Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: 09 Oct 2008 17:19:00 +0200
From: "Helmut Hullen" <Hullen@...nline.de>
To: john-users@...ts.openwall.com
Subject: Re: reading "signons.txt" from friefox

Hallo, RB,

Du (aoz.syn) meintest am 09.10.08:

>> can "john" work in a simple way with the "signons.txt" file (or
>> "SIGNONS.TXT") from "firefox"?

> I didn't have one (signon saving is one of the first things I kill)
> and ended up creating a short one, but there's probably a better way,
> given that FF typically auto-decrypts the passwords somehow using
> key3.db.  I'll leave analysis of that to someone else.  That said,
> it'd probably be even easier to just go check the source.

> The records are in a format described here:
> http://kb.mozillazine.org/Signons2.txt.  The "encrypted password"
> field is a base64 string, which decodes to a 62-byte string.  Cursory
> examination seems to indicate the format is:

[...]

Another description maybe in

        http://www.haypocalc.com/wiki/Lamer

But that seems to be only the entry for decoding, not the solution.

Viele Gruesse!
Helmut

-- 
To unsubscribe, e-mail john-users-unsubscribe@...ts.openwall.com and reply
to the automated confirmation request that will be sent to you.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux