Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 7 Mar 2007 15:58:51 +0300
From: Solar Designer <solar@...nwall.com>
To: john-users@...ts.openwall.com
Subject: Re: LM an NTLM combination

On Wed, Mar 07, 2007 at 12:03:42PM +0100, Antares wrote:
> My first run found i.e. 1459 guesses (in 1 min, 10s)
> Invoking the very same command again (using by bash history) found 
> another 65 guesses (in 1 min, 11s)
> 
> How is that possible?

This sounds like a bug, and I suspect the new NTLM patch - it has not
been tested extensively yet.  Please try with the older NTLM patch that
is a part of the jumbo patch -

	http://www.openwall.com/john/contrib/john-1.7.2-all-2.diff.gz

and let the list know of your results.

> Times are almost the same, by coincident?

No, times are supposed to be almost the same, although 1 minute feels a
bit excessive - what hardware are you on, how many cracked LM hashes do
you have in your john.pot?

> btw. i don't want to bother you ;) if you have no time for this, let me 
> know, i'll post it then to the list...

Actually, you did the right thing by posting this to the list right away.
I prefer to not discuss these things in private.

Thanks,

-- 
Alexander Peslyak <solar at openwall.com>
GPG key ID: 5B341F15  fp: B3FB 63F4 D7A3 BCCC 6F6E  FC55 A2FC 027C 5B34 1F15
http://www.openwall.com - bringing security into open computing environments

-- 
To unsubscribe, e-mail john-users-unsubscribe@...ts.openwall.com and reply
to the automated confirmation request that will be sent to you.

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