5 ms·
Reminds me of a year or two ago when I had to boot my old SGI. Forgot the user password on IRIX and thought that this is where I'll be clever (hacking terminals
by Keyframe 9y ago
Reminds me of a year or two ago when I had to boot my old SGI. Forgot the user password on IRIX and thought that this is where I'll be clever (hacking terminals, matrix music in the background, etc.). Turns out, IRIX had 8 character limit for user passwords. Thanks to the modern GPUs and a passwd file restored from the system (on a recovery console), a few hours later I had the password brute-forced. I'll get to be clever hax0r next time, I guess.
- mmjaa 9y agoTurns out I need to do that with my old SGI. Got any tips?
- jjwiseman 9y agoNot quite what you're asking, but if you just want to get a shell on the machine, IRIX often had a bunch of accounts with no password. Try lp, demo, games, and guest.
- DanBC 9y agoWould something like John the Ripper, first with wordlists and then with incremental mode, be acceptable? http://www.openwall.com/john/ http://www.openwall.com/john/ http://www.openwall.com/john/doc/ http://www.openwall.com/john/doc/
- Aloha 9y agoBoot from a CD, mount the drive, change the password or remove it - if it were linux I'd edit /etc/shadow - obviously easier with another IRIX machine to put the drive into.
- Keyframe 9y agoMultiple ways to do it. All lead to you getting to the /etc/passwd file and the hash inside for the root. If you have IRIX installation CD then you can even set the new password, but you probably don't have it? You can also put the disk into another SGI, also not what everyone has. If guest account is enabled, login with guest (no password) and just cat the /etc/passwd. If guest account is not enabled, you can do the cat via sash, which is a bit more compicated, like this: https://web.archive.org/web/20151023042224/http://crackaddict.com/~nate/hackirix.html https://web.archive.org/web/20151023042224/http://crackaddic... Once you have your hash, do it with John the Ripper (GPU version). Store the password int a text file in format of root:hash and run john the ripper on it. Encryption is, AFAIK, DES so use john --format=des passwd.txt if john doesn't autodetect which encryption it is (I remember I had to set it manually). It can take awhile, depending on the GPU, but not that long. If you run into trouble, I can have a look. I think I wrote down somewhere what to do, in case I need it again.
- mmjaa 9y agoThanks for this, looks to be not a problem at all! Well, now I've got one less reason to keep the SGI boxes wrapped up, thanks!
- neko_koneko 9y agoWhen I was in similar situation (bought an old SGI O2 box and didn’t had any other SGI machines to plug HDD into to get /etc/passwd), I used telnet RCE/privilege escalation exploit: https://www.exploit-db.com/exploits/20149/ https://www.exploit-db.com/exploits/20149/, worked like a charm. These old systems have many vulnerable services running by default, including telnet.
- mmjaa 9y agoHad some great suggestions, but this one wets my whistle the most, haha! Probably what I'll do, though, is set up SCSI on a linux box somewhere and try to xxx the shadow, seems to be the smoothest route .. don't wanna mess too much, because after all, 20 years later .. I still wanna boot my old SGI like the good ol' days. :)
- contingencies 9y agoTry logging in as lp. Often no password.
- atkbrah 9y agoYou will need /etc/passwd file from SGI the disk. Either use irix installation CDs or boot the system over network [1]. You could also try booting openbsd [2] to get your hands to it. Next you would use something like hashcat [3] to bruteforce the password. 1. http://software.majix.org/irix/install-network.shtml http://software.majix.org/irix/install-network.shtml 2. https://ftp.openbsd.org/pub/OpenBSD/6.2/sgi/INSTALL.sgi https://ftp.openbsd.org/pub/OpenBSD/6.2/sgi/INSTALL.sgi 3. https://hashcat.net/hashcat/ https://hashcat.net/hashcat/
- raverbashing 9y agoI think you don't need a GPU to crack an old password (with crypt?) limited to 8 chars. Better than that only the Windows LM Hashes
- amatecha 9y agoI was in a similar situation. I bought a used SGI Octane, but didn't have the root password and I didn't want to reformat the machine (and didn't have OS discs). It ended up being pretty easy to crack the password, though I can't remember the exact process (this was years ago). Once you have physical access, pretty much any security implementation can be defeated.
- e12e 9y agoI don't know. Cracking passwords using A SUPERCOMPUTER FROM THE FUTURE, seems plenty worthy of some decent theme music...
- ASalazarMX 9y agoI hope he ran the Hollywood script while the password cracker ran modestly in the background https://github.com/dustinkirkland/hollywood https://github.com/dustinkirkland/hollywood
- vidarh 9y agoFits right into Kung Fury [1] - a parody/homage of 80's movies that includes time travel and Hackerman... And a dinosaur, vikings and nazis and David Hasselhoff. It's as bad as it sounds, but in a good way. They fit an impressive amount of 80's movie tropes into 30 minutes. https://www.youtube.com/watch?v=bS5P_LAqiVg&t=1306s https://www.youtube.com/watch?v=bS5P_LAqiVg&t=1306s
- 13of40 9y agoBest one I've seen was a university library card catalog system from the 80s/90s that used unshadowed, 8-character salted passwords via the crypt() function on the Unix box it was on. Inexplicably, whoever wrote the application had limited it to require exactly five uppercase letters, crackable in a few seconds on my 33Mhz 386.
- romwell 9y agoMaybe that was the reason? To provide a way for the developer to do customer support in these cases, that is. The password being there, as the people in the bike store where I bought the lock told me, to keep the honest people honest.
- 13of40 9y agoAnyone with admin access on the Unix box could have just edited the password file and put in a hash for a password they knew.
- kalleboo 9y agoMy high school in the late 90's similarly handed out passwords all composed of 8 (or was it 6?) numbers. Combined with Windows 98's weak hashing (was it LanMan back then?), Cain & Abel on contemporary hardware could reveal them in seconds.