Re: Cain shows DefaultPassword in plain text - LASS writes it

clavigo_at_gmx.at
Date: 05/21/05


Date: 21 May 2005 00:07:28 -0700

Steve, thank you for your assistance.

You pinpoint what I'm asking for. Cain does not show your password on
your computer because it is not stored as LSA secret. That's the way it
meant to be.

But on my computer LSASS does store my password as LSA secret, every
time I change the password and unfortunately I do not know how to
change this behavior.

I will install SP2 and see if things get better.

Clavigo

BTW: mentioning Kerberos was a joke. I know that is not used for local
authentication but - Kerberos is such a well known dog, and hash is
such a delicious dog food, and my dog's name gives such a good
password, and that password should give such a tasty hash that XP
should store this hash, if it wants to be a good dog handler ;-)



Relevant Pages

  • Re: bad code, needs work...
    ... > The problem I am getting is checking to see if one field matches the city, ... The outfile opens can be handled in a loop that will at least prevent ... then store that scalar into a hash, which would be a convenient way to ... Again if you store the output handles to a hash, ...
    (perl.beginners)
  • Re: Best practices for storing/retrieving login credentials
    ... you must make sure that incoming callers are allowed to make FTP ... I think - Roy is interested in is how to protect the common FTP credentials. ... You cannot hash the FTP password, because the application needs to provide ... > then have to consider how to store the encryption key. ...
    (microsoft.public.dotnet.security)
  • Re: Secure password storing
    ... The reason why I can't store a hash is that the ... with a symetric key, there are loads of free libraries out there that will ... passport system are only storing hash of the passwords. ...
    (microsoft.public.dotnet.general)
  • Re: (OT) lincense protection generator
    ... Jarek Zgoda wrote: ... It could be a long string and then take a hash from it and store the hash value. ... generate sha1 sum of general machine configuration and store it on random internet node. ... These people are, to put it mildly, not the most computer savant people around. ...
    (comp.lang.python)
  • Re: Is it necessary to store the entire MD5, etc. hash for validation?
    ... >I want to store the last 10 passwords used on a legacy database that, ... but I don't have room to store 10x128+ bytes. ... I think you are mistaken about the size of the output of hash functions, ... passphrase hashes if you use SHA-256, ...
    (sci.crypt)