5 ms·
I did the same thing on a server for a major department store chain in the '90s. I booted a Linux diskette and copied the SAM file to it. I also ran l0phtcrac
by b06timmer 4y ago
I did the same thing on a server for a major department store chain in the '90s. I booted a Linux diskette and copied the SAM file to it. I also ran l0phtcrack, or John the Ripper on a 486 (?) PC in my apartment. I think I bought a rainbow table and something else to expand the iterations it would use on the hashes. I let it run for over a week and had a couple of thousand clear passwords. This was for every store west of the Mississippi and included most of the "big-wigs" in our chain.
I was going to send the information to our security people in another state but decided it probably wouldn't be a wise thing to do.
I come across the HDD where I have this stuff archived every now and then and it makes me smile. This was also in the "Free Kevin" days.
- KennyBlanken 4y agoSo you copied the auth file off company servers and cracked it on personal systems and you kept the files and cracked passwords? Not just kept around, but archived? Dude.
- mrelectric 4y agoI think most of us in sec do that.