Security Information

Crack The Code - Thats A Direct Challenge


I Challenge You To Crack The Code
-------------------------------------
I had quite an interesting experience recently. I was hired by a company to perform a vulnerability assessment and penetration test on their network. During the initial meeting, one of the key technical staff presented me with a challenge; He handed over the NTLM hash of the domain Administrator account and challenged me to decipher it. He explained that the complexity and length of the password would prevent me from deciphering it during the time allotted for the project. He was actually quite confident in my impending failure.

In most cases, this individual would have been right on the mark. On the other hand, I'm not sure he expected to challenge someone who has close associates with discretionary time on some of the most powerful computers in the world.

6 Hours, 2 Servers, 64GB of Memory, and 32 Processors Later and.....
------------------------------------
It took just under six hours to decipher the password. Of course, my 'associates' were using a program of my choice on servers with 32 processors and 64GB of RAM a piece. It's nice to have friends with access like this. Especially in my line of work. Needless to say, my client was shocked when I called him the next day and gave him the password.

Let's Have Some Fun: A Challenge For You
----------------------------------------------
(In order for you to do this, you need to go to: http://www.defendingthenet.com/NewsLetters/ CrackTheCode-ThatsADirectChallenge.htm)

Shortly after this experience, I started thinking about writing an article about it. Then I thought to myself, why write just an article? Why not come up with a challenge for our readers?

Hidden in this article is information that will ultimately provide you with a phrase that has been encrypted. You will need to know a few pieces of general information such as, where to find the hash in this article, how to extract the hash from the article, what the password is that will reveal the hash, and what type of hash is being used! Still with me on this? You will need to do all this before you can start cracking the encrypted phrase.

First, you need to find the hashed phrase located in this article. I'll give you a hint; I recently wrote an article about hiding messages in files. This article can be found on the Defending The Net Newsletter Archive. It is also in the www.CastleCops.com archive. Oh, and once you find where the hash is you will need a password to extract it. This one I am going to give away. The password to extract the hash is 'letmein' (without the ' ' of course).

Then, you will need a tool that can easily handle deciphering of the hash once you extract it from this article. There are quite a few out there that will do the job, however, I highly recommend using pnva naq noyr i2.69, a publicly available security tool that no self respecting security engineer should be without. You will also need to know the type of hashing algorithm that was used. I decided to use zrffntr qvtrfg svir because it is relatively well-known. (Try saying that 13 times real fast!)

Conclusion
----------------
The first person to successfully unravel this riddle and e-mail me at riddle@paralogic.net with the deciphered phrase, along with a detailed description of how they accomplished the task, will receive a 512MB, USB2.0 Jump Drive. As soon as we receive this information we will post it on the main page of www.defendingthenet.com.

About The Author
----------------
Darren Miller is an Information Security Consultant with over sixteen years experience. He has written many technology & security articles, some of which have been published in nationally circulated magazines & periodicals. If you would like to contact Darren you can e-mail him at Darren.Miller@ParaLogic.Net


MORE RESOURCES:

How the NSA Took Linux To the Next Level
Slashdot - 6 hours ago
In RBAC, permissions are provided based on roles that are granted by the security system. The concept of a role differs from that of a traditional group in ...
Anatomy of Security-Enhanced Linux (SELinux) OS News
all 1,730 news articles


Private security firms say no way to meet demand of 2010 Winter Games
The Canadian Press, VANCOUVER - 8 hours ago
VANCOUVER — There's no way the private security industry can meet the demands from either Olympic organizers or the RCMP for help during the 2010 Winter ...
RCMP checking into downtown Vancouver hotel for 2010 Olympic Games The Canadian Press
all 32 news articles


No need to check background of cabinet spouses, partners, says Day
The Canadian Press, OTTAWA - 7 hours ago
OTTAWA — Public Safety Minister Stockwell Day says there's no need to run security checks on the spouses or partners of federal cabinet ministers, ...
Minister to face grilling by Commons over judgment Globe and Mail
Foreign Affairs Minister Maxime Bernier under fire CTV.ca
Bloc calls for Bernier security probe Toronto Star
Canada.com - The Gazette (Montreal)
all 321 news articles


Secure Computing delivers security gateway virtual appliances for ...
Al-Bawaba, Jordan - 1 hour ago
Secure Computing Corporation (Nasdaq: SCUR), a leading enterprise gateway security provider, has announced it is working with VMware to provide customers ...


Rebate excludes many taxpayers with foreign spouses
The Associated Press - 8 hours ago
But Shelat is married to a foreigner who still hasn't completed the often years-long process that allows her to apply for a Social Security number. ...


China's biggest city beefs up subway security check
Xinhua, China - 29 minutes ago
The increased workforce was expected to help speed up security checks during work day rush hours to ensure smooth traffic flow as well as improve Metro ...


Peninsula On-line

IB blames 'slack' BSF for infiltration
Times of India, India - 6 hours ago
It is fairly common for security forces engaged in counter-terrorism operations to lower their guard during periods of lull. What is also common is that ...
Jammu terrorist attack defies BSF claims Merinews
Hostage crisis over in Jammu, 2 terrorists killed CNN-IBN
Militants strikes back: Heavy Firing along LoC Little About
Reuters India - CNN-IBN
all 126 news articles


China's energy security moves it closer to the Middle East
Daily Star - Lebanon, Lebanon - 4 hours ago
Therefore China has a significant interest in the Middle East, and any changes in the situation there will affect China's energy security. ...


The Southern Ledger

Security source: Terrorists firing mortars to avoid retaliation
Ynetnews, Israel - 4 hours ago
'We cannot continue living under fire without proper fortification,' one resident says The problem, according to a security source, stems from the ...
Negev council head: Government busy with investigations instead of ... Ynetnews
all 179 news articles


WBT

Gov't of Sudan to lodge complaint to UN Security Council against Chad
Xinhua, China - 5 hours ago
KHARTOUM, May 11 (Xinhua) -- Sudan announced on Sunday it would lodge an official complaint to the United Nations Security Council against Chad's government ...
Sudan steps up security, says Darfur rebels advance Reuters
Sudan Imposes Curfew to Hunt for Darfur Rebels in Capital; Cuts ... Voice of America
Sudan cuts ties with Chad The Associated Press
Yahoo! Italia Notizie - New York Times
all 661 news articles

Security - Google News

home | site map

Visit our other sites:
GamesBlog | GamingDepot | GimmeaRide | GimmeNetwork | Golf Biz | HotorNotGame | I Want Computers | I Want Games | I Want Hosting | I Want Music | I Want Security | JokeBox | ScriptShock | Wantedfonts | Webalize
© 2006