RE: L0phtCrack and Windows 2000 LM Hashes
I would report it to @stake. I have heard of something like this before
with l0phtcrack. It couldn't hurt to report it. Who knows, maybe they
already know of something like this and are planning to fix it in the
next release.
Tyran
-----Original Message-----
From: Chris Mawer [mailto:red_hantu@hotmail.com]
Sent: Thursday, February 06, 2003 2:27 PM
To: focus-ms@securityfocus.com; honeypots@securityfocus.com
Subject: L0phtCrack and Windows 2000 LM Hashes
List,
My win2k box shows that three user-accounts on my windows 2000 machine
report as being *empty*, <8 and 2 of the three share a NULL password LM
Hash
of AAD3B435B51404EEAAD3B435B51404EE. The third hash is different and I
do
not wish to report it here for what id deem obvious reasons.
The three accounts include Administrator and two other users. The
passwords
are known and have been fed into a wordlist. Running LC3 repeats these
results.
The Administrator account is most definitely not NULL, and the other two
accounts are not guest users. Attempting login with null password is
denied
for all three accounts. LC3 is being run on the local machine.
- Should I treat the box as compromised? Highly unlikely as there are
enough alarms in place
- Should I report my findings to @Stake, in the belief LC has a flaw?
Much appreciated,
Chris Mawer
MSN Messenger - fast, easy and FREE! http://messenger.msn.co.uk
Received on Fri Feb 7 11:30:24 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:26 EDT
|