Easy Cracking with NetLM Downgrade Attacks

DerbyCon 2.0 - The Reunion

Presented by: Dave Howard
Date: Sunday September 30, 2012
Time: 14:00 - 14:50
Location: Track 1
Track: Break Me

Tired of waiting for your GPU to finish cracking that NTLM hash? We will discuss a post exploitation technique to downgrade encryption from NTLM to NetLM, in order to crack 99%+ of 8-15 character passwords over your lunchbreak, without uploading malware of having SYSTEM permissions.

Greetz to: @ReverendDigital @the_m00z @rwnin @shawnmoyer @nathanhamiel @ri0t @natr0nkeltner @hacktalkblog.

Dave Howard

Used to be on defense, but got tired of losing. Moved to offense. Security Consultant, FishNet Security.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats