Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 52 guests and 3 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Tutorialsarrow Rainbow Tables/Crack whitepaper
EH-Net
May 25, 2012, 05:01:29 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Rainbow Tables/Crack whitepaper  (Read 7639 times)
0 Members and 2 Guests are viewing this topic.
LSOChris
Guest
« on: July 29, 2006, 04:24:33 PM »

all, you can read my Rainbow Tables/ Rainbow Crack whitepaper here:

http://www.windowsecurity.com/whitepapers/Rainbow_Tables__RainbowCrack_Introduction1614.html


comments always welcome.
Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #1 on: July 30, 2006, 10:17:45 AM »

Great job on that paper Chris. Explains it in a very readable manner that a user could understand and still comprehensive enough for an experience security pro to get something out of it.

About the only criticism that I could think of is more of just opinion than a problem with the paper. NTLM tables are becoming easily available for anyone that really wants them and I'm somewhat paranoid so I take the stance that passwords just aren't a secure way to authenticate. Two part authentication is really the only way to protect yourself. You address this by stating all but the most determined attacker but I think the addition of two part authentication to the mitigation portion would complete this fine work.

Kudos!
Logged

CISSP
LSOChris
Guest
« Reply #2 on: July 30, 2006, 10:47:48 AM »

thanks for the good comments and god points, i can add that to the revsion, especially since two-multifactor authentication is getting affordable for the home user.

thanks!
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3917


Editor-In-Chief


View Profile WWW
« Reply #3 on: July 30, 2006, 11:36:42 AM »

Well done.

Let me know if you'd be intersted in having us post some of your articles, especially any new ones. We're always looking for good content, and this seems to fit the bill. Keep us posted on a revision to this article. Maybe v2 will have a home at EH-Net?

All the best,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
LSOChris
Guest
« Reply #4 on: August 13, 2006, 10:34:52 PM »

Hug_IT

thanks, i have updated the paper to include multifactor authentication and a few other things like more on ALT characters.  I appreciate the feedback.

Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #5 on: August 14, 2006, 09:26:41 AM »

No problem. It actually spurred some more research for me actually which is very timely being I'm rolling out EFS. The biggest weakness being authentication.

It seems after spending hours and hours reading and testing that NTLMv2 passwords over 14 characters seem pretty strong even with a minimum of complexity. I've read it before but never really taken the time to try and crack something that long. Beyond my technical ability for sure but that may only be for a short time. Still going to stick with two factor though. I think if you get into passwords that long you are almost forcing your users to put it on a sticky note. Of course they'll probably just leave their smartcards in their laptops all the time anyway.  Roll Eyes
Logged

CISSP
LSOChris
Guest
« Reply #6 on: August 14, 2006, 04:34:32 PM »

i can tell you for sure that is what they will do...trust me...i see it everyday at work now that we have gone to smartcard only logons.
Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #7 on: August 14, 2006, 04:59:16 PM »

I think I'm going to try to go to dual purpose cards. We use prox cards for physical access control. If I make them dual purpose then they have to take them out to go anywhere in the building. Hopefully that will help them get used to the idea of removing them when not in use. LOL@myself. Wishful thinking I'm sure.
Logged

CISSP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.295 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.