 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 295
Members: 0
Total: 295
|
|
|
|
|
 |
Full disclosure |
 |
CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS
apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
CVE-2025-59397 - Open Web Analytics SQL Injection
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
Samtools v1.22.1 Improper Handling of Excessive Histogram Bin Counts in Samtools Coverage Leads to Stack Overflow
|
|
|
|
|
|
 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
|
|
obviously not as easy a crack as I hoped it might be.. |
|
|
|
|
I've been running LM alpha tables just against a ton of accounts, with cain.. and it works great, and when it gets 1/2 the pw it shows that 1/2 of it.... Got me about 4000 pw's off the bat.. in just a ... |
|
|
|
|
I'm not sure why it's empty.. other than the pw could be longer than 15 characters??
The pc registry for logon is not set to not keep LM hashes..
Domain policy also does not say "no lm hash'....
... |
|
|
|
|
registry of the pc?
hmmm
could try that... not sure where it would have stored it. |
|
|
|
|
success probability 0
well that sucks... |
|
|
|
|
not forced to change password.
Just looks like it got changed... the 2nd hash did anyway...
hash is now
pandenclv:"":"":AAD3B435B51404EEAAD3B435B51404EE:39C8871C817D9FE0046BD54E566ACC15 |
|
|
|
|
123Gb?
I told winrtgen to do 7-14 characters, lower alpha-numeric, ntlm...
and it says it will do it in 600mb
is that incorrect? |
|
|
|
|
I'll apologize now before I annoy the crap out of you... Appreciate the help.
Got winrtgen... generating tables for pw's of 7-15 characters... that will make 600mb of rainbow tables. I could then d ... |
|
|
|
|
cain/abel w/ the syskey won't work?
As I said, new to this, so I'm kind of grasping at straws...
I thought maybe if I can dump the sam, it would work. |
|
|
|
|
Ok I have a hard drive from the domain controller of the system I was working on, installed into a separate piece of hardware....
So I have this "clone" of the DC, totally outside the network, offlin ... |
|
|
|
|
It seems like it's a possibility. Just not sure.
I went ahead and set the account to reversible. I'm going to dump the AD out tomorrow, and see if C&A can figure anything out..
For whatever rea ... |
|
|
|
|
Seems I can't find much documentation on the "store as reversible" field.
Microsoft doesn't document when the change is made... I've searched everywhere I can think of though.
Anyone tried it ever? |
|
|
|
|
Yes, it's NTLM out of a dump from AD.
I tried to brute force it as well but I couldn't get it. I'm not sure, maybe it's longer of a pw than I thought.
I have a followup question on this, maybe so ... |
|
|
|
|
admittedly new to this, got a few so far, can't get this one.
pandenclv:"":"":AAD3B435B51404EEAAD3B435B51404EE:4355D77672F12CAB3962DBC21A44479A |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|