More on windows cached password recovery

hmm looks like it's not quite as bad as I thought it was. After a bit more reading on the subject, the windows cached password is not just an NTLM hash, it's actually a salted hash, with the salt being the username.

So rainbow tables aren't really a practical attack for this, although it's interesting to note that there's a John the ripper plug-in for cachedump now which enables you to do dictionary based/brute-force attacks on retrieved credentials

About this Entry

This page contains a single entry by Rory2 published on November 29, 2006 9:12 AM.

PWDumpX was the previous entry in this blog.

Finally ! A sensible view on AJAX Security is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Pages

Powered by Movable Type 4.37

About this Entry

This page contains a single entry by Rory2 published on November 29, 2006 9:12 AM.

PWDumpX was the previous entry in this blog.

Finally ! A sensible view on AJAX Security is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.