|
From: Jelmer <jkuperus@planet.nl>
Date: Wed Jun 23 2004 - 22:33:33 EDT
One final addendum to this ongoing thread
Drew Copley was kind enough to point out to me that can steal any user's
What basically happens is that the server sends an 8 byte challenge to the
http://www.insecure.org/sploits/l0phtcrack.lanman.problems.html
If you know the response and you know the challenge (obviously we do since
Anyway great find Bitlance winter!!
Updated demo at
http://jelmer.homedns.org/test2.htm
Updated (very messy) code at
http://jelmer.homedns.org/code2.zip
This page does a pretty good job at describing the ntlm protocol
http://www.innovation.ch/java/ntlm.html
_______________________________________________
This archive was generated by hypermail 2.1.8 : Thu Jun 24 2004 - 00:06:13 EDT |
Custom Search
|