Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 14 Jun 2013 00:02:09 +0530
From: Dhiru Kholia <dhiru.kholia@...il.com>
To: john-users@...ts.openwall.com
Subject: Re: rar2john failing?

On 06/13/13 at 01:59pm, Luis Santana wrote:
> Hey, trying to run rar2john on an OSX system but getting the following
> output:
>
> ! -hp mode entry found in 1.rar
> 1.rar:$RAR3$*0*0000000000000000*00000000000000000000000000000000:0::::1.rar

This doesn't look right.

> As this is a file that a client believes is being used to exfiltrate
> data from the network, I sadly cannot share the archive for debugging
> purposes but I hope someone has run into this issue in the past and
> can point me in the right direction.

No one has reported such an issue so far.

Without the actual file there isn't much I can do.

Can you create a similar (but dummy) RAR file for which rar2john fails?

> I hope it's just an OSX issue and I can throw the rar into a Virtual
> Machine to solve this.

Unlikely but who knows? ;)

--
Dhiru

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.