Security Basics mailing list archives

RE: How to decode Yahoo Messenger saved password?


From: "Tom" <tommy () providesecurity com>
Date: Mon, 10 May 2004 20:00:25 -0400


http://www.elcomsoft.com/aimpr.html

Elcomsoft makes great recovery tools!

-----Original Message-----
From: Amin Tora [mailto:atora () EPLUS com] 
Sent: Monday, May 10, 2004 15:00
To: Masroor Ehsan; security-basics () lists securityfocus com
Subject: RE: How to decode Yahoo Messenger saved password?


Hmm.... Don't use yahoo messenger and don't know - how long is the
password hash ; most likely it is a hash if it is actually stored in the
reg. you'll probably have to do a brute force + comparison.


-amin
 

-----Original Message-----
From: Masroor Ehsan [mailto:ophelia () proshikanet-ctg com] 
Sent: Saturday, May 08, 2004 11:07 AM
To: security-basics () lists securityfocus com
Subject: How to decode Yahoo Messenger saved password?

Hi list!
Does anyone know how Yahoo Messenger encrypts it's password? I know it's
stored in the "HKCU/Software/Yahoo/Pager/EOptions String" registry key.
Can anyone share some thought/code on how to decrypt the pass?

The password decoder YPass.exe uses the yahoo dll (ycrwin32.dll).
Anybody knows which functions this program calls?

Regards. 


------------------------------------------------------------------------
---
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
off any course! All of our class sizes are guaranteed to be 10 students
or less to facilitate one-on-one interaction with one of our expert
instructors. 
Attend a course taught by an expert instructor with years of
in-the-field pen testing experience in our state of the art hacking lab.
Master the skills of an Ethical Hacker to better assess the security of
your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------
----


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the
skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------



---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: