Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Gold at the end of rainbow cracking?
Robert Lemos, SecurityFocus 2005-11-09

A trio of entrepreneurial hackers hope to do for the business of password cracking what Google did for search and, in the process, may remove the last vestiges of security from many password systems.

Comments Mode:
Gold at the end of rainbow cracking? 2005-11-10
Anthony LAI, CISSP, CISM (1 replies)
Gold at the end of rainbow cracking? 2005-11-10
Mike B (3 replies)
Re: Gold at the end of rainbow cracking? 2005-11-10
Pete (3 replies)
Re: Re: Gold at the end of rainbow cracking? 2005-11-11
Anonymous
I believe the issue is to do with defence in depth, and the known proclivities of people to use the same passwords on different systems. (if this isn't the case, I'd be glad to hear!)

So, you break into one system and gain admin rights (bypassing the password system somehow, or using a password cracked from another system from a stolen password hash), then you crack the passwords, and can use them on *other computers*, as well as the one you originally broke into.

Once you've broken in and got admin rights, you don't need so much to crack passwords to do bad things, like read or alter sensitive data. However, if you have a password perhaps it's a more stealthy way to continue your nefarious activities? There's no rootkit left around to detect, though if you use someone's password and assume their identity - that leaves traces of system usage that can be picked up in audit logs.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11355/32722#32722
Gold at the end of rainbow cracking? 2005-11-11
Anonymous (1 replies)







 

Privacy Statement
Copyright 2009, SecurityFocus