<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Zettalife. &#187; LM cracking</title>
	<atom:link href="http://www.zettalife.com/tag/lm-cracking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zettalife.com</link>
	<description>Zetta = 10^21</description>
	<lastBuildDate>Wed, 14 Jul 2010 23:15:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Si su empresa tiene compatibilidad con windows 9x, entonces es vulnerable.</title>
		<link>http://www.zettalife.com/2009/03/12/si-su-empresa-tiene-compatibilidad-con-windows-9x-entonces-es-vulnerable/</link>
		<comments>http://www.zettalife.com/2009/03/12/si-su-empresa-tiene-compatibilidad-con-windows-9x-entonces-es-vulnerable/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 02:33:40 +0000</pubDate>
		<dc:creator>Zetta</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Seguridad Informática]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[hacking windows]]></category>
		<category><![CDATA[LM cracking]]></category>
		<category><![CDATA[SAM]]></category>
		<category><![CDATA[seguridad windows]]></category>

		<guid isPermaLink="false">http://www.zettalife.com/?p=74</guid>
		<description><![CDATA[¿Por qué es vulnerable su empresa si se tiene compatibilidad con windows 9x? 
Porque la compatibilidad de Windows 9x permite que en la SAM local (y del directorio activo) se almacenen dos tipos de hash: Hash LM (compatibles con windows 9x) y Hash NTLM.  Las debilidades de LM permite que sea &#8216;crackeado&#8217; en poco tiempo. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>¿Por qué es vulnerable su empresa si se tiene compatibilidad con windows 9x? </strong></p>
<p>Porque la compatibilidad de Windows 9x permite que en la SAM local (y del directorio activo) se almacenen dos tipos de hash: Hash LM (compatibles con windows 9x) y Hash NTLM.  Las debilidades de LM permite que sea &#8216;crackeado&#8217; en poco tiempo. (Ver <a href="http://www.zettalife.com/2008/11/24/respuesta-a-la-pregunta-%c2%bfcual-hash-debo-crackear-lm-o-ntlm/" target="_blank">cracking lm vs ntlm</a>).</p>
<p>Puede que en su empresa no tengan ningún equipo 9x, pero Windows 2000, xp y 2003, TIENEN HABILITADOS POR DEFECTO la compatibilidad con windows 9x, y por lo tanto almacenan en la SAM tanto LM como NTLM.</p>
<p><strong>¿Cómo evitar almacenar hashes LM?</strong></p>
<p>Seguir las recomendaciones de microsot en su artículo: http://support.microsoft.com/kb/299656 el cual practicamente dice:</p>
<blockquote>
<ol>
<li>En Directiva de grupo, expanda <strong class="uiterm">Configuración del 				equipo</strong>, <strong class="uiterm">Configuración de Windows</strong>, 				<strong class="uiterm">Configuración de seguridad</strong>, <strong class="uiterm">Directivas 				locales</strong> y, a continuación, haga clic en <strong class="uiterm">Opciones de 				seguridad</strong>.</li>
<li>En la lista de directivas disponibles, haga doble clic en 				<strong class="uiterm">Seguridad de red: no almacenar valor de hash de LAN Manager en el 				próximo cambio de contraseña</strong>.</li>
<li>Haga clic en <strong class="uiterm">Habilitado</strong> y después en 				<strong class="uiterm">Aceptar</strong>.</li>
</ol>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.zettalife.com/2009/03/12/si-su-empresa-tiene-compatibilidad-con-windows-9x-entonces-es-vulnerable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Benchmark LM Cracking &#8211; CPU vs. GPU &#8211; John the Ripper vs. Cain vs. Elcomsoft Distributed Password Recovery</title>
		<link>http://www.zettalife.com/2008/11/22/benchmark-lm-cracking-cpu-vs-gpu-john-the-ripper-vs-cain-vs-elcomsoft-distributed-password-recovery/</link>
		<comments>http://www.zettalife.com/2008/11/22/benchmark-lm-cracking-cpu-vs-gpu-john-the-ripper-vs-cain-vs-elcomsoft-distributed-password-recovery/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 01:13:58 +0000</pubDate>
		<dc:creator>Zetta</dc:creator>
				<category><![CDATA[Benchmark]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[cpu vs gpu]]></category>
		<category><![CDATA[Cracking Benchmark]]></category>
		<category><![CDATA[gpu cracking]]></category>
		<category><![CDATA[LM cracking]]></category>
		<category><![CDATA[password cracking]]></category>

