Security Information

Crack The Code - Thats A Direct Challenge


I Challenge You To Crack The Code
-------------------------------------
I had quite an interesting experience recently. I was hired by a company to perform a vulnerability assessment and penetration test on their network. During the initial meeting, one of the key technical staff presented me with a challenge; He handed over the NTLM hash of the domain Administrator account and challenged me to decipher it. He explained that the complexity and length of the password would prevent me from deciphering it during the time allotted for the project. He was actually quite confident in my impending failure.

In most cases, this individual would have been right on the mark. On the other hand, I'm not sure he expected to challenge someone who has close associates with discretionary time on some of the most powerful computers in the world.

6 Hours, 2 Servers, 64GB of Memory, and 32 Processors Later and.....
------------------------------------
It took just under six hours to decipher the password. Of course, my 'associates' were using a program of my choice on servers with 32 processors and 64GB of RAM a piece. It's nice to have friends with access like this. Especially in my line of work. Needless to say, my client was shocked when I called him the next day and gave him the password.

Let's Have Some Fun: A Challenge For You
----------------------------------------------
(In order for you to do this, you need to go to: http://www.defendingthenet.com/NewsLetters/ CrackTheCode-ThatsADirectChallenge.htm)

Shortly after this experience, I started thinking about writing an article about it. Then I thought to myself, why write just an article? Why not come up with a challenge for our readers?

Hidden in this article is information that will ultimately provide you with a phrase that has been encrypted. You will need to know a few pieces of general information such as, where to find the hash in this article, how to extract the hash from the article, what the password is that will reveal the hash, and what type of hash is being used! Still with me on this? You will need to do all this before you can start cracking the encrypted phrase.

First, you need to find the hashed phrase located in this article. I'll give you a hint; I recently wrote an article about hiding messages in files. This article can be found on the Defending The Net Newsletter Archive. It is also in the www.CastleCops.com archive. Oh, and once you find where the hash is you will need a password to extract it. This one I am going to give away. The password to extract the hash is 'letmein' (without the ' ' of course).

Then, you will need a tool that can easily handle deciphering of the hash once you extract it from this article. There are quite a few out there that will do the job, however, I highly recommend using pnva naq noyr i2.69, a publicly available security tool that no self respecting security engineer should be without. You will also need to know the type of hashing algorithm that was used. I decided to use zrffntr qvtrfg svir because it is relatively well-known. (Try saying that 13 times real fast!)

Conclusion
----------------
The first person to successfully unravel this riddle and e-mail me at riddle@paralogic.net with the deciphered phrase, along with a detailed description of how they accomplished the task, will receive a 512MB, USB2.0 Jump Drive. As soon as we receive this information we will post it on the main page of www.defendingthenet.com.

About The Author
----------------
Darren Miller is an Information Security Consultant with over sixteen years experience. He has written many technology & security articles, some of which have been published in nationally circulated magazines & periodicals. If you would like to contact Darren you can e-mail him at Darren.Miller@ParaLogic.Net


MORE RESOURCES:

AZFamily

Debit card for Social Security payments
San Francisco Chronicle,  USA - 7 hours ago
The Department of the Treasury said Thursday that nearly 2 million Social Security recipients in 12 Western states will receive information this month about ...
Treasury Department Offers Social Security Debit Card FOXNews
Social Security? Put it on plastic The Oregonian - OregonLive.com
Social Security payment touted Arizona Republic
KOLD-TV - ABC15.com (KNXV-TV)
all 98 news articles


LAX tightens security measures after alleged smuggling
Los Angeles Times, CA - 4 hours ago
By Dan Weikel, Los Angeles Times Staff Writer Airport officials and federal authorities said Thursday that they have tightened security at Los Angeles ...


Security Incidents Fall At East Hartford High, Rise At Middle School
Hartford Courant, United States - 4 hours ago
By KATE FARRISH | Courant Staff Writer EAST HARTFORD — - Arrests and security incidents were down significantly at East Hartford High School but up at East ...


Tribes refuse to accept state's minimum security guidelines for ...
San Diego Union Tribune, United States - 1 hour ago
Background: California's gambling commission wants to adopt minimum security standards for Indian casinos. Tribes say they already spend millions of dollars ...


DIR INFORMATION SECURITY MGMT
Seattle Post Intelligencer - 14 hours ago
Providence Health & Services is recruiting for a Director, Information Security Management (Job #40774, full-time, exempt). This is a replacement position ...
PremiereTec(TM) Solutions LLC Selects Elvis Moreland as New Chief ... PR.com (press release)
all 3 news articles


FiSpace.net Issues MarketStats on Security and Surveillance ...
MarketWatch - 3 hours ago
FiSpace.net offers a platform for investors in security and surveillance equities and the opportunity for investors to respond with their own opinions. ...


Alameda Harbor Bay Isle security guard saves kite boarder
San Jose Mercury News,  USA - 5 hours ago
A crowd hosting a party on Sea View Parkway heard him scream and got the attention of two security guards making their rounds at the nearby Harbor Bay Isle ...


Tight security for PM, Sonia visit
Hindu, India - 5 hours ago
SALEM: Salem city and its suburbs have been brought under a heavy three-fold security blanket as all is set for the foundation stone laying ceremony for ...


ZoneAlarm Internet Security Suite 2009
PC Magazine - 14 hours ago
ZoneAlarm's security suite was showing its age, however, with a dated user interface. Thanks to a comprehensive makeover, the main display in ZoneAlarm ...
ZoneAlarm Internet Security Suite 2009 So-So Spyware Removal PC Magazine
ZoneAlarm Internet Security Suite 2009 Keeping Programs Under Control PC Magazine
ZoneAlarm Internet Security Suite 2009 PC Magazine
PC Magazine - PC Magazine
all 10 news articles


AG: Security guards can detain people in felonies
Chicago Tribune, United States - 10 hours ago
Private security guards can hold people for felonies they didn't see happen. That's according to a new informal legal opinion from Wisconsin Attorney ...

Security - Google News

home | site map
© 2006