Re: Password Cracking Challenge...

From: David Riley (oscar_at_the-rileys.net)
Date: 07/28/03

  • Next message: David Schwartz: "RE: Password Cracking Challenge..."
    Date: Mon, 28 Jul 2003 16:47:19 -0400 (EDT)
    To: Justin Pryzby <justinpryzby@users.sf.net>
    
    

    On Mon, 28 Jul 2003, Justin Pryzby wrote:

    > Date: Mon, 28 Jul 2003 12:44:45 -0700
    > From: Justin Pryzby <justinpryzby@users.sf.net>
    > To: "vuln-dev@securityfocus.com" <vuln-dev@securityfocus.com>
    > Subject: Re: Password Cracking Challenge...
    >
    > Can't say for sure, but the zero's are interesting. I know the MS NTLM
    > scheme takes passwords longer than 7(?) and breaks them up into two
    > passwords, each of maximum length 7(?). That's the first thing I'd try.
    > The encryption is documented, [http://www.innovation.ch/java/ntlm.html]
    > is a good starting point.

    It is a good starting point, and that's what I thought of as well.
    However, the cutoff here seems to be 8 bytes instead of 7. I'm still
    looking at it, but the encoding of the second chunk seems dependent on the
    first (e.g. the "321" chunk of "Pa$$word321" is different than that of
    "Password321".

    Just my 2 cents.


  • Next message: David Schwartz: "RE: Password Cracking Challenge..."

    Relevant Pages

    • Re: Password variation scheme a plus in security?
      ... Unless your scheme is easily guessable, or I have grabbed two or more of your passwords along with the sites you use them on, you don't have nearly as much to worry about. ... immediately successful logins, ... and from these maybe 90.000 give them immediate login success ...
      (Security-Basics)
    • Re: Password hashes
      ... There are only two hashes used for storing passwords in the Microsoft ... and there is no dedicated NTLM hash for stored passwords. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: k-deterministic public-private key generation
      ... I won't disagree with your evaluation of this scheme in context of ... input to a PK generation scheme, ... Your point about remembering passwords that aren't entered ... and 3) protect against attacks on the key pair from even ...
      (sci.crypt)
    • Re: Password statistics and standards
      ... Check out the Project RainbowCrack ... My understanding of how NTLM stores passwords is by storing the first ... characters in one location and up to 7 more characters in a second. ...
      (Security-Basics)
    • Re: admin account password management
      ... and utterly obscure to anyone else. ... match to create a password scheme. ... safe to store passwords and or system/network information on either. ... >All your favorites on one personal page – Try My Yahoo! ...
      (Security-Basics)