		<guid isPermaLink="false">http://www.zettalife.com/?p=43</guid>
		<description><![CDATA[Hi to all. This is my firs post in english (I&#8217;m not the best writing in english).
I made a Benchmark for LM Cracking using my laptop:
Dell XPS M1530
Intel Core 2 Duo T7500 2.2Ghz
4 GB RAM
Windows Vista Ultimate
Hard Disk 120 GB 7200 RPM
Nvidia Gforce 8600M GT 256 MB
I Used:

John The Ripper (386 and mmx)
Cain
Elcomsoft Distributed Password [...]]]></description>
			<content:encoded><![CDATA[<p>Hi to all. This is my firs post in english (I&#8217;m not the best writing in english).</p>
<p>I made a Benchmark for LM Cracking using my laptop:</p>
<p>Dell XPS M1530<br />
Intel Core 2 Duo T7500 2.2Ghz<br />
4 GB RAM<br />
Windows Vista Ultimate<br />
Hard Disk 120 GB 7200 RPM<br />
Nvidia Gforce 8600M GT 256 MB</p>
<p>I Used:</p>
<ul>
<li>John The Ripper (386 and mmx)</li>
<li>Cain</li>
<li>Elcomsoft Distributed Password Recovery</li>
</ul>
<p><strong>BENCHMAR</strong></p>
<p>The objetive was test how many password/seg could be cracked using diferent software.<br />
There are crackers based in cpu and recently in gpu.<br />
For CPU test, I used John the ripper (386 and mmx) and CAIN.<br />
For GPU test, I used Elcomsoft Distributed Password Recovery. Although this software allow more than 1 cliente, I only used my own laptop.</p>
<p>Here we go.</p>
<p><strong>JOHN THE RIPPER 386. Speed: 4 M/s</strong></p>
<p><strong></p>
<div id="attachment_78" class="wp-caption alignnone" style="width: 454px"><strong><img class="size-full wp-image-78" title="LM cracking with John The Ripper 386" src="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-with-1cpu-4m-john.png" alt="John the ripper 386 test in core 2 duo 2.2GHZ" width="444" height="199" /></strong><p class="wp-caption-text">John the ripper 386 test in core 2 duo 2.2GHZ</p></div>
<p></strong></p>
<p><strong>JOHN THE RIPPER MMX. Speed: 9.2 M/s</strong></p>
<div id="attachment_45" class="wp-caption alignnone" style="width: 310px"><a href="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-with-1cpu-9m-john-mmx.png"><img class="size-medium wp-image-45" title="Lmcracking with john the ripper -mmx" src="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-with-1cpu-9m-john-mmx-300x134.jpg" alt="John the ripper mmx test in core 2 duo 2.2 Ghz" width="300" height="134" /></a><p class="wp-caption-text">John the ripper mmx test in core 2 duo 2.2 Ghz</p></div>
<p><strong>CAIN. Speed: ~8 M/s</strong></p>
<div id="attachment_46" class="wp-caption alignnone" style="width: 310px"><a href="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-with-1cpu-8m.png"><img class="size-medium wp-image-46" title="LmCracking CAIN at 8 M/s " src="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-with-1cpu-8m-300x220.png" alt="Cain cracking LM hash in core 2 duo 2.2 Ghz" width="300" height="220" /></a><p class="wp-caption-text">Cain cracking LM hash in core 2 duo 2.2 Ghz</p></div>
<p><strong>ELCOMSOFT DISTRIBUTED PASSWORD RECOVERY (GPU). Speed: 22.5 M/s</strong></p>
<div id="attachment_47" class="wp-caption alignnone" style="width: 310px"><a href="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-with-gpu-22m.png"><img class="size-medium wp-image-47" title="LM cracking with gpu" src="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-with-gpu-22m-300x198.png" alt="Elcomsoft Distributed Password Recover with 1 GPU cracking at 22.5 M/s" width="300" height="198" /></a><p class="wp-caption-text">Elcomsoft Distributed Password Recover with 1 GPU cracking at 22.5 M/s</p></div>
<p><strong>FULL RESULTS </strong></p>
<p>EDPR (gpu):            22572914 c/s<br />
John mmx (cpu):       9230000 c/s<br />
Cain (cpu):                7969348 c/s<br />
John 386 (cpu):         4043000 c/s</p>
<div id="attachment_48" class="wp-caption alignnone" style="width: 670px"><a href="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-benchmark.jpg"><img class="size-full wp-image-48" title="Lm Cracking Benchmark" src="http://www.zettalife.com/wp-content/uploads/2008/11/lmcracking-benchmark.jpg" alt="Lm Cracking Benchmark" width="660" height="405" /></a><p class="wp-caption-text">Lm Cracking Benchmark</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.zettalife.com/2008/11/22/benchmark-lm-cracking-cpu-vs-gpu-john-the-ripper-vs-cain-vs-elcomsoft-distributed-password-recovery/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
