Date: Thu, 4 Mar 2010 01:48:02 +0300 From: Solar Designer <solar@...nwall.com> To: john-users@...ts.openwall.com Subject: Re: NTLM Hashes On Wed, Mar 03, 2010 at 07:27:06PM +0000, keith johnson wrote: > Hi all, Which version of J-t-R is required for cracking NTLM hashes? Any version with a proper patch, or JtR Pro. > If this task requires a patch, please can you provide me a link, and details on how to install it on a Windows XP machine, as the wiki page on patches I read some time back was for Unix users only. No, the wiki page was not for Unix users only. Those patches may be used on Windows as well, but indeed you would be assumed to be able to patch and rebuild JtR from source under Cygwin. The jumbo patch, which is the primary one you'd need, is maintained separately, though, so it's not found on the wiki page, but rather on the JtR homepage. Anyway, given your requirements, your best bet is to download Erik's latest build of JtR 1.7.5 (with the jumbo patch applied) for Windows: http://www.openwall.com/john/#contrib You need: "1.7.5 + jumbo patch revision 1 build for Win32 (1.8 MB) by Erik Winkler" To have it crack NTLM rather than LM hashes, you'll need to specify the "--format=nt" command-line option. If you want to take advantage of your cracked LM hashes in order to crack the corresponding NTLM hashes faster (assuming that you do have accounts with hashes of both types at once), you can use the approach described here: http://www.openwall.com/lists/john-users/2006/07/08/2 Instead of renaming the section as this old posting says, you can now use the "--rules=nt" option. Alexander
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.