LM & NTLMv1 + challenge
#7
(12-19-2022, 06:57 PM)Chick3nman Wrote: It's not currently released, apologies. I try to only release things in a relatively polished state so I've got quite the backlog of half finished stuff. This is also a little further complicated by the ESS/SSP hashes that do not contain a valid LM challenge response. I've not yet decided how to handle those hashes and if I should trust the user to know better or if I should try and parse the hash to reject them in the module parser.

Hi!
If there is no vaild response, it may simply indicate a wrong password. If think we can filter it out, as with the NTLM version. Even John can not tell, and try to attack such hash with no success. Hope that helps a bit. Smile Tell me if I can help you with testing!
Reply


Messages In This Thread
LM & NTLMv1 + challenge - by jason81 - 12-19-2022, 02:53 PM
RE: LM & NTLMv1 + challenge - by Snoopy - 12-19-2022, 03:09 PM
RE: LM & NTLMv1 + challenge - by Chick3nman - 12-19-2022, 06:57 PM
RE: LM & NTLMv1 + challenge - by jason81 - 12-21-2022, 11:32 PM
RE: LM & NTLMv1 + challenge - by jason81 - 01-24-2023, 11:29 AM
RE: LM & NTLMv1 + challenge - by Chick3nman - 01-24-2023, 05:37 PM
RE: LM & NTLMv1 + challenge - by jason81 - 03-13-2023, 04:12 PM
RE: LM & NTLMv1 + challenge - by jason81 - 04-07-2023, 03:17 PM
RE: LM & NTLMv1 + challenge - by Chick3nman - 04-10-2023, 04:12 AM