Penetration Testing mailing list archives

Re: [PEN-TEST] Decrypting VNC passwords - Tool required


From: H D Moore <hdm () SECUREAUSTIN COM>
Date: Wed, 23 Aug 2000 12:54:24 -0500

There is an tool called dsniff which can sniff and decrypt these
passwords (and many others) off the wire.

Link: http://freshmeat.net/projects/dsniff/

Dug Song r0x ;)


-HD


David Jacoby wrote:

Dear erica!

if it was just standard DES encyption you can easy use the program John The Ripper. You can download
the program at

ftp://ftp.technotronic.com/unix/passwd-crackers/

//pewp

erica bernt skrev:

Hi Everyone,

I was doing an audit of some systems and managed to
penetrate into the NT domain. I see that VNC is
installed and so I picked up the DES encrypted
password from the registry. As per :

http://www.securiteam.com/securitynews/VNC_3_3_2_R6_uses_a_weak_password_protection_mechanism.html

My specific questions to you is what tool would you
recommend to decrypt this password ? and are there any
other ways to attack VNC ?

On a more general level, what are the most formidable
remote management tools that are out there that you
have most difficulty to detect and penetrate ?

regards Erica

__________________________________________________
Do You Yahoo!?
Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/


Current thread: