Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 15 guests online
 
Advertisement

You are here: Home arrow Columnsarrow Gatesarrow [Article]-Video: RainbowCrack after MS-SQL/Pwdump Hack
EH-Net
May 19, 2013, 04:54:46 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Video: RainbowCrack after MS-SQL/Pwdump Hack  (Read 15000 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: November 26, 2006, 11:40:36 PM »

Quote
Although this does not follow the exact steps of the article, this video is a companion to Chris Gates' highly popular, definitive work entitled Tutorial: Rainbow Tables and RainbowCrack

Follow along as we perform the following hack:

  • - Hack an MS SQL box.
  • - Dump the password hashes with Pwdump.
  • - Crack the hashes utilizing rainbow tables.

Enjoy and keep an eye out for future videos. Feel free to post comments and suggestions for future videos.

Thanks,
Chris Gates

Video: RainbowCrack after MS-SQL/Pwdump Hack

Don
« Last Edit: November 26, 2006, 11:51:07 PM by don » Logged

CISSP, MCSE, CSTA, Security+ SME
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 385



View Profile WWW
« Reply #1 on: November 27, 2006, 07:56:33 PM »

That was too cool! Thanks for sharing it with all of us.

Slimjim100
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
LSOChris
Guest
« Reply #2 on: November 27, 2006, 10:06:13 PM »

thanks for the feedback!
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #3 on: November 28, 2006, 11:42:08 AM »

Digg this video:

http://www.digg.com/security/Video_All_You_Ever_Wanted_to_Know_About_PW_Cracking_and_Rainbow_Tables

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 385



View Profile WWW
« Reply #4 on: November 28, 2006, 09:37:49 PM »

Dugg Smiley
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
thorin
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #5 on: January 11, 2007, 10:43:50 AM »

Good video, however it would have been much more realistic if you at least included one decent strength password (time lapse it, or highlight the cracking time or whatever).

It was a very illustrative video to show someone the steps however it should also point out the fact that cracking a good password could take days or be impossible. PenTesters would love if all PW crack attempts only took minutes or hours and gave them something to show their clients however that's not really realistic. If you're PenTesting for a client that doesn't have a decent password policy then there's a lot of work they need on sec management, policy and governance before jumping into technical evaluation(s) of their apps, systems, or infrastructure.
Logged
LSOChris
Guest
« Reply #6 on: January 11, 2007, 02:12:40 PM »

thanks for the good feedback.  if you check out the rainbowtables/rainbow crack tutorial that set of password hashes does include some "tough" ones and one that is not stored as LM.  but i dont really get that into analyzing which ones it cracked and which ones it didnt in the vid.

with rainbow tables it will either crack it or not, it wont take days (thats the whole point of them that i spent the time to create the tables and i enjoy a decent % of cracked passwords).  now with john the ripper be prepared to wait...
Logged
thorin
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #7 on: January 11, 2007, 02:24:35 PM »

thanks for the good feedback.  if you check out the rainbowtables/rainbow crack tutorial that set of password hashes does include some "tough" ones and one that is not stored as LM. 

I did notice a few numbers but I didn't notice much mixed case or non-alpha num characters (!@#$%^*, etc).... though I guess that would require a much much larger set of tables.

However, your point about it not taking days is well received. I went hunting after your reply a noticed that passwords of a strength which I'd feel confident suggesting to a client still fell in <20min (based on the example at the bottom of the rainbowcrack.com main page).
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.099 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.