Top Banner
Anti-Hacker Tool Kit Chapter 9 Password Password Cracking Cracking Brute-Force Brute-Force Tools Tools Vicky
19

Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Dec 18, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Anti-Hacker Tool Kit

Chapter 9 Password CrackingPassword Cracking

Brute-Force ToolsBrute-Force Tools

Vicky

Page 2: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Introduction

“Password” is the key

Page 3: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

About the password

One-way hash

Plain Text WZYxAM$5IGD3yl

Page 4: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Solaris DES from /etc/passwd Mandrake DES from /etc/shadow FreeBSD MD5 from /etc/shadow OpenBSD Blowfish from /etc/master.pass

wd Windows 2000 from \WINNT\repair\SAM

Where is the password ?Shadow Password

Encrypted Password

Page 5: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Start to Cracking

John the Ripper Pwdump2 Pwdump3 L0phtCrack

SMBGrind Nbaudit

Page 6: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

John the Ripper

• Get the file

• Uncompress

• make

Page 7: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Benchmark

Page 8: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Start to cracking

Page 9: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

1. Task Monitor

2. Find out PID

3. Get the hashs

Pwdump

Grab a text version of the SAM

Usage

Page 10: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Pwdump3

Pwdump2+remote access

Usage

Page 11: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

L0phtCrack

Pwdump + Brute-Force Cracking

Page 12: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Removing the LanMan Hash

Why…

LanMan 69^7MD4 96^8

How to…

LaMan

LaMan LaMan

MD4

Page 13: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Lasdump

Dump the password from memory No cracking

Page 14: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

SMBGrind

Page 15: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Nbaudit

SMBGrind+ Scan address range Specify put file

Usage

Page 16: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Windows may be more security

Run secpol.msc

Page 17: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.

Summary: Strong password

好膽!賣走long

numbers

A-Z

a-z

!@#$%^&

Page 18: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.
Page 19: Anti-Hacker Tool Kit Chapter 9 Password Cracking Brute-Force Tools Vicky.