Penetration Testing mailing list archives

RE: Password cracker tool


From: "Robert Belk" <robertb () Westernnb com>
Date: Mon, 29 Jan 2007 17:01:36 -0600

We have used a tool called LCP. It is freeware, and worked very well. It
has dictionary / brute force / hybrid attacks. We used it on our domain
accounts and liked it very well. I can't remember if it can scan web
logons or printers.

http://www.lcpsoft.com/english/index.htm 

Thank you,
 
Robert Belk
Network Security Administrator
Phone: 432.617.1274
Email: robertb () westernnb com
Web: www.wnbonline.com
 
 

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Milind Nanal
Sent: Monday, January 29, 2007 12:09 AM
To: pen-test () securityfocus com
Subject: Password cracker tool


Dear list,

I am looking for password dictionary / brute force / hybrid password
cracker tool. 
I have default set of user name & password using which I want to check
my network for below scenarios. 

1) Try default user/password on web logon service on all network
management device on the subnet
2) Try default password on all Windows exchange server domain account.
3) Try default user/password on all network printer management web
logon.

 The tool should be run on Windows /  MS DOS systems.  I can have
preferably common tool or separate tools for each scenario. 
This will help auditing weak password management within LAN.

Regards,

Milind 
Disclaimer:
This e-mail may contain Privileged/Confidential information and is 
intended only for the individual(s) named. Please notify the sender, if 
you have received this e-mail by mistake and delete it from your system.

Information in this message that do not relate to the official business
of 
the company shall be understood as neither given nor endorsed by it. 
E-mail transmission cannot be guaranteed to be secure or error-free. The

sender does not accept liability for any errors or omissions in the 
contents of this message which arise as a result of e-mail transmission.

If verification is required please request a hard-copy version.
Visit us at www.kaleconsultants.com

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=7016
00000008bOW
------------------------------------------------------------------------

#####################################################################################
Note:
This message is for the named person's use only.  It may contain confidential,
proprietary or legally privileged information.  No confidentiality or privilege
is waived or lost by any mistransmission.  If you receive this message in error,
please immediately delete it and all copies of it from your system, destroy any
hard copies of it and notify the sender.  You must not, directly or indirectly,
use, disclose, distribute, print, or copy any part of this message if you are not
the intended recipient. Western National Bank and any of its subsidiaries each reserve
the right to monitor all e-mail communications through its networks.

Any views expressed in this message are those of the individual sender, except where
the message states otherwise and the sender is authorized to state them to be the
views of any such entity.

Thank You.
#####################################################################################

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: