RE: Cracking a Netscreen password

From: symbiot (symbiot_at_elitemail.org)
Date: 09/11/03

  • Next message: Birl: "Re: Strange logon attempts to Win2k server"
    To: pen-test@securityfocus.com
    Date: Thu, 11 Sep 2003 15:25:45 -0500
    
    

    Just thought I'd provide some password hashes/strings from my netscreen
    5XP,
    If there are any special requests, I can provide those too.
    All of these are with user 'netscreen'

    nKeZGvrkNDkPcAPBmsCA4HOtH7GS7n - 1
    nOQZIFrvATpIcOdASsZMK8OtfMK4an - 2
    nPpJA8rpL0CKcpTAYsOJ2LAtrMM68n - 3
    nLxjIprbBdiEcwHAusWPcwKtcIEdIn - 4
    nGu7CdrtMKOHcehC6scAR6It/EEJPn - 5
    nCAyE9rEMlJCciPASsYEyRMtjrKcrn - a
    nCD+GurSCh6Nc23I5sZCZbFtcYOtWn - b
    nC4oMxrsCJ0HcTECWsdL7DItlnGhZn - c
    nGoVPPrkAhMHcieDksYBP6Gt9TLsxn - d
    nO4VErrvBu4KcboG3sMCq0MtzdPapn - e

    nFfKOErLK76PcENArsdHDDFt6hJM+n - 000000
    nMXpHOrfPsKBcSmDzsOBP1Cts7E7hn - 00000
    nGcQMtrJGtHGcA3ATstGRZPtSdNlCn - 0000
    nEWbALrrLQ9IcaLKGs0DkwNtp0Nfrn - 000
    nK50AZrIPgOGcXpF4s0IbZKtQgBcln - 00
    nJB7PBrUJQnHcolEnsnLbkGt7+Bnpn - 0

    n C4oMx r sCJ0H c TECW s dL7DI t lnGhZ n - netscreem - <- yes that's an
    'm'
    n KVUM2 r wMUzP c rkG5 s WIHdC t qkAib n - netscreen -

    So the above hash with out the "common" characters 'nrcstn' is the
    following.

    KVUM2wMUzPrkG5WIHdCqkAib 24 chars. + a 6 char salt?

    I've played with Md5Crack and base64 encoding. nothing that I can see,
    but I'm not very crypto-literate.

    -symbiot

    -- 
      symbiot
      symbiot@elitemail.org
    -- 
    http://www.fastmail.fm - Sent 0.000002 seconds ago
    ---------------------------------------------------------------------------
    FREE Trial!
    New for security consultants and in-house pros: FOUNDSTONE PROFESSIONAL 
    and PROFESSIONAL TL software. Fast, reliable vulnerability assessment 
    technology powered by the award-winning FoundScan engine. Try it free for  21 days at: http://www.securityfocus.com/sponsor/Foundstone_pen-test_030825
    ----------------------------------------------------------------------------
    

  • Next message: Birl: "Re: Strange logon attempts to Win2k server"