Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 31 Jan 2013 11:16:45 +0400
From: Solar Designer <solar@...nwall.com>
To: john-dev@...ts.openwall.com
Subject: Re: NetNTLMv1

On Thu, Jan 31, 2013 at 07:29:05AM +0100, atom wrote:
> This weakness was obvious to me. I was wondering why its not implemented in JtR.

Somehow we missed it, maybe in part because there was no specific person
in charge of optimizing this format (as well as most other formats...)

> You're right so far, the weakness is the third DES part. Its keyspace
> is just 2^16. All you need is to Brute-Force this keyspace on CPU,
> which is very fast. It takes only a few ms with OpenSSL DES on a
> single core. But once you found it, you know the last 16 bit of the
> MD4.

Yeah, and this is better than my hack with maintaining a table for the
third DES block.

Thanks!

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.