Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 16 Sep 2008 07:55:37 +0400
From: Solar Designer <solar@...nwall.com>
To: john-users@...ts.openwall.com
Subject: Re: A patch for http digest and various tools

On Wed, Aug 27, 2008 at 05:06:39PM +0200, Romain Raboin wrote:
> I developped several tools related to password security, which you can
> find on this page: http://syscall.eu/romain/
> 
> While all of them are probably of interest for John users, these three
> are directly related to John :
> - HTTP Digest Access Authentication patch. A patch for john-1.7.3 that
> allow you to brute force HTTP Digest Access Authentication when you
> got a network capture of an authentication.

I've merged this one into the latest jumbo patch - thank you!  I did not
place the john-1.7.3.1-HDAA.diff.gz patch for download separately
because of a few issues I found and fixed while merging this into the
jumbo patch.  You might want to import those fixes and release an updated
patch (call it john-1.7.3.1-HDAA-2.diff.gz), which I will likely place
into the contrib/ directory on the FTP.

> - passwd_cracker: Distributed (in Ruby) password cracker using myjohn.

I've added this one to the collection:

	ftp://ftp.openwall.com/pub/projects/john/contrib/parallel/passwd_cracker/

You might want to update the documentation to reflect the fact that the
Markov generator is now merged into the jumbo patch, as well as to
provide a short summary and a link to your website (where updated
versions could be found) at the start of the README file.  I will then
update "my" copy.

> - myjohn: Corrections on Simon Marechal's patch for John The Ripper.

I've diff'ed Simon's myjohn.tgz of July 23 vs. yours of July 18 (both
were the latest available at the download URLs known to me as of two
days ago).  Most of the differences were a result of Simon merging in my
changes made in 1.7.3+, which apparently were not yet in his tree at the
time you started modifying it.  I found only a few other changes in your
tree, including the addition of HDAA support (but your separate patch
for it appeared to be slightly newer), a bug fix to NSLDAPS_fmt.c (but I
think the same issue was already addressed in the jumbo patch), the
addition of genincstats.rb (which I also dropped into the run/ directory
in the latest jumbo patch, just in case someone finds it useful),
various unintentional and/or local changes, and also the following fix
to params.h:

Simon - besides merging the bug fixes from the jumbo patch, you could
want to disable JOHN_SYSTEMWIDE and revert your change to CFG_FULL_NAME.
These two unexpected changes are very confusing to most people who might
try to use your tree.

Thanks,

Alexander

-- 
To unsubscribe, e-mail john-users-unsubscribe@...ts.openwall.com and reply
to the automated confirmation request that will be sent to you.

Powered by blists - more mailing lists

Your e-mail address:

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.