Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <loom.20120421T220939-811@post.gmane.org>
Date: Sat, 21 Apr 2012 20:14:27 +0000 (UTC)
From: donovan <contact.newangels@...il.com>
To: john-users@...ts.openwall.com
Subject: Re: Extract the cracked pass from John.pot

jfoug <jfoug@...> writes:
 
> Thus, I would strongly recommend, to NOT use dynamic_7 (with the -sep=) or
> use the -sep=X flag at all any more.  Yes, it works, but there are better
> ways to proceed.  Dynamic_7 and dynamic_6 are exactly the same, except
> dynamic_7 FORCES you to use the -sep= (dyna 7 may be forced at 3 byte salt
> also, where 6 is not limited).  
> 
> The $HEX$ format is only part of the dynamic_X formats, but it allows this
> very variable format to handle salts which normal JtR would not properly
> handle.  It may require some pre-processing of the hashes, to get the ones
> that need to be HEX'd into the format, but once that is done, JtR should
> find the password just fine.
> 
> Symptoms of this problem would be if you knew you had 1000 'proper' hashes,
> and they are salted 'dynamic' hashes, but when running JtR, it says it can
> only find 963 of them. The other 27 hashes were not found because JtR cut
> the salt.  A worse symptom would be a salted format, that did not have a
> specific 'length' salt (dynamic format).  In that case, JtR may tell you
> that all 1000 were loaded, but if there were 27 with ':' chars in them, the
> salts would be broken (short), and JtR would never find a password for them,
> EVEN if the password was something simple like 12345.   Converting to $HEX$
> within the salt will eliminate any problems like this.
> 
> Jim.



HI Jim,

Thanks a lot for the explain, understand, well, this part come propably from an
old attempt...i allready read & apply your recomendation about "dynamic_6".

Maybe on the next realases you can remove this "dynamic_7" line...if it's not
usefull.

Again, look i my reply to frank i just posted for the reason of my request to
extracted only the plain pass from pot file.

Regards,

Donovan

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.