CPTTM Network Admin newsletter issue #5

Topics in this issue:

Monitor your network traffic

There are over 100 workstations in CPTTM Cyberlab to provide services. All workstations can access the network. As a network administrator, we concern about the loading of both the internal and external network. We use MRTG (Multi Router Traffic Grapher) on our router to monitor the network traffic in a pretty graphical view.
MRTG can monitor multi network devices through SNMP, providing detail traffic analysis on daily, monthly, weekly and yearly graphs. MRTG can be used on both Windows and Linux platform and easy to setup. It is FREE!


You can find more information on their website.
http://www.mrtg.org

If you found any questions on using MRTG, welcome to ask on our IT Support Forum. Many experts are happy to answer you.
http://www2.cpttm.org.mo/forum

Windows Password Recovery

One day, we found that one student had changed the administrator password of one Windows XP. This made us annoyed.
I just thought of re-installing the Windows XP. Before that I searched the web to see if any tool can help me.
Then, I found a suitable tool : An Offline Password editor.
It is casted into a bootable floppy or CD. You just use it to boot the computer, then, you can edit the password of any local user account of the Windows OS, including NT, 2000, XP, 2003, installed on it. Even the "Local Administrator" is OK! But, it is limited to local user accounts only.

How does it works?
The NT family of Windows stores encrypted passwords of local user accounts into the file named: "sam" in the folder \winnt\system32\config. "sam" means Security Account Manager. This file is protected by the Windows OS and cannot be edited directly under Windows. If you know the way to decode this file, how to encrypt the passwords and can find a way to edit it, you can change the passwords inside.

This tool is actually a tool written under a tiny version of Linux, which can understand FAT, FAT32 and NTFS.
After booting up, this tool will ask you where is the "sam" file and then reads the "sam" file to get the local accounts inside. (since Windows is not running, the "sam" file is not protected.) Then, you can choose which account to change its password. The tool will encrypt the new password and put it back to the "sam" file.

You can read more information, the complete procedure and download this free tool at :
http://home.eunet.no/~pnordahl/ntpasswd/

It really works. We have tried. Remember that it can only reset the password of local user account. This tool reminds you that Physical Security is very important. If you want to reset the password for domain user accounts, there is a more complicated way to do it. See the following web page:
http://www.petri.co.il/reset_domain_admin_password_in_windows_server_2003_ad.htm

The web site also has many useful articles about managing the Windows Operating Systems. Don't miss them.

To learn how to manage Windows Server 2003, please consider taking our courses :
CM164 MCSE 2003 Certificate Program
CM179 MCSE 2003 (Authorized by Microsoft)
Unluckily, you need to wait until 3rd Quarter of 2006. For information, please see the currently running ones:
http://www2.cpttm.org.mo/training/sdb/showCourse.do?courseCode=CM164-01-2006-C
http://www2.cpttm.org.mo/training/sdb/showCourse.do?courseCode=CM179-08-2005-C

**Warning** This technique may only be legally used for computers that you own, otherwise you will take full responsibility of the action.

Books review - MCSE Self-Paced Training Kit

The Microsoft Certified Systems Engineer (MCSE) credential is the premier certification for professionals who analyze the business requirements and design and implement the infrastructure for business solutions based on the Microsoft Windows Server 2003 platform and the Microsoft Windows Server System. Your implementation responsibilities include installing, configuring, and trouleshooting network systems.

With official MCSE Self-Paced Training Kits, you can build the skills tested by the MCSE exams - and on the job. This all-in-one set provides in-depth preparation for the four required networking system exams.

Ace your preparation for the core MCSE networking system exams with in-depth training and practice - all in one box. Covering Exams 7-290, 70-291, 70-293, and 70-294, these four, all-new Microsoft study guides pack the resources you need to help maximize your success on the exams - and on the job.

You can borrow this book from our "CPTTM Microsoft Technology Book Shelf" in Cyberlab. Please visit :
http://www2.cpttm.org.mo/cyberlab/mslib/