Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Tutorialsarrow Rainbow Tables/Crack whitepaper
EH-Net
May 22, 2013, 02:15:48 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Rainbow Tables/Crack whitepaper  (Read 8525 times)
0 Members and 1 Guest are viewing this topic.
LSOChris
Guest
« on: July 29, 2006, 04:24:33 PM »

all, you can read my Rainbow Tables/ Rainbow Crack whitepaper here:

http://www.windowsecurity.com/whitepapers/Rainbow_Tables__RainbowCrack_Introduction1614.html


comments always welcome.
Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #1 on: July 30, 2006, 10:17:45 AM »

Great job on that paper Chris. Explains it in a very readable manner that a user could understand and still comprehensive enough for an experience security pro to get something out of it.

About the only criticism that I could think of is more of just opinion than a problem with the paper. NTLM tables are becoming easily available for anyone that really wants them and I'm somewhat paranoid so I take the stance that passwords just aren't a secure way to authenticate. Two part authentication is really the only way to protect yourself. You address this by stating all but the most determined attacker but I think the addition of two part authentication to the mitigation portion would complete this fine work.

Kudos!
Logged

CISSP
LSOChris
Guest
« Reply #2 on: July 30, 2006, 10:47:48 AM »

thanks for the good comments and god points, i can add that to the revsion, especially since two-multifactor authentication is getting affordable for the home user.

thanks!
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #3 on: July 30, 2006, 11:36:42 AM »

Well done.

Let me know if you'd be intersted in having us post some of your articles, especially any new ones. We're always looking for good content, and this seems to fit the bill. Keep us posted on a revision to this article. Maybe v2 will have a home at EH-Net?

All the best,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
LSOChris
Guest
« Reply #4 on: August 13, 2006, 10:34:52 PM »

Hug_IT

thanks, i have updated the paper to include multifactor authentication and a few other things like more on ALT characters.  I appreciate the feedback.

Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #5 on: August 14, 2006, 09:26:41 AM »

No problem. It actually spurred some more research for me actually which is very timely being I'm rolling out EFS. The biggest weakness being authentication.

It seems after spending hours and hours reading and testing that NTLMv2 passwords over 14 characters seem pretty strong even with a minimum of complexity. I've read it before but never really taken the time to try and crack something that long. Beyond my technical ability for sure but that may only be for a short time. Still going to stick with two factor though. I think if you get into passwords that long you are almost forcing your users to put it on a sticky note. Of course they'll probably just leave their smartcards in their laptops all the time anyway.  Roll Eyes
Logged

CISSP
LSOChris
Guest
« Reply #6 on: August 14, 2006, 04:34:32 PM »

i can tell you for sure that is what they will do...trust me...i see it everyday at work now that we have gone to smartcard only logons.
Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #7 on: August 14, 2006, 04:59:16 PM »

I think I'm going to try to go to dual purpose cards. We use prox cards for physical access control. If I make them dual purpose then they have to take them out to go anywhere in the building. Hopefully that will help them get used to the idea of removing them when not in use. LOL@myself. Wishful thinking I'm sure.
Logged

CISSP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.06 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.