “Administrator” and sets its password to blank. So if

    you have forget Your user account password then try this:
    Start system and when you See Windows Welcome screen / Login screen, press ctrl+alt+del keys Twice and it’ll show Classic Login box. Now type “Administrator” (without quotes) in

    Username and leave Password field blank. Now press Enter and you should be able to log in Windows.
    Now you can reset your account password from “Control Panel -> User Accounts”.
    Same thing can be done using Safe Mode. In Safe Mode Windows will show this in-built Administrator account in Login screen.

    Windows XP and further versions also provide another method to recover forgotten Password by using “Reset Disk”. If you created a Password Reset Disk in Past, you can use that

    disk to reset the password. To know more about It, please visit http://www.passwordreset.biz/

  • At first I didn’t how to do until my friend told me to use the software Windows Password Recovery(http://www.windowspassword-recovery.com/). It really helped me a lot!

  • Hallock says:

    Such a great article. YouWriter should receive credit for it. Thanks

  • cainisthebest says:

    does it run on windows 7, i have it on vista but i am getting a new one which has window 7. thx

  • johnjilinkin says:

    SMARTKEY Password Recovery Bundle is a must-have toolkit to recover/remove/reset passwords for Windows, Excel, Word, Access, PowerPoint, Outlook, Outlook Express, PDF, RAR/WinRAR, ZIP/WinZIP, MSN, AOL, Google Talk, Paltalk, Trillian, Miranda, Opera, Firefox and IE Browser, etc. Over 21 types of passwords can be Recovered instantly. Until now, these password recovery tools are the fastest on the market, the easiest to use and the least expensive..
    http://www.google.com.hk/search?hl=zh-CN&source=hp&q=http%3A%2F%2Fwww.lost-password.net%2F&btnG=Google+%E6%90%9C%E7%B4%A2&meta=&aq=f&aqi=&aql=&oq=

  • barbara says:

    another wonderful password recovery tool called SmartKey windows password recovery is highly recommended because of its features, to find your passwords is a child’s play.

  • johnjilinkin says:

    How can you said that?
    As many people recommend, SMARTKEY Password Recovery Bundle can works fine!

  • Leave a Reply

    XHTML: You can use these tags: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <pre> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

    Hack a Day serves up fresh hacks each day, every day from around the web as well as hacking related news.

    Send us your hacks










         




    Hacks

    Resources