Nmap Development mailing list archives

Re: Replacing passwords.lst


From: David Fifield <david () bamsoftware com>
Date: Sat, 6 Mar 2010 09:54:25 -0700

On Sat, Mar 06, 2010 at 09:15:00AM -0600, Ron wrote:
- john the ripper-like complexity rules -- though much simpler like
adding a '1' to the end of the passwords. We have to keep in mind that
bruteforcing != cracking, so we can't go crazy like john does

I second that--specifically adding "1" to the end of passwords. I think
this could be nicely implemented as another iterator that wraps the
unpwdb.passwords iterator. Other iterators could be combined to add
other fancy accoutrements. My gut says that think "1" is going to be the
single most effective modification.

David Fifield
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: