Re: Password cracking / recovery Lotus Notes R6

From: dawn (dawngirl_at_gmail.com)
Date: 11/25/05

  • Next message: Hernan Antolini: "Re: Identifying whether 2 IPs are from the same server"
    Date: Fri, 25 Nov 2005 15:34:15 -0500
    To: Richard Zaluski <rzaluski@ivolution.ca>
    
    

    Hi, Richard,

    Advance Lotus Password Recovery from Elcom Software is a program to
    recover lost or forgotten passwords to the files/documents created in
    IBM/Lotus applications (all versions): Organizer, WordPro, 1-2-3,
    Approach and Freelance Graphics. Passwords to ftp and proxy sites set
    in Lotus SmartSuite components can be also extracted. The passwords
    are recovered instantly; multilingual passwords are supported.

    The URL for the trial version is below, but I am do not know if the
    trial version recovers the complete password or a partial password.
    The cost of the software is minimal, $49 for the personal version.

    The URL is:
    http://www.elcomsoft.com/download/alpr.zip

    Good luck!

    On 11/25/05, Richard Zaluski <rzaluski@ivolution.ca> wrote:
    > Hello,
    >
    > Currently I am working with a client to gain access to a Lotus Notes R6
    > (running on NT) database. We have full access to the box and need to
    > penetrate the passwords on the data bases.
    >
    > Does anyone have tools or techniques they can suggest to achieve this goal?
    >
    > Thanks....
    >
    >
    > Richard Zaluski
    > CISO, Security and Infrastructure Services
    > iVOLUTION Technologies Incorporated
    > 905.309.1911
    > 866.601.4678
    > www.ivolution.ca
    > rzaluski@ivolution.ca
    >
    >
    >
    >
    >
    > ------------------------------------------------------------------------------
    > Audit your website security with Acunetix Web Vulnerability Scanner:
    >
    > Hackers are concentrating their efforts on attacking applications on your
    > website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    > login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    > futile against web application hacking. Check your website for vulnerabilities
    > to SQL injection, Cross site scripting and other web attacks before hackers do!
    > Download Trial at:
    >
    > http://www.securityfocus.com/sponsor/pen-test_050831
    > -------------------------------------------------------------------------------
    >
    >

    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on your
    website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------


  • Next message: Hernan Antolini: "Re: Identifying whether 2 IPs are from the same server"

    Relevant Pages

    • RE: Whitespace in passwords - now alt+xxx
      ... Subject: Whitespace in passwords ... 60 possible characters and the password is 7 characters long. ... >> Check your website for vulnerabilities to SQL injection, ... >> scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • RE: Rainbow Tables
      ... Subject: Rainbow Tables ... Fortunatly for this project we are only doing LM passwords, ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)
    • RE: Rainbow Tables
      ... Subject: Rainbow Tables ... Fortunatly for this project we are only doing LM passwords, ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are ...
      (Pen-Test)
    • Re: Rainbow Tables
      ... wouldn't it be easier to create a diccionary with the passwords ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Hackers are concentrating their efforts on attacking applications on your ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)
    • Re: Rainbow Tables
      ... I have now been tasked to take a list of passwords and try to generate a precomputed hash table out of those passwords...not sure if this can be done but of course I have to find a way..since I am "holding up a project". ... Reason for this...the idea is that if we take the current list of passwords create a pre-computed hash table the next time we audit we'd run LC5 and all but the passwords that changed and new accounts would get knocked out right away. ... Hackers are concentrating their efforts on attacking applications on your website. ... Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. ...
      (Pen-Test)