AW: Unisphere Password Hashes

Marc.Werner_at_t-systems.com
Date: 09/08/05

  • Next message: Micha Borrmann: "Re: Merging .NBE"
    To: pen-test@securityfocus.com
    Date: Thu, 8 Sep 2005 10:30:42 +0200 
    
    

    Hi,

    this hash seems to be not a base64 hash. I tried to decrypt the one I found in a (real live) config. Cain wasn't able to crack this.
    Trying the example from the manual cain showed me "cd1163" as the hex-dump of the given example...
    Any other ideas???

    Cheers Marc

    -----Ursprüngliche Nachricht-----
    Von: Miguel Dilaj [mailto:mdilaj@nccglobal.com]
    Gesendet: Donnerstag, 8. September 2005 10:02
    An: pen-test@securityfocus.com
    Cc: Werner, Marc
    Betreff: RE: Unisphere Password Hashes

    Hi Marc,

    This is the base64 for "cd1163", so I suppose that this was the password ;-)
    Cheers,

    Miguel

    >Does anyone know how the passwords on unisphere (juniper) ERXs are hashed?
    They look like zRFj_6>^]1OkZR@e!|S$ (example from the manual). Do they have
    different hash types for different
    >security levels? Thank you in advance!!!

    ***********************************************************************************************************
    DISCLAIMER:
    This e-mail contains proprietary information, some or all of which may be legally privileged.
    It is for the intended recipient only. If an addressing or transmission error has misdirected this e-mail,
    please notify the author by replying to this e-mail. If you are not the intended recipient you may not use,
    disclose, distribute, copy, print or rely on this e-mail.
    ***********************************************************************************************************

    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on your
    website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------


  • Next message: Micha Borrmann: "Re: Merging .NBE"

    Relevant Pages

    • Re: Rainbow Tables
      ... I guess what I should have asked was what is the best program or method of creating hash tables since I doubt I'll remember the name since I say it in passing.... ... Hackers are concentrating their efforts on attacking applications on your website. ... Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. ... Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: Secure Password Policy?
      ... "Note that after you disable the storage of passwords you will have ... From what I have seen the LM field for the hash is blanked ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: SAP R/3 password encryption ?
      ... Stupid of me - I never thought about including the "hash" word in my ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: Insecure Hash Algorithms (MD5) and NTLMv2
      ... hash when you have no access to the original input. ... The only weakness that's really in the air is Collision Resistance, ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • [REVS] Denial of Service via Algorithmic Complexity Attacks
      ... both binary trees and hash tables can degenerate to linked lists with ... demonstrate attacks against the hash table implementations in two versions ... Bro server to its knees; after six minutes of carefully chosen packets, ...
      (Securiteam)

    Loading