L0phtCrack (v6) Rises Again
FyreWyr writes "L0phtCrack — now 12 years old — used to be a security 'tool of choice' for black hats, pen-testers, and security auditors alike — that is, until it was sold by L0pht to @stake, then Symantec, to be released and subsequently dropped as LC 5. As an IT security consultant, I used this tool to regularly expose vulnerabilities or recover data when there were few other options available. Eventually, I let it go as tech evolved away. Now, after being returned to its original developers, version 6 was released this week with fresh features: support for 64-bit multiprocessors, (current) Unix and Windows operating systems, and a number of other features, including enhanced handling of NTLM password hashes and support for rainbow tables. Interested parties, especially consultants, will find this shiny new version sports a hefty price tag. It raises doubts in my mind whether it can effectively compete with open source alternatives that go by similar names, but as I found earlier versions so useful, its re-emergence seems worth the mention."
interesting... the download site seems to be unavailable right now. =)
Password security seems pointless when password recovery systems are even less secure.
This just seems like a cracker tool - to gain passwords. Or am I missing something (since Symantec owns it I probably am)?.
"Maybe this world is another planet's hell"
Aldous Huxley
Putting the "no" in innovation, again.
Let's face it: Anything that symantec touches turns into worthless and junk.
Symantec is like the Anti-Midas of technology.
They touched Norton and poof, a great tool was turned into the worst nightmare of all times.
Now they are releasing the ultimate hackers' tool under their umbrella.
If i was anything like ParMaster, i would run as fast as i could and as far as away from it.
"Doing what i can, with what i have." ~ Burt Gummer
When the submitter referenced "open source alternatives that go by similar names", he was referring to ophcrack. Similar features are also available from Cain and Abel, and John the Ripper.
I maintain a list of top password crackers and sniffers as part of my SecTools.Org site.
While the submitter is correct that they have much more competition now, I still wish to congratulate the former L0pht guys on the new release!
True to that. They slaughtered my favorite windows firewall sygate :(
https://www.speakservers.com/
Loph who?...
What cracks?
12 years? That's pretty old stuff. Who needs it?
Does it work on iPhone?
Can I crack my XBox with it?
Really people, I bet that 90% of slashdotters are still wondering what is L0phtCrack and how can you eat it.
I waited for 10 minutes. No replies. Mute reaction.
L0phtCrack, and their creators, the "L0pht Heavy Industries" group, were once shinning stars inside the Hacker community. Now who remembers them? There are not even scriptkiddies around, all society is a scripkiddy.
L0pht people also created the "tool that never got its true name" - "netcat", which can only be found in most *nix systems as "nc". Pretty great tool, just two weeks ago I used it, once again, for more than 11 years.
Hail to you guys, happy to see you around.
And Hail to the Cow!
Sigh. Do you...do... IT? It seems like a "cracker tool" to you? What the hell are you, the FBI raiding Steve Jackson games 15 years ago because you're too inept to understand the difference between a concept and using it criminally?
You understand that even tools put to ill use by criminals have legitimate purposes right? Or are you in the ban sporks because they can be used in spork crimes camp? </flame> You deserved that.
L0phtcrack--cracks--passwords. There's nothing inherently wrong with that. Valid reasons include:
* lack of backups and a need to recover an existing password
* testing employee passwords for compliance with policy and strength requirements with authorization
* being paid to pen-test a system
* Just freakin' wanting to run it at home to see how fast such tools 'really work'
* Discovering passwords used on a compromised system (it may help reveal passwords used in encrypted files with naive rootkits)
* General Proof of concept against poor password implementations--early versions of l0phcrack hit some systems a lot faster than others as I recall
Can we stop with this namby crap that the tool is somehow used and written by 'bad people' is 'bad' itself?
