Re: Password Audit tools

From: GuidoZ (uberguidoz_at_gmail.com)
Date: 12/20/04

  • Next message: GuidoZ: "Re: delving deeper"
    Date: Mon, 20 Dec 2004 03:13:39 -0500
    To: "John Forristel (SunGard-Chico)" <John.Forristel@sungardbi-tech.com>
    
    

    > If you have the time and disk space, Rainbow Crack is another very fast
    > cracker. It creates tables of possible hashes based on the parameters
    > you set, such as "lower-case, numeric". It takes about 640 megs for
    > letters and numbers. It takes about 200 GIGS for special and alt chars.
    >
    > When you crack, it is incredibly fast because the work is already done

    Something to add to this - frequently when doing pen-tests, you'll
    find that weak passwords are only alphanumeric. Generating the rainbow
    tables and popping them onto a CD or large USB thumb drive (or usb
    hdd) works wonders. Then you can take them with and crack passwords
    on the spot in minutes. (RainbowCrack will also run from a USB drive.)

    --
    Peace. ~G
    On Tue, 14 Dec 2004 09:30:35 -0800, John Forristel (SunGard-Chico)
    <John.Forristel@sungardbi-tech.com> wrote:
    > 
    > If you have the time and disk space, Rainbow Crack is another very fast
    > cracker.  It creates tables of possible hashes based on the parameters
    > you set, such as "lower-case, numeric".  It takes about 640 megs for
    > letters and numbers.  It takes about 200 GIGS for special and alt chars.
    > 
    > When you crack, it is incredibly fast because the work is already done.
    > 
    > 
    > -----Original Message-----
    > From: Dan Connelly [mailto:connellyd@gmail.com]
    > Sent: Tuesday, December 14, 2004 4:25 AM
    > To: Jeffrey M. Miller CISSP
    > Cc: pen-test@securityfocus.com
    > Subject: Re: Password Audit tools
    > 
    > Internet Scanner does a good job of enumerating accounts on a Windows
    > Domain(using netbios and null sessions) but if you tried to brute
    > force/dictionary every account that it found the scan would take a
    > VERY long time to complete.  If you are trying to pw crack through a
    > service (ftp,telnet,http...), use hydra otherwise use LC or John the
    > Ripper.
    > BTW, Nessus also does a good job enumerating accounts, and its free ;)
    > Dan
    > 
    > On Mon, 13 Dec 2004 19:10:29 -0600, Jeffrey M. Miller CISSP
    > <jmiller@acumeninfosec.com> wrote:
    > > I've used Internet Security Scanner from ISS and really like it's
    > > ability to pull users from NT domains and test common passwords, such
    > > as username=password, password=password, etc.
    > >
    > > I've considered purchasing the consultant version of l0phtcrack LC5.
    > >
    > > Has anyone used LC5 and can anyone compare it to ISS?  Also are there
    > > any OpenSource tools that can do these sorts of checks?
    > >
    > > Thanks
    > >
    > > J_
    > >
    > >
    > 
    >
    

  • Next message: GuidoZ: "Re: delving deeper"

    Relevant Pages

    • Re: hardware vs. john the ripper
      ... and how your cracking process is structured to address those ... (Some of the add-on modules to john can be ... Crack all the simple ones quickly? ... And what passwords are ...
      (Pen-Test)
    • Re: yet another fake exploit making rounds
      ... > and let them spin there wheels trying to crack the passwords. ...
      (Vuln-Dev)
    • Re: Cracking Ettercap Generated hashes
      ... What you have there are the challenge/response hashes. ... You can crack ... i got a hash through Ettercap(ARP ... Chief Information Security Officer ...
      (Pen-Test)
    • Re: Is WPA-PSK + TKIP really that easily breakable? I dont think so.
      ... Tom's hardware about how to crack it but I am not particularly confident its *that* insecure if you configure other options and use very long complex passwords. ... Of course intend to go 802.1x when available but this is my current ... But with choice of a good pre-shared key and keeping it a secret should be very secure. ...
      (alt.internet.wireless)
    • Re: password security
      ... store local user accounts/ passwords. ... the network would have a SAM for the domain. ... Client so they can authenticate with NTLM V2. ... the hash with a network sniffer and crack it fairly easily. ...
      (microsoft.public.win2000.security)