Re: Password Cracking

From: Fabio Miranda Hamburger (fabmirha_at_ns.isi.ulatina.ac.cr)
Date: 09/15/04

  • Next message: David Gillett: "RE: learning ethical hacking"
    Date: Wed, 15 Sep 2004 11:44:02 -0600 (CST)
    To: xyberpix <xyberpix@xyberpix.com>
    
    

    > To me I've always had great success with LC4 and John, it all depends
    > what platform I'm on at the time though, and what dictionary lists I
    > have loaded at the time as well, so far I haven't found a passwd that I
    > haven't been able to crack, yet!

    You use easy to guess passwords based on letters and numbers. The
    dicctionary and GECOS generated passwords are weak. If you can crack all
    the passwords that host doesnt have a password policy.

    Have you cracked passwords like:

    k;!p-__f
    "d%g..H#
    ^ f!)I..

    You can make the passwords > 8 digits so you cant really crack all the
    passwords.

    fabio.

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------


  • Next message: David Gillett: "RE: learning ethical hacking"

    Relevant Pages

    • Re: hardware vs. john the ripper
      ... and how your cracking process is structured to address those ... (Some of the add-on modules to john can be ... Crack all the simple ones quickly? ... And what passwords are ...
      (Pen-Test)
    • Re: yet another fake exploit making rounds
      ... > and let them spin there wheels trying to crack the passwords. ...
      (Vuln-Dev)
    • Re: Is WPA-PSK + TKIP really that easily breakable? I dont think so.
      ... Tom's hardware about how to crack it but I am not particularly confident its *that* insecure if you configure other options and use very long complex passwords. ... Of course intend to go 802.1x when available but this is my current ... But with choice of a good pre-shared key and keeping it a secret should be very secure. ...
      (alt.internet.wireless)
    • Re: password security
      ... store local user accounts/ passwords. ... the network would have a SAM for the domain. ... Client so they can authenticate with NTLM V2. ... the hash with a network sniffer and crack it fairly easily. ...
      (microsoft.public.win2000.security)
    • Re: Cisco Secret 5 and John Password Cracker
      ... Cain and Abel can be used to crack that. ... > Any other tools available to crack these types of passwords. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)