Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Cryptocard database |
|---|---|
| Date: | Thu, 17 Feb 2005 14:50:28 -0700 |
Hi,
Doing an internal pen-test for a company i came across a mysql db that contains the Cryptocard tokens database (root with no password)
The most interesting table (duh !!!) is the "EncryptedKey". Obviously this is not good. I made the usual recommandation to secure the db but i was curious to know if any one had experience with Cryptocard tokens and what is uses to encrypt that field. I presume they use the PIN of each user...???
The size of the field is 48 characters (3DES ?)
I would appreciate any info
Thank you
John
Kurt Seifried, kurt@seifried.org A15B BEE5 B391 B9AD B0EF AEB0 AD63 0B4E AD56 E574 http://seifried.org/security/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Data Mining for PIX Firewall Logs, Michael J McCafferty |
|---|---|
| Next by Date: | Re: TR: Mapping Class A network ( any easy trick?), Vicente Feito |
| Previous by Thread: | Re: Cryptocard database, Noel Rosenberg |
| Next by Thread: | RECON 2005 CFP [Montreal, Canada], Hugo Fortier |
| Indexes: | [Date] [Thread] [Top] [All Lists] |