Penetration Testing mailing list archives

RE: Password cracking / recovery Lotus Notes R6


From: "Richard Zaluski" <rzaluski () ivolution ca>
Date: Mon, 28 Nov 2005 12:57:43 -0500

Can't actually do that, traffic in this regard is encrypted.

Richard Zaluski
CISO, Security and Infrastructure Services 
iVOLUTION  Technologies Incorporated
905.309.1911
866.601.4678
www.ivolution.ca
rzaluski () ivolution ca


-----Original Message-----
From: Joachim Schipper [mailto:j.schipper () math uu nl] 
Sent: Friday, November 25, 2005 5:37 PM
To: pen-test () securityfocus com
Subject: Re: Password cracking / recovery Lotus Notes R6

On Fri, Nov 25, 2005 at 08:38:09AM -0500, Richard Zaluski wrote:
Hello,

Currently I am working with a client to gain access to a Lotus Notes R6
(running on NT) database.  We have full access to the box and need to
penetrate the passwords on the data bases.

Does anyone have tools or techniques they can suggest to achieve this
goal?

Thanks....

Can't you just sniff them off the wire?

                Joachim

----------------------------------------------------------------------------
--
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are

futile against web application hacking. Check your website for
vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers
do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
----------------------------------------------------------------------------
---




------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: