Live data from Hacker News

L0phtCrack Is Now Open Source

l0phtcrack.gitlab.io

141–150 of 151 posts

Re: L0phtCrack Is Now Open Source

#141

I got expelled from high school because of this program. I'm a millionaire now though so shrug

I didn't get caught.

But as a result of my demonstrative flexing cyber-security activity — I was granted with 'root' credentials on the school's SUSE Linux server… Which apparently at the same time was used as an ISP router for an entire city block.

This granted responsibility, unsurprisingly, turned out to be an extremely effective step to cool my eagerness to hack into all things.

Re: L0phtCrack Is Now Open Source

#142

I haven't thought about Mudge in a long time. If you've ever worked cybersecurity for the government, or in general, you owe him, Brian Oblivion, Space Rogue and the other members of L0pht for opening the door. They were pioneers of responsible disclosure, and brought the problem to light when they testified to Congress in 98 that in 30 minutes they could shut down the Internet. He and the others had uncovered DoS, s…

I don't work in infosec or gov but after reading that bio, I think we all owe him. Thanks for the tip.

Re: L0phtCrack Is Now Open Source

#143
post #94

Earlier quoted context omitted.

You've surely heard about Tor, socks proxies, VPNs, SSH tunnels.

But which ones are really setup by the NSA to get said evidence that will be inconvenient for him at some point in the future? (I suspect Tor, and at least a few of the commercial VPN providers)

It might be true. But what if you chain multiple defenses, each one in states that do not get well with each other? Every investigation will need collaboration.

Re: L0phtCrack Is Now Open Source

#144
post #86

Shame what happened to Terrahash (previous owner of L0phtCrack). As someone who has purchased several Brutalis cracking rigs, those things were the most badass machines on the market. Looks like they sold and committed to a bunch of cracking rigs before sourcing enough GPUs right before prices skyrocketed, and were suddenly on the hook for a lot more than they could realistically pay for. Hopefully Jeremi manages to…

That's disappointing. They have some great systems. I hope they come through it OK.

Re: L0phtCrack Is Now Open Source

#146

> L0phtCrack is a password auditing and recovery application originally produced by Mudge from L0pht Heavy Industries. It is used to test password strength and sometimes to recover lost Microsoft Windows passwords, by using dictionary, brute-force, hybrid attacks, and rainbow tables. - Wikipedia

So it's a hash cracking tool? How does it compare to Hashcat? Any notable distinguishing features?

It's a part of it, also open-source https://gitlab.com/l0phtcrack/hashcatdll

Re: L0phtCrack Is Now Open Source

#147
post #94

Earlier quoted context omitted.

But which ones are really setup by the NSA to get said evidence that will be inconvenient for him at some point in the future? (I suspect Tor, and at least a few of the commercial VPN providers)

It might be true. But what if you chain multiple defenses, each one in states that do not get well with each other? Every investigation will need collaboration.

True, but your last hop to you is usually the most important one. It’s all about a risk analysis on how likely and cheap it would be to use it vs the cost to you if someone does. And keeping in mind that a lot of these agencies have to burn their budget or risk losing it.

Re: L0phtCrack Is Now Open Source

#148
post #94

Earlier quoted context omitted.

But which ones are really setup by the NSA to get said evidence that will be inconvenient for him at some point in the future? (I suspect Tor, and at least a few of the commercial VPN providers)

Some recent news out of the commercial VPN universe... From a cryptographer professor at Johns Hopkins: https://twitter.com/matthew_d_green/status/14493567426896896... Kape, an Israeli 'adware' company that renamed itself to distance itself from its prior history as an adware company, recently bought up ExpressVPN and several other services and rebranded itself as a VPN services company. Kape also bought VPN ranking…

Oof, what VPN is the best for privacy nowadays?

Re: L0phtCrack Is Now Open Source

#149

I remember that the binary for L0phtCrack had some sort of software protection included with it, and it took a 1-bit change to be cracked, itself -- a 0x74 to 0x75, iirc (or 0x74 to 0xEB if you're a stickler for doing it right). I don't remember exactly what the protection was, maybe there was some sort of password count limit or time limit. It was a long time ago. I just remember being a little disappointed that it…

The idea behind the weak license protection was hackers could crack it but it would keep the govt and corps honest.

Re: L0phtCrack Is Now Open Source

#150
post #4

Is it even really relevant anymore?

No. They seem to have been doing a few puff PR pieces recently. Can’t imagine anyone under 30 knows or cares about them. I guess their main claim to fame was being the first “hacker” group to do PR moderately well and transition into decent careers. Not really even an interesting footnote in history.

Hashcat can’t dump password hashes. L0phtcrack can and it has been a core feature for 20 years. I suppose a decent career is founding a security unicorn, Veracode. :)
Post reply on HN