To run your first crack, click OK in the Auditing Options For This Session dialog box, then select Session, Begin Audit. LC3 proceeds through the different types of cracks, as Web Figure 1 shows. (To view this figure, go to http://www.secadministrator.com and enter InstantDoc ID 24052.) During the dictionary and hybrid attacks, you can see how far along LC3 is by looking under Dictionary Status in the interface's right pane. During brute-force cracks, LC3 displays its progress statistics under Brute Force in the right pane. As LC3 completes each password-cracking approach, LC3 checks off that type with a red check mark in the interface's bottom right corner. Whenever LC3 cracks a password, it displays the amount of time it took in the Audit Time column and displays the password in the LM Password and NTLM Password columns.
Occasionally, you'll see the last portion of a password preceded by seven question marks, such as the SavvyUser's password, which Web Figure 1 shows. Passwords can be up to 14 characters long. Because of vulnerabilities in the LM hash algorithm, LC3 can work on the first and second sets of seven characters independently. LC3 often cracks the last seven characters of a password before the first seven, which is important because those characters might offer a clue to the beginning portion of the password. . . .
jslocumb March 31, 2008 (Article Rating: