Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20120823170816.GB17849@openwall.com>
Date: Thu, 23 Aug 2012 21:08:16 +0400
From: Solar Designer <solar@...nwall.com>
To: john-dev@...ts.openwall.com
Subject: Re: Mac OS X 10.8 Mountain Lion password hash sample

On Thu, Aug 23, 2012 at 06:51:49PM +0200, Lukas Odzioba wrote:
> According to:
> http://projects.puppetlabs.com/issues/12833
> https://gist.github.com/3258894
> 
> Maybe it is just 15174 or 29069.

The http://projects.puppetlabs.com/issues/12833 page mentions several
other iteration counts as well.  I wonder if Apple makes the iteration
count random (within some range) and stores the value along with the
hash.  (BTW, I think making the iteration count random is a bad idea.
It is also not a new one.)

Once you crack the iteration counts for a few sample hashes (or even for
just one of them), please search for the iteration count in nearby data
(assume little-endian first).

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.