Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  NEWS  community  lists  Wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Sun, 10 Feb 2008 08:28:29 +1300
From: Russell Fulton <r.fulton@...kland.ac.nz>
To: john-users@...ts.openwall.com
Subject: extracting hashes from openldap for cracking

Hi Folks

Bloody spammers have found out webmail system and have managed to  
guess a few passwords :( Running JtR over this has been on my todo  
list for a long time but never made it to the top :(  Now it is rather  
urgent, I'm getting sick of playing whack a mole!

The IMAP server which all the cracked accounts are on uses openldap  
for authentication.  The conf files says that the passwords are stored  
in crypt hashes and the database is ldbm.

Given time I am sure I can cook up some perl to pull the hashes out  
into something that I can feed to JtR but I'm hoping that someone has  
already done this and can point me to a script.

Thanks, Russell


-- 
To unsubscribe, e-mail john-users-unsubscribe@...ts.openwall.com and reply
to the automated confirmation request that will be sent to you.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