Monday, March 20, 2006

Pwdump6 (version 1.2 BETA) released.

Pwdump6 (version 1.2 BETA) released.

The ever so popular LanMan password hash grabber has a new release.
Pwdump6, NTLM, LAnManWindows 2000/XP/2003 NTLM and LanMan Password Grabber.

Now with support for Blowfish encryption to secure data. This would make
it possible to evade some IDS signatures. 96-bit key generation scheme.

For those who never have used pwdump, pwdump is used to dump the password hashes
from with the help of DLL injection of the Local Security Authority Subsystem.

What to do with the hashes? Well, if you are doing a password audit, you could
run the hashes through John the Ripper, or @stake LopHtcrack LC3, LC4, to try and extract
weak cleartext passwords. A password with only A-Z characters and no special characters, such as
#!;-[]"# for example, will most likely be broken in a short period of time.