Home > Support > Global Security Advisor 

Spyware Detail

L0phtCrack

Date Published:
Monday, August 16, 2004

Threat Assessment

Overall Risk: Critical
Privacy:
Productivity:
System Integrity: Critical

Description


Summary

NT password cracker.

Alias

LC4

Vendor Description

NT password cracker. from the doc: 'a tool for turning Microsoft LANMAN and NT password hashes back into the original clear text passwords. The program does this using dictionary cracking and also brute force. L0phtCrack 1.5 returns not just the LANMAN passord but the NT password up to 14 characters in length. Version 1.0 of L0phtCrack was deficient because the graphical version of the program did not support the brute force method. This has been fixed for version 1.5. The brute force efficiency has been improved and an option to select the character set that makes up the password has been added. The default behavior of L0phtCrack is to do a dictionary attack on the password file and then brute force the remaining uncracked passwords. Sample password files are named pwfile.txt, pwfile2.txt, pwfile3.txt and pwfile4.txt. A 28000 word dictionary file is included named wfile.txt. You can dump passwords directly from L0phtCrack if you have administrator rights. L0phtCrack 1.5 includes the ability to dictionary attack or brute force the network NT server challenge that is used to prevent the OWF from going across the wire in its plaintext format. Sample network sniffed challenges are in files sniff.txt and sniff2.txt. This means you can get NT passwords without administrator privileges if you have network access between the client and the server. You can build the sniff files by hand using your favorite network analyzer or wait for our tool which sniffs the network and builds these files. The sniffing tool will be made available shortly.'

Category

Password Cracker:  A tool to decrypt a password or password file. PestPatrol uses the term both for programs that take an algorithmic approach to cracking, as well as those that use brute force with a password cracking word list. Password crackers have legitimate uses by security administrators, who want to find weak passwords in order to change them and improve system security.



Variants

L0phtCrack 1.5 · L0phtCrack 2.0 FAQ · L0phtCrack 2.0 Manual · L0phtCrack 2.01 · L0phtCrack 2.5 · L0phtCrack 2.5 FAQ · L0phtCrack 2.52 · L0phtcrack 3.0 · L0phtcrack 4.0 · L0phtCrack Technical Rant ·

Immediate Protection Info

 
DAT Release Product DAT Version
OriginaleTrust PestPatrol v4
eTrust PestPatrol v4
eTrust PestPatrol v5
eTrust PestPatrol v4
CA Antispyware v9
eTrust PestPatrol v8
CA Antispyware v9
03 30 2006
08 07 2006
08 11 2004
08 11 2004
08 11 2004
08 11 2004
02 17 2009
LatesteTrust PestPatrol v5
eTrust PestPatrol v4
eTrust PestPatrol v8
eTrust PestPatrol v4
eTrust PestPatrol v4
CA Antispyware v9
07 09 2009
03 28 2006
07 09 2009
08 03 2006
01 11 2007
11 09 2009
 


View Full Details

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All
 
 
Page Tools