Attention Overseas Customers
As required by law, L0phtcrack is subject to United States export controls. L0phtCrack may not be downloaded or otherwise exported or re-exported outside the United States. By downloading or using L0phtCrack, you are agreeing to the foregoing and all applicable export control laws. See disclaimer for more details.
What kind of sorry-ass black-hat tool is this?
What would make a real killer for cracking would be a combination of Cain and Abel + GPU Support. Imagine having a ten/hundred fold increase in hashes per second from utilizing a Nvidia / ATI card.
You do have other programs for this kind of work, but the price tag I've seen so far would make my stomach turn.
Right, because if there's one thing that computers are horrible at, it's searching for things really, really quickly. Thanks for the useful post!
To be fair, Midas' touch didn't really work out too well either...
Then do it.. and offer it for free.
Fact: Everything I say is fiction.
There needs to be a -1 Missed the Point mod. He was saying there are various legit reasons to do password recovery and you respond with a mixed list of how you think security consulting should work and why you wouldn't run L0pht and why there are better tools than L0pht. The funny thing is I don't really disagree with any of your rants but his list was valid as well and you simply took a weird side path to argue some points that apparently have been irritating you lately
Perhaps the reason your clients don't listen is because despite technical competence your communication skills needs some work. Try listening to their complaints and problem and trying to respond to them and convincing them rather than just preaching loudly and sounding like Chicken Little. Every company I've worked at in the past 20 years has adopted strong (or at least medium) password policies at some point. The reason IT gets a bad name (other than the fact we fail to deliver ALOT) is that we have bad attitudes about the skills of others and we don't listen to those that are actually paying for our services we just preach and get upset when they don't immediately take our advice. Being right and knowledgeable is important but being convincing and influential is even more important if you actually want to get something done.
Let's face it: Anything that symantec touches turns into worthless and junk.
Symantec is like the Anti-Midas of technology.
They touched Norton and poof, a great tool was turned into the worst nightmare of all times.
Now they are releasing the ultimate hackers' tool under their umbrella.
If i was anything like ParMaster, i would run as fast as i could and as far as away from it.
Don't mod this as "funny." Mod it as "insightful." It's not a joke -- Symantec makes some of the worst products in the industry, and turns otherwise good products into terrible products.
I had a copy of l0phtcrack on my disk that I downloaded years ago from their site, and was left gathering dust on a forgotten corner of my hard drive. Recently a full drive scan by an antivirus (AVG?) identified it has having a trojan. It could be a false positive, but it seems more likely to really be a trojan that had been deliberately planted there. Consider yourselves warned.
If my doctor ever told me "you really need to do X", I would do it. If I thought I knew more about medicine than he does, then I wouldn't pay him to practice medicine on me. So it doesn't make any sense to pay good money for his help if I am not going to comply with his recommendations. Yeah, I could get a second opinion and all of that, but I wouldn't do that without a good reason and I'm trying to keep this analogy simple.
When somebody goes to a doctor and says "doc, it hurts when I do this" and the doctor examines you and says "well, you have Y disease", people generally would not look that doctor in the eye and say "no I don't," at least not without providing some very good reasons why they disagree. That's because doctors, lawyers, and other traditional professionals are generally recognized and respected as the trained experts that they are. This is not the case with IT. IT often has to deal with uncooperative users who don't recognize when they are out of their element. I can't really prove this, but I think I can safely say that IT deals with uncooperative clients far more than any other highly trained professional. Whether anyone likes this or not, that will definitely sour relations.
I see the practicality of it, but I disagree in principle with your comment about the importance of being convincing and influential. That's because I don't subscribe to this idea that you should have to have an uphill battle with someone in order to help them. They should either want and appreciate your help or they should deal with their own problems. I shouldn't need movie-star charisma and a silver tongue to convince people to do something that is clearly in their best interests. All I should need to do is point out how much better it would be if they took a few steps and their own desire for a better or more problem-free experience should take care of the rest.
