Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Ophcrack Bug
EH-Net
May 23, 2013, 07:25:59 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Ophcrack Bug  (Read 4154 times)
0 Members and 1 Guest are viewing this topic.
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« on: September 24, 2012, 09:15:44 PM »

If anyone has a moment to test something, I would greatly appreciate it.

I think the most recent version of Ophcrack for both Linux and Windows has a bug. I've tested this on two separate machines and am getting the same result.

The problem is when Ophcrack cracks a password that contains a colon. It's not that it cant crack it, in fact the password does display correctly on the screen (both in the non gui *nix version on the screen as well as within the windows gui), but when it writes to an output file it mangles the colon.

It seems every time there is a colon, it replaces it with a ---> Á (C1 in hex). I am 100% certain the password does not have this character and when I double check by checking the NT hash, it does contain a colon.

Bizzare, just wondering if anyone can validate my claims.

For your own testing, you can use this hash:
2d6b481f44d7f18a5acdcd7c247fa83a:a903feb8614046a6bf6dde39fd334ffc

which = the password 2012:meh

WTF

« Last Edit: September 24, 2012, 10:04:34 PM by cd1zz » Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #1 on: September 25, 2012, 02:40:06 AM »

I tested with v3.4 of the Windows GUI. It displays fine in the GUI, but this is what is saved to file:

Code:
::2d6b481f44d7f18a5acdcd7c247fa83a:a903feb8614046a6bf6dde39fd334ffc:2012ÁME:H:2012Ámeh
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #2 on: September 25, 2012, 07:53:27 AM »

NICE, its not just me. Thanks for doing that.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.059 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.