Related Links

Related Stories

  • Information security and the recession
    As the recession continues to chew into budgets, and cyber criminals see increased opportunity for looting, CIOs must ensure that information security defences remain strong and affordable, even if this means a little bargaining. Stephen Pritchard looks at how organisations can negotiate the rough seas ahead.
  • An Olympic effort to secure the Games
    Managing the security of the 2010 Olympic Games in Vancouver is no mean feat. Danny Bradbury went behind the scenes at the Olympic site to talk to the people who are tasked with ensuring the event goes smoothly
  • Nine lives - when malware becomes self-modifying
    As the Conficker (aka Downadup and Kido) worm proved when it first appeared in October 2008, there's more to a piece of malware code than meets the eye, especially when it is self-updating. But can self-updating also mean self-modifying? Steve Gold investigates whether an IT security manager's nightmare has become programming reality...
  • Keeping sensitive information secure when staff is leaving
    Career loyalty is an endangered creature. Unlike our predecessors, today’s workforce is unlikely to stay committed to a job for five years, let alone their entire lives. But with such a fluid stream of employees keeping human resources busy, and countless eyes being cast over company data, Rob Stringer investigates how sensitive information can stay faithful to its organisation, even if its staff don’t...
  • Leaving a trace
    IT forensics is seen by many in the industry as something of a black art. But it's actually a highly professional discipline, with professional software to assist, as Steve Gold discovers

News

New version of L0phtCrack to be unveiled next week

03 March 2009

Seasoned penetration testers and security experts will recall that L0phtCrack, a seriously heavy-duty password testing utility, was quietly withdrawn by Symantec in 2006, after the IT security vendor reportedly became worried about export regulations of the high-tech software from the United States.

Although the Windows version of the software was commercial, a command
line interface version was free to download and use.

And since the software - whose origins date back to the early 1990s -
was capable of customised dictionary, brute force and rainbow password
attacks, many IT security experts breathed a quiet sigh of relief when
the software was withdrawn in 2006.

Rainbow attacks take advantage of the fact that passwords are normally
stored as the output of a hash function.

As any programmer will attest, hashes are one-way operations. Even if
a cracker gained access to the hashed version of a password, it's not
possible to rebuild the password from the hash value alone.

But it is possible to crack the hashed value of your password using
rainbow tables: huge pre-computed hash values for every possible
combination of characters.

L0phtCrack is a rare breed of security application that uses rainbow
tables, making it a highly dangerous piece of software in the wrong
hands.

And now the original L0pht team that developed the software have
obtained the rights back from Symantec and will be releasing it at the
Source event in Boston when it opens on March 11.

The L0pht IT security think tank is famous in security circles for
when senior members testified to the US Senate in 1998 that they could
bring the Internet down in less than half an hour.

L0pht, as an organisation, ceased to exist in 2000 when its members
formed an IT security collective called @Stake, which was later to be
acquired by Symantec.

According to a blog posting by `Space Rogue,' one of the original team
of L0pht members, version 6 of L0phtcrack will be unveiled at 1015am
on March 11.

Unconfirmed reports suggest that the revised software - codenamed LC6
- is much more powerful than the original and features support for 64-
bit Windows platforms.
 

 

This article is featured in:
Identity and Access Management Internet and Network Security Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.