TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

L0phtcrack 7 will be released as open source

160 pointsby atlacatl_svalmost 4 years ago

6 comments

neilvalmost 4 years ago
Bit of related history about password-cracking tools...<p>A bit before L0pht was founded, one of the open source crackers for Unix passwords was called Crack.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Crack_(password_software)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Crack_(password_software)</a><p>At the time, SunOS was distributing the encrypted passwords for an organization over the LAN via YP (aka NIS). I worked for a company with lots of Suns and other Unix workstations, and I&#x27;d gotten almost all of the non-Suns also configured to use and trust the YP maps. (The goal was to reduce friction to engineering work, and we weren&#x27;t directly connected to the Internet.) So I ran my site&#x27;s passwords through Crack one evening, and it easily got many people&#x27;s passwords. (I don&#x27;t remember how many SPARCstations I threw at it, but it was probably only a few, less than 100 MIPS total.)<p>Things like running Crack were within the scope of the sysadmin side of my job at time, I dutifully reported the concerning results to the head sysadmin, engineers were asked to change weak passwords, and all was good.<p>Some people who ran Crack at some <i>other</i> companies, however, got in big trouble, when there was ambiguity or misunderstanding, about their authority or intent. Besides all the mischief-or-worse uses of Crack that presumably went on. (Disclosure: One of the net.famous people who got a career footnote by running Crack happened to be an acquaintance for a while, years later; I didn&#x27;t ask them about what must&#x27;ve been a pretty upsetting event, and I just now read on Wikipedia that their case was expunged in the end.)
评论 #28031944 未加载
评论 #28031981 未加载
评论 #28033304 未加载
MauranKilomalmost 4 years ago
For context:<p>L0phtCrack -&gt; <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;L0phtCrack" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;L0phtCrack</a><p>DilDog -&gt; <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Christien_Rioux" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Christien_Rioux</a>
评论 #28031123 未加载
评论 #28033717 未加载
评论 #28037241 未加载
0x0nyandesualmost 4 years ago
And this is how I got expelled from high school for &quot;hacking&quot;
评论 #28031061 未加载
评论 #28032074 未加载
评论 #28031021 未加载
stirloalmost 4 years ago
Great follow up tweet [0] where he shows built in a trivial to implement license check bypass for people in the scene. From his comments however it seems like it was never uncovered and instead crackers implemented a more complex difficult licensing bypass on pirated versions.<p>[0] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;dildog&#x2F;status&#x2F;1421877460782698500" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;dildog&#x2F;status&#x2F;1421877460782698500</a>
e12ealmost 4 years ago
I wonder if it&#x27;s any better than hashcat?<p><a href="https:&#x2F;&#x2F;github.com&#x2F;hashcat&#x2F;hashcat" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;hashcat&#x2F;hashcat</a>
评论 #28032421 未加载
walshemjalmost 4 years ago
Interesting that the author mentioned John The Ripper&quot; I remember (with a lot of ass covering) using this at British Telecom back in the day - to break into some NT boxes where a customer had lost the passwords.<p>I got a break quickly (they had used a date as the password) - before I went to stage to stage 2 and used the 20 or so development sun boxes we had over night.
评论 #28031683 未加载