[130] in Best-of-Security
BoS: FAQ: NT Password Attack & Defences
daemon@ATHENA.MIT.EDU (Alan C. Ramsbottom)
Mon Apr 28 22:27:12 1997
Date: Sat, 26 Apr 1997 20:08:20 +0000
Reply-To: Windows NT BugTraq Mailing List <NTBUGTRAQ@RC.ON.CA>,
"Alan C. Ramsbottom" <acr@ALS.CO.UK>
From: "Alan C. Ramsbottom" <acr@ALS.CO.UK>
Errors-To: best-of-security-request@suburbia.net
To: best-of-security@suburbia.net
Resent-From: best-of-security@suburbia.net
I've written what could loosely be described as a "FAQ" on the
issues surrounding attacks on NT password hashes, once they have
been "extracted" from the SAM.
Russ Cooper has kindly provided a home for a copy of the document
at:
http://ntbugtraq.rc.on.ca/samfaq.htm
It is now revision 1.2. Recent changes include some small (but
significant) increases to the number of punctuation characters
that may be used in a password.
--Alan--
acr@als.co.uk