Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

SAM and SYSTEM hive

Posted on 2011-09-08
7
Medium Priority
?
792 Views
Last Modified: 2012-05-12
With local  ladmin rights - can the admin copy the SAM and SYSTEM registry hives from a windows server? If not how can copies be obtained?
0
Comment
Question by:pma111
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 800 total points
ID: 36504894
I believe these files are not able to be copied while windows is running. I think you can access these files with a bootable linux CD or you may also be able to copy them using a tool like NT Offline.

http://www.pogostick.net/~pnh/ntpasswd/
0
 
LVL 3

Author Comment

by:pma111
ID: 36504907
I wondered if ntbackup would work
0
 
LVL 9

Assisted Solution

by:Ashok Dewan
Ashok Dewan earned 600 total points
ID: 36504938
you can copy only registry hives but not sam file. Download any mini windows live cd or any linux live cd.
1. Ubuntu
2. knoppix
these are bootable live cd's
http://www.ubuntu.com/download/ubuntu/download
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 9

Expert Comment

by:Ashok Dewan
ID: 36504947
sorry you also cannot copy registry hives.
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 36504960
Another option you can try is this.

1. Create a restore point.
2. Open C:\System Volume Information\_restore{0145FC50-D40A-42A0-A56A-275EF2B2493B} folder and locate the latest restore folder starting with RP**.
3. In RP** folder, open snapshot folder. Where u can find all 5 OS hives restored.

Original posting here.
http://www.firewall.cx/ftopicp-21828.html
0
 
LVL 93

Assisted Solution

by:nobus
nobus earned 600 total points
ID: 36508670
or hook the drive to a working pc to copy the files
0
 
LVL 3

Author Comment

by:pma111
ID: 36508732
Its a live (v important server) so powering it down is out the equation or taking drives out.

I am suprised you cant just ntbackup the config folder :( then access them from a restored backup
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
Each password manager has its own problems in dealing with certain websites and their login methods. In Part 1, I review the Top 5 Password Managers that I've found to be the best. In Part 2 we'll look at which ones co-exist together and why it'…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question