Re: breaking 2k passwords

From: Jeff Cochran (jcochran)
Date: 10/11/02


From: jcochran at naplesgov dot com (Jeff Cochran)
Date: Fri, 11 Oct 2002 18:44:18 GMT


>my domain users use a password schem of ssxxxx (last 4 are
>always numbers). How long would it take someone (internal
>or external) to crack these passwords? 10min, 1 day, 1
>month?

Now knowing what I know about your system, there are 10,000 possible
combinations on your passwords (all 0's to all 9's). Brute force at
100 a minute it would be less than two hours. Calling Jan the
receptionist, telling her that I'm Dave at the help desk and I need
her login and password to check a potential problem in her payroll
would get me in about 118 minutes quicker... :)

Jeff



Relevant Pages

  • Re: breaking 2k passwords
    ... depends on the hardware they are running lopht crack on ... > my domain users use a password schem of ssxxxx (last 4 are ...
    (microsoft.public.win2000.security)
  • Re: breaking 2k passwords
    ... I just set my password to your senario and Lophat cracked in just under 7 ... > my domain users use a password schem of ssxxxx (last 4 are ...
    (microsoft.public.win2000.security)
  • breaking 2k passwords
    ... my domain users use a password schem of ssxxxx (last 4 are ... or external) to crack these passwords? ...
    (microsoft.public.win2000.security)
  • Re: breaking 2k passwords
    ... >my domain users use a password schem of ssxxxx (last 4 are ... >Win2k AD DC's,w/ 2k workstations ... Your scheme ssxxxx would take approximately 36 Seconds to crack, no matter, ...
    (microsoft.public.win2000.security)