.TH SAMDUMP2 1 "April 2012" "Version 3.0.0" .SH NAME .B samdump2 \- retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM. .SH SYNOPSIS .B samdump2 [\fIOPTIONS\fR] \fISYSTEM_FILE SAM_FILE\fR .SH DESCRIPTION .TP \fBsamdump2\fR is designed to dump Windows 2k/NT/XP password hashes from a SAM file, using the syskey bootkey from the system hive. .TP \fB\-d\fR enable debugging .TP \fB\-h\fR display this help .TP \fB\-o \fIfile\fR write output to file .SH EXAMPLE \fBsamdump2 \-o \fIout \fI/mnt/ntfs/WINDOWS/system32/config/system \fI/mnt/ntfs/WINDOWS/system32/config/sam\fR .SH AUTHOR This manual page was written by Adam Cecile for the Debian system (but may be used by others) and modified by Objectif Securite Permission is granted to copy, distribute and/or modify this document under the terms of the GNU General Public License, Version 2 or any later version published by the Free Software Foundation On Debian systems, the complete text of the GNU General Public License can be found in /usr/share/common-licenses/GPL-2. .SH SEE ALSO .br .B ophcrack(1)