BugTraq
Kerberos login sniffer and cracker for Windows 2000/XP Nov 28 2002 06:06AM
Arne Vidstrom (arne vidstrom ntsecurity nu) (1 replies)
RE: Kerberos login sniffer and cracker for Windows 2000/XP Dec 02 2002 02:24AM
Jason Coombs (jasonc science org)
Aloha, Arne.

Where can we find the source code for kerbcrack?

It may be useful to point out that Internet Explorer 5.0 and later support
Kerberos authentication by way of a Negotiate WWW-Authenticate header that
is always sent by IIS paired with a classic NTLM WWW-Authenticate header. IE
sends BOTH NTLM and Kerberos authorization data back to IIS, letting it pick
the one it prefers to use.

Kerbcrack points out the need for IPSec to be used in conjunction with
Kerberos, but lazy client implementations that can't be forced to stop using
older less-secure authentication methods concurrently with Kerberos are also
an ongoing problem.

Sincerely,

Jason Coombs
jasonc (at) science (dot) org [email concealed]

-----Original Message-----
From: Arne Vidstrom [mailto:arne.vidstrom (at) ntsecurity (dot) nu [email concealed]]
Sent: Wednesday, November 27, 2002 8:06 PM
To: bugtraq (at) securityfocus (dot) com [email concealed]
Subject: Kerberos login sniffer and cracker for Windows 2000/XP

Hi all,

I've coded a simple Kerberos login sniffer and cracker for Windows 2000/XP
that you might find useful. You can find it for download at:

http://ntsecurity.nu/toolbox/kerbcrack/

Regards /Arne

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus