 |
Further
Reading ...
|
|
Boomerang, Don't Ricochet your Web Site Visitors You don't win your visitors' trust right away. It may take from 4-7 visits before they buy. You must always give them a reason to buy, and not offend them in any way because they will ricochet to other sites. Here's some things I do to get people...
Force the download, hide the path Force the download, hide the path This is an article about providing downloads on a website. It describes common webmaster issues when it comes to file downloads and it will discuss several solutions. Some of them are easy to implement, others...
Adware: How to Beat the Sneakiest Software Promoters of adware, software that shows advertising on a user's computer, use some cunning tricks to get you to install their software on your machine.
Here's what to look out for.
Adware is, by definition, something reasonable people don't...
No Use Crying Over Spilled Ink The dreaded blinking light, it happens to the best of us. Your school project is due in one hour or your boss wants a copy of the latest business report on his desk as soon as possible, preferably before the early morning meeting with the president....
|
|
|
Crack The Code - That's A Direct Challenge
|
 |
Written By:
Darren Miller
|
|
|
You may reprint or publish this article free of charge as long as the bylines are included.
Original URL (The Web version of the article)
------------
Crack The Code - That's A Direct Challenge
Title
-----
Crack The Code - That's A Direct Challenge
I Challenge You To Crack The Code
-----------------------------------------------
I had quite an interesting experience recently. I was hired by a company to perform a vulnerability assessment and penetration test on their network. During the initial meeting, one of the key technical staff presented me with a challenge; He handed over the NTLM hash of the domain Administrator account and challenged me to decipher it. He explained that the complexity and length of the password would prevent me from deciphering it during the time allotted for the project. He was actually quite confident in my impending failure.
In most cases, this individual would have been right on the mark. On the other hand, I'm not sure he expected to challenge someone who has close associates with discretionary time on some of the most powerful computers in the world.
6 Hours, 2 Servers, 64GB of Memory, and 32 Processors Later and.....
--------------------------------------
It took just under six hours to decipher the password. Of course, my 'associates' were using a program of my choice on servers with 32 processors and 64GB of RAM a piece. It's nice to have friends with access like this. Especially in my line of work. Needless to say, my client was shocked when I called him the next day and gave him the password.
Let's Have Some Fun: A Challenge For You
----------------------------------------------
(In order for you to do this, you need to go to: http://www.defendingthenet.com/NewsLetters/ CrackTheCode-ThatsADirectChallenge.htm)
Shortly after this experience, I started thinking about writing an article about it. Then I thought to myself, why write just an article? Why not come up with a challenge for our readers? - continued below ...
|
|
|
continued ...
Hidden in this article is information that will ultimately provide you with a phrase that has been encrypted. You will need to know a few pieces of general information such as, where to find the hash in this article, how to extract the hash from the article, what the password is that will reveal the hash, and what type of hash is being used! Still with me on this? You will need to do all this before you can start cracking the encrypted phrase.
First, you need to find the hashed phrase located in this article. I'll give you a hint; I recently wrote an article about hiding messages in files. This article can be found on the Defending The Net Newsletter Archive. It is also in the www.CastleCops.com archive. Oh, and once you find where the hash is you will need a password to extract it. This one I am going to give away. The password to extract the hash is 'letmein' (without the ' ' of course).
Then, you will need a tool that can easily handle deciphering of the hash once you extract it from this article. There are quite a few out there that will do the job, however, I highly recommend using pnva naq noyr i2.69, a publicly available security tool that no self respecting security engineer should be without. You will also need to know the type of hashing algorithm that was used. I decided to use zrffntr qvtrfg svir because it is relatively well-known. (Try saying that 13 times real fast!)
Conclusion
----------------
The first person to successfully unravel this riddle and e-mail me at riddle@paralogic.net with the deciphered phrase, along with a detailed description of how they accomplished the task, will receive a 512MB, USB2.0 Jump Drive. As soon as we receive this information we will post it on the main page of www.defendingthenet.com and www.castlecops.com.
About the Author
About The Author
----------------
Darren Miller is an Information Security Consultant with over sixteen years experience. He has written many technology & security articles, some of which have been published in nationally circulated magazines & periodicals. Darren is a staff writer for www.defendingthenet.com
|
|
|
|
 |
|
|
| _Additional Resources ... |



|
It Really Is Simple RSS I have 'Googlebot' coming to my site every day since a month ago I put up my first news feed, since then I have put up yet another. I never used to see 'Googlebot' much before, so it goes to show that if you want to be noticed by the search...
Overview of HTTP If you have been using the internet for a while, you have probably typed into your browser something that starts with "http:" and ends with ".html", hit "Go", watched your modem lights flicker on and off, and a couple of seconds later you are...
Broadband Feature Connections Broadband Features Available
The variety of Internet service providers available is growing as the Internet makes its way into more homes in America. This proliferation of ISP providers makes it difficult to decide which ISP you should subscribe...
|
|
|
|
|
|
 |
|
|
|