How To: Recover a Windows Password with Ophcrack

Recover a Windows Password with Ophcrack

When Windows stores a password, it is done so by hashing the password in an LM hash and putting it in the Windows SAM file. In the scary moment that you lose your password, but don't want to pay some geek to have full root access to your computer, you need to recover it using Ophcrack. Ophcrack doesn't remove the password, or bypass it, it cracks the password hash using rainbow tables.

Ophcrack is favored to be used on a live CD medium. Windows has a security measure in place that disallows all access to the SAM file when the system is in use. To combat this, the partition and Windows file system must be mounted using a operating system that can load and run itself from memory. This prevents the Windows system from loading, and allows the SAM file to be read from.

In today's Null Byte, we are going to burn the Ophcrack medium to a disc, and run its tables against our Windows password to assess their strength.


  • A Windows installation on your hard drive
  • A blank CD

Step 1 Burn Ophcrack to a Disc

We need to burn our tool to a CD so we can boot from it and crack our SAM file.

  1. First, let's install some easy-to-use, free software to burn our ISO.
        Download Free ISO Burner.
  2. Download the Ophcrack ISO that corresponds to your OS.
  3. Open up Free ISO Burner and select the Ophcrack ISO file. Here is an example image from the website:How to Recover a Windows Password with Ophcrack
  4. Check off Finalize Disc.
  5. Set the burn speed to as low as you can. The slower the burn, the higher the quality it is. It also helps reduce turning CDs into a coffee coaster due to incorrectly burning the image.
  6. Click "Brun" (program typo).

Step 2 Boot from Ophcrack

  1. Throw the disc in your disc tray.
  2. Reboot your computer.
  3. Hit the button to get into the setup menu during boot time (variable f* key).
  4. Boot from the CD first.
  5. The software should have a popup window that runs the rainbow tables against your SAM file.

I'm not sure how large Ophcrack tables are, but some people swear it has a greater than 90% success rate. I doubt it would on mine, with my ridiculous passwords.

Please, come by the IRC and talk with me and other crew members! You can follow me on Twitter and G+ to get Null Byte's latest updates.

Just updated your iPhone? You'll find new features for Podcasts, News, Books, and TV, as well as important security improvements and fresh wallpapers. Find out what's new and changed on your iPhone with the iOS 17.5 update.

Image via tintshoppe


I cant remember the table "speccs" right now, but they can crack a lot. I think you can download extra tables for larger and more advanced passwords though.
I've used Ophcrack about ~7 times, and it has successfully cracked every password except my last try so I ended up having to reformat the computer.
My sister in law whom is 10 years old cant remember her password :/

Hehe, that's when you just KonBoot :D.

Hehe true :)

why so dificult, when starting up your pc press F4 for save mode, then you can choose a new password.
you don't need the old one.

Because, most users have the default admin account disabled. Also, it is because we want to KNOW the password, not just get rid of it, or get access to the computer. Think outside the box, buddy :).

we can reset windows password with the third software.

Share Your Thoughts

  • Hot
  • Latest