[geeks] IRIX, Passwords over 8 char?

Bill Bradford mrbill at mrbill.net
Thu Apr 4 00:53:39 CST 2002


On Thu, Apr 04, 2002 at 01:50:53AM -0500, Ethan wrote:
> What is the big deal anyways? Who cares if the system accepts more than 8
> character passwords. No body brute forces DES encrypted password hashes...

They dont?  I did a couple of weeks ago to get into a box where the person
responsible for it had left without leaving the password, and the password
file was on an xfs partition.. I could *read* it, but not *write* to it
while booted w/sash; so I wrote down the hash, walked over to my Solaris
box, and ran a cracker on that hash.

Took about thirty seconds, and I had a password that got me into the box.

Bill

-- 
Bill Bradford
mrbill at mrbill.net
Austin, TX



More information about the geeks mailing list