Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 10 Mar 2007 04:49:16 +0300
From: Solar Designer <solar@...nwall.com>
To: john-users@...ts.openwall.com
Subject: Re: LM an NTLM combination

Alain,

On Fri, Mar 09, 2007 at 08:41:16PM +0100, Alain Espinosa wrote:
> Antares send me privately the password file with the hashs (passwd) and the
> wordlist (wordlist) but i cant reproduce the problem. Here are what i do:
...

One more observation: in these tests, you've never tried running John in
batch mode (not specifying a cracking mode on the command line).  In
that mode, John loads all hashes, including duplicates, since that might
provide extra information for the "single crack" mode (which is the
first pass with batch mode).  As a side effect, the presence of
duplicate hashes in John's in-memory "database" might expose bugs in
your patch that are otherwise not seen - and I had that happen in my
testing today (with your -4).

Please note this when you're testing further revisions of your patch.

Thanks,

-- 
Alexander Peslyak <solar at openwall.com>
GPG key ID: 5B341F15  fp: B3FB 63F4 D7A3 BCCC 6F6E  FC55 A2FC 027C 5B34 1F15
http://www.openwall.com - bringing security into open computing environments

-- 
To unsubscribe, e-mail john-users-unsubscribe@...ts.openwall.com and reply
to the automated confirmation request that will be sent to you.

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