Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: taxcontrol
I see that you haven't been introduced to rainbow tables. The typical hash used is md5. If you can get the shadow password file off a Linux system, you then take the md5 associated with the user you want (usually root) and run that through the rainbow table. It will hand you an ascii string that produces the md5 sum. The advent of cloud computing means there are many rainbow table servers sitting on the web to provide the lookup service.

If you want to know more details about system security, sign up for SANS classes. They are worth the time and money.

79 posted on 07/25/2013 5:46:05 PM PDT by Myrddin
[ Post Reply | Private Reply | To 8 | View Replies ]


To: Myrddin

Dictionary attacks were popular 20 years ago.

Which makes me wonder why they need the passwd file. If they’ve got control of the network they can just see the password in transit.


87 posted on 07/25/2013 6:05:55 PM PDT by Black Agnes
[ Post Reply | Private Reply | To 79 | View Replies ]

To: Myrddin

I figured it had already been done...


106 posted on 07/25/2013 6:49:04 PM PDT by null and void (You don't know what "cutting edge" means till you insult Mohammed.)
[ Post Reply | Private Reply | To 79 | View Replies ]

To: Myrddin

Actually I am very aware of rainbow tables and if you review my other posts, you will find that I also describe other ways one can obtain the password. I will point out that rainbow tables ARE NOT reversing the hash. A rainbow table is just a more educated brute force attack.

Many SANS classes are worth the money. However, I already have my CISSP and hold patents in cryptography so I’m not really interested in the majority of classes they offer.


173 posted on 07/26/2013 9:17:37 AM PDT by taxcontrol
[ Post Reply | Private Reply | To 79 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson