Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Password cracking / recovery Lotus Notes R6 |
|---|---|
| Date: | Fri, 25 Nov 2005 16:21:23 -0000 |
Hi Richard, Having access to the box it should be trivial to obtain a copy of the names.nsf and bypass the ACLs (see for techniques on that), or if you've ANY valid user login into Notes and create a COPY (not replica) that will get rid of the ACL anyway. Then get you a copy of Lepton's Crack, and adapt the LotusScript in the readme to incorporate it into your copy of names.nsf and dump all HTTP hashes. If HTTP hashes in the old R4 format are there those can be cracked with Lepton's Crack. Even if Domino is not used perhaps the password is the same for Notes. In regards to Notes itself, its security is pretty good. Basically authentication is like PKI, where you've the ID file for each user that contains the public portion and the private portion encrypted using the user's passphrase... You can still attack (dictionary/bruteforce) ID files, there're a couple programs out there for that purpose. Cheers, Miguel -----Original Message----- From: Richard Zaluski [mailto:rzaluski@ivolution.ca] Sent: 25 November 2005 13:38 To: pen-test@securityfocus.com Subject: Password cracking / recovery Lotus Notes R6 Hello, Currently I am working with a client to gain access to a Lotus Notes R6 (running on NT) database. We have full access to the box and need to penetrate the passwords on the data bases. Does anyone have tools or techniques they can suggest to achieve this goal? Thanks.... Richard Zaluski CISO, Security and Infrastructure Services iVOLUTION Technologies Incorporated 905.309.1911 866.601.4678 www.ivolution.ca rzaluski@ivolution.ca ------------------------------------------------------------------------ ------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 ------------------------------------------------------------------------ ------- Miguel Dilaj Pen Test Consultant NCC Group Manchester Technology Centre, Oxford Road, Manchester, M1 7EF Tel: +44 (0)161 209 5459 Mobile: +44 (0)7811 352 848 Fax: +44 (0)161 209 5400 eMail: Miguel.Dilaj@nccgroup.com website: www.nccgroup.com *********************************************************************************************************** DISCLAIMER: This e-mail contains proprietary information, some or all of which may be legally privileged. It is for the intended recipient only. If an addressing or transmission error has misdirected this e-mail, please notify the author by replying to this e-mail. If you are not the intended recipient you may not use, disclose, distribute, copy, print or rely on this e-mail. *********************************************************************************************************** ------------------------------------------------------------------------------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Re: Nmap scanning speed, tarunthenut |
|---|---|
| Next by Date: | Re: Identifying whether 2 IPs are from the same server, Franck Veysset |
| Previous by Thread: | Re: Password cracking / recovery Lotus Notes R6, thomas springer |
| Next by Thread: | Re: Password cracking / recovery Lotus Notes R6, Simon Marechal |
| Indexes: | [Date] [Thread] [Top] [All Lists] |