Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Gold at the end of rainbow cracking?
Robert Lemos, SecurityFocus 2005-11-09

A trio of entrepreneurial hackers hope to do for the business of password cracking what Google did for search and, in the process, may remove the last vestiges of security from many password systems.

Comments Mode:
Gold at the end of rainbow cracking? 2005-11-10
Anthony LAI, CISSP, CISM (1 replies)
Gold at the end of rainbow cracking? 2005-11-10
Mike B (3 replies)
I feel like I must be missing something, but aren't the hashes of the passwords usually stored in a protected file, such as /etc/shadow?

Regardless as to whether or not the password is hashed, shouldn't it still be hidden from normal users? Shouldn't it be non-trivial to collect the hashes to submit to a rainbow cracking database unless you are the system admin anyway?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11355/32711#32711
Gold at the end of rainbow cracking? 2005-11-11
Anonymous (1 replies)







 

Privacy Statement
Copyright 2009, SecurityFocus