Penetration Testing mailing list archives
Re: Password Auditing
From: Christine Kronberg <seeker () shalla de>
Date: Sun, 6 May 2007 09:45:35 +0200 (CEST)
On Fri, 4 May 2007, Mike Gibson wrote:
Can anyone recommend a good password auditing tool. Basically I want to identify weak passwords on my servers (Windows, Linux, Unix). Ideally this would be done by a tool that could remotely fetch the local password database and then attempt to brute force the passwords and prepare a report in a central location. Any suggestions?
I just did something similar for a customer. Basically I used john plus a dictionary and some handwork to create a reporting script. It was not a all-in-one solution but therefore had some more flexibility. Once you defined the specs you are looking for such a reporting script is easily written. Depending on what you define as "weak" using rainbow tables may serve your purpose better. Cheers, Christine Kronberg. ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
Current thread:
- Password Auditing Mike Gibson (May 04)
- RE: Password Auditing Beauchamp, Brian (May 04)
- RE: Password Auditing John Babio (May 04)
- Re: Password Auditing Manuel Arostegui Ramirez (May 04)
- RE: Password Auditing Ken Kousky (May 05)
- Re: Password Auditing kevin (May 04)
- Re: Password Auditing Nico Golde (May 04)
- Re: Password Auditing crazy frog crazy frog (May 06)
- Re: Password Auditing rajat swarup (May 07)
- Re: Password Auditing Christine Kronberg (May 07)
- <Possible follow-ups>
- RE: Password Auditing Brungardt, Jill (May 04)
- Re: Password Auditing kevin.horvath (May 07)