Chinese gang shoots down aerospace security with MSFT flaws

"SAM dump and hash cracking definatley works on DCs above Win2k"

Only if they have been upgraded from an earlier version without updating the security settings. As per the link above - from Win2K3 onwards, the default is not to use reversible encryption for Active Directory passwords.

