Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 4 Mar 2010 01:48:02 +0300
From: Solar Designer <solar@...nwall.com>
To: john-users@...ts.openwall.com
Subject: Re: NTLM Hashes

On Wed, Mar 03, 2010 at 07:27:06PM +0000, keith johnson wrote:
> Hi all, Which version of J-t-R is required for cracking NTLM hashes?

Any version with a proper patch, or JtR Pro.

> If this task requires a patch, please can you provide me a link, and details on how to install it on a Windows XP machine, as the wiki page on patches I read some time back was for Unix users only. 

No, the wiki page was not for Unix users only.  Those patches may be
used on Windows as well, but indeed you would be assumed to be able to
patch and rebuild JtR from source under Cygwin.  The jumbo patch, which
is the primary one you'd need, is maintained separately, though, so it's
not found on the wiki page, but rather on the JtR homepage.

Anyway, given your requirements, your best bet is to download Erik's
latest build of JtR 1.7.5 (with the jumbo patch applied) for Windows:

http://www.openwall.com/john/#contrib

You need:

"1.7.5 + jumbo patch revision 1 build for Win32 (1.8 MB) by Erik Winkler"

To have it crack NTLM rather than LM hashes, you'll need to specify the
"--format=nt" command-line option.

If you want to take advantage of your cracked LM hashes in order to
crack the corresponding NTLM hashes faster (assuming that you do have
accounts with hashes of both types at once), you can use the approach
described here:

http://www.openwall.com/lists/john-users/2006/07/08/2

Instead of renaming the section as this old posting says, you can now
use the "--rules=nt" option.

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.