|
|
Message-ID: <20051006005136.GA1422@openwall.com>
Date: Thu, 6 Oct 2005 04:51:36 +0400
From: Solar Designer <solar@...nwall.com>
To: john-users@...ts.openwall.com
Subject: Re: Newbie question on jtc show
On Wed, Oct 05, 2005 at 09:22:23PM +0400, Solar Designer wrote:
> On Wed, Oct 05, 2005 at 11:55:55AM -0500, Shashank Khanvilkar wrote:
> > #>john -show passwd.2
> > Administrator:???????:500:31d6cfe0d16ae931b73c59d9e0c089c0:::
> > Guest:???????:501:31d6cfe0d16ae931b73c59d7e0c089c0:::
> > --SNIP--
> >
> > what do these "???" signify
>
> John uses the question marks to indicate uncracked portions of
> partially-cracked passwords. However, in your case this appears to be a
> bug in the version of John you're using. What version was that?
This was determined to be a bug in John 1.6 ("stable") in that it fails
to properly detect LM hashes of empty passwords when those hashes are
encoded with lowercase characters. I believe the original PWDUMP used
all-uppercase characters.
This has been corrected shortly after John 1.6 release... Yes, it's
high time I put out a John 1.7.
--
Alexander Peslyak <solar at openwall.com>
GPG key ID: B35D3598 fp: 6429 0D7E F130 C13E C929 6447 73C3 A290 B35D 3598
http://www.openwall.com - bringing security into open computing environments
Was I helpful? Please give your feedback here: http://rate.affero.net/solar
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.