Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Re: Etc/shadow file and john

Subject: Re: Etc/shadow file and john
Date: Wed, 27 Jul 2005 19:38:32 -0500
i dont have much other experience with any other cracker besides john since it does what it does so well, however i can say what steps i take to minimize the length of time it takes to crack. Get yourself several good dictionary files. One english language dictionary, one with first names and one with surnames. I haven't used john in a long time but it used to have the options to run dictionary attacks with variations on the words in the dictionary file. I'd get many hits in a short period like this. After that I would then switch to incremental mode and let it run for as long as i had the patience (4 days for me tops). It doesn't matter the format of the file I believe since it reads the contents into memory anyways. Try that. If you had already done this and I wasted your time I'm sorry.

However, since you were able to get the shadow file this means you have root access and would net more passwords by installing a sniffer like ettercap or dsniff. Just an option.

PS. I like your paints, they shine well (i bet you get that alot)

Terry Vernon
CTO
Sprite Technologies

Sherwyn Williams wrote:

I am doing an assesment for passwords on a network, after getting the password file I piped the output to a text file, tried to run that against John and can't get any luck with the program. Do anyone here uses any other password programs, and is there a better format than a text file to store the out of the etc/shadow when trying to get the passes.
Sherwyn Williams
Technical Consultant
Sherwill22@tmail.com



<Prev in Thread] Current Thread [Next in Thread>