RE: Cached Domain Password on Notebook, secure?

From: Frank Heyne (fh@rcs.urz.tu-dresden.de)
Date: 02/25/02


From: "Frank Heyne" <fh@rcs.urz.tu-dresden.de>
To: focus-ms@securityfocus.com, Rowan.Smith@csiro.au
Date: Mon, 25 Feb 2002 20:13:11 +0100

On 25 Feb 2002, at 9:42, Rowan.Smith@csiro.au wrote:

> My philosphy is that until someone actually releases a tool to crack the
> cached passwords then they are reasonably secure as someone is going to
> have to go through a lot of effort to obtain the password including
> writing the algorithm to crack it!
 
Did you never before hear about l0phtcrack or the linux boot disk to reset
passwords?

Frank Heyne



Relevant Pages

  • Re: hardware vs. john the ripper
    ... and how your cracking process is structured to address those ... (Some of the add-on modules to john can be ... Crack all the simple ones quickly? ... And what passwords are ...
    (Pen-Test)
  • Re: yet another fake exploit making rounds
    ... > and let them spin there wheels trying to crack the passwords. ...
    (Vuln-Dev)
  • Re: Is WPA-PSK + TKIP really that easily breakable? I dont think so.
    ... Tom's hardware about how to crack it but I am not particularly confident its *that* insecure if you configure other options and use very long complex passwords. ... Of course intend to go 802.1x when available but this is my current ... But with choice of a good pre-shared key and keeping it a secret should be very secure. ...
    (alt.internet.wireless)
  • Re: password security
    ... store local user accounts/ passwords. ... the network would have a SAM for the domain. ... Client so they can authenticate with NTLM V2. ... the hash with a network sniffer and crack it fairly easily. ...
    (microsoft.public.win2000.security)
  • Re: Cisco Secret 5 and John Password Cracker
    ... Cain and Abel can be used to crack that. ... > Any other tools available to crack these types of passwords. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)