Penetration Testing mailing list archives

policy-based password cracker


From: Chris Costantino <clckct () yahoo com>
Date: Thu, 1 Dec 2005 09:50:10 -0800 (PST)

Hi all,

I am looking for a brute-force password cracker that
can be configured based on password policies.  For
example, I am trying to audit a system that I know the
security policy on (min/max pw length, complexity
rules, etc)  What I want is to only brute-force
passwords that fit that policy.  Obviously, min and
max is not the issue, but I can not seem to find
anything that will only test passwords that meet
complexity requirements (lowercase alpha, uppercase
alpha, number).  Something that generates this into a
rainbow table would be even better.....

Anyone aware of such a tool?

Thanks in advance,
Chris


                
__________________________________________
Yahoo! DSL – Something to write home about.
Just $16.99/mo. or less.
dsl.yahoo.com


------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: