Penetration Testing mailing list archives

AW: Unisphere Password Hashes


From: Marc.Werner () t-systems com
Date: Thu, 8 Sep 2005 10:30:42 +0200

Hi,

this hash seems to be not a base64 hash. I tried to decrypt the one I found in a (real live) config. Cain wasn't able 
to crack this. 
Trying the example from the manual cain showed me "cd1163" as the hex-dump of the given example...
Any other ideas???

Cheers Marc

-----Ursprüngliche Nachricht-----
Von: Miguel Dilaj [mailto:mdilaj () nccglobal com] 
Gesendet: Donnerstag, 8. September 2005 10:02
An: pen-test () securityfocus com
Cc: Werner, Marc
Betreff: RE: Unisphere Password Hashes

Hi Marc,

This is the base64 for "cd1163", so I suppose that this was the password ;-)
Cheers,

Miguel

Does anyone know how the passwords on unisphere (juniper) ERXs are hashed?
They look like zRFj_6>^]1OkZR@e!|S$ (example from the manual). Do they have
different hash types for different 
security levels? Thank you in advance!!!


***********************************************************************************************************
DISCLAIMER:                                                                                                
This e-mail contains proprietary information, some or all of which may be legally privileged.              
It is for the intended recipient only. If an addressing or transmission error has misdirected this e-mail, 
please notify the author by replying to this e-mail. If you are not the intended recipient you may not use,
disclose, distribute, copy, print or rely on this e-mail.                                                  
***********************************************************************************************************

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: