Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 4 May 2006 01:51:31 +0400
From: Solar Designer <solar@...nwall.com>
To: john-users@...ts.openwall.com
Subject: Re: Password Hashes loaded vs. ./john --show

On Wed, May 03, 2006 at 05:08:43PM -0400, Arvind Sood wrote:
> The only reason I loaded it with the NT parameter was based on the
> case-sensitive stuff I read about on the forum. Since I was not sure if I
> could live with the passwords being displayed in the wrong case, I went in
> with the safer option.
> 
> Having seen how much quicker it cracked the LM hashes (there are some
> accounts for which the --format=LM already shows a password while the
> --format=NT is still working)..... I see your point about trying with the LM
> format first.

When you have both hash types, you do not need to be actually cracking
your NTLM hashes.  Instead, you may use them to infer the right case of
characters in your LM-hash-cracked passwords - which is done quickly:

http://article.gmane.org/gmane.comp.security.openwall.john.user/470
http://article.gmane.org/gmane.comp.security.openwall.john.user/513

-- 
Alexander Peslyak <solar at openwall.com>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598
http://www.openwall.com - bringing security into open computing environments

Was I helpful?  Please give your feedback here: http://rate.affero.net/solar

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.