Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 18 Nov 2012 02:04:43 +0100
From: magnum <john.magnum@...hmail.com>
To: john-users@...ts.openwall.com
Subject: Re: cracking passwords with a kerberos traffic dump / aes256-cts-hmac-sha1-96 (18)

On 17 Nov, 2012, at 22:03 , Dhiru Kholia <dhiru.kholia@...il.com> wrote:
>> The password in my case is 15+ (maybe MS is using a different hash with
>> length=15+ passwords? (...a shot in the blue)
>> What setup do you have? Win7 client + Server 2003?
> 
> Both my Kerberos server and client are CentOS (Linux) 6.3 machines.

As in standard Kerberos? It would surprise me a whole lot if Microsoft do not use the Unicode version of the password, or (even more likely) the 16 byte NT hash as input just like in mskrb5, as opposed to the plain string you use now.

OTOH your test vector do have that known plaintext timestamp. That is interesting. Does that mean the plaintext attack can be used against non-Microsoft authentications as well?

> It would be great if you can post a pcap file for a dummy user.


This is probably imperative for successfully making a version that has any chance of cracking a sniffed AD authentication. We need one or more test pcaps with known passwords. One of them should ideally include a non-ascii character in the password, like a pound or euro sign.

magnum

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.