It's hard because those users are (typically) also your customers. In business, that means you often cannot be completely up-front and honest with them if it is going to offend them. That still doesn't make it right that they hire you for your expertise and then routinely ignore that expertise when you try to use it to improve their experience. It really doesn't make it right when they scream at you because they have problems that would have been completely avoided had they followed your advice. Sure, as a professional dealing with customers you are expected to handle that gracefully, but it's a burden that most other professions don't have to shoulder to such a degree and I think that's often not recognized or appreciated.
It is a miracle that curiosity survives formal education. - Einstein
Time to break out the printing presses!
... especially considering the recently announced cyber-security initiatives, not to mention all of the DOD stuff going on.
We are building an entire ARMY of script kiddies who will need such tools. ;) And guess who's paying for them?
http://oss.coresecurity.com/projects/pshtoolkit.htm
'nuff said
There is a difference between posting about what is wrong in a dicsussion with tech folks on a site such as /. or zdnet (which are both made up of technology workers and professional and/or amateur journalists) and communicating with customers. The approach and tone for each is and should be different as the education level, expectations, and requirements of each audience is different. Here I do not need to sugar-coat my comments or opinions of given product choices.
With customers sometimes the medicine needs to be dosed with a spoonful of sugar. I'm sorry you cannot grasp that distinction, however in this case I do not feel any need to apologise if this particular post offends you, since having nothing worthwhile to say you went directly for an ad-hominem attack. Therefore, I will assume you are a Symantec shill - either an employee, distributor, or associated with an advertising firm for them.
The Christian Right is Neither (Christian nor right). See: Matthew 23, Matthew 25, Ezekiel 16:48-50
They did it to sygate too? Hmmm...I recall they bought the defunct AtGuard firewall and neutered it into their "Internet Security" program...I remember the first (and maybe the second) iteration still had the exact same statistical screen at AtGuard.
AtGuard was the best.
Is this still useful against modern implementations of active directory? I thought it used either kerberos or an improved version of NTLM these days.
A slashdotter who didn't build his own computer is like a Jedi who didn't build his own lightsaber.
whoever gets the first clean cracked version, email me.
Should take about thirty seconds.
Richard Steven Hack - This sig is TOO GODDAMN SHORT TO DO ANYTHING USEFUL WITH! MORONS!
But, somebody already has. Here is a list of 100 great Security tools. (It says "Network Security", but the tools are usually able to do more than just network processes.)
...and to Axent.
there is not a professional accreditation for IT....
It is like those inherently black-hat tools like DES, RSA, SHA-1, and their ilk. Why anyone would want to be the "first to say" such a ridiculous thing is beyond me, but the fact that your ridiculous post has been modded up would only surprise me if this was Slashdot about a decade ago, before it became so popular among the gleefully clueless.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
You might want to read TFA, so you have some idea what you are talking about. L0phtcrack is not owned by Symantec, and has been re-acquired by the original developers. It is in the article. Really. Don't let the clueless mods fool you. Your post was not only completely lacking in insight, it is just plain and flat wrong.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
Grand parent here:
That's basically my point, I can use existing resources from all those tools and still achieve the same feature set. Call me troll if you like but if people are stupid/lazy enough to buy that software for that price instead of getting off their ass and using what's already available then perhaps they shouldn't be in the industry that would use these tools (Especially at that price, I doubt anyone but people working in IT Security would bother spending that much in the first place).
Haha, that's the exact problem right there. IT thinks they are computer "doctors", when in fact they are the computer "janitors".
Seriously, anyone who's worked in IT longer than a year or so should know that at least 50% of their colleagues are incompetent bullshitters, and IT as a whole is the tail who thinks they wag the dog.
Oh, so now you are saying that symantec HAS the midas touch and that it produces Excellent Norton Utiilities and Anti-Virus...?
"Doing what i can, with what i have." ~ Burt Gummer
What if I don't want 100 tools... what if I just want one that I know works? in all reality, 300 bucks (or 1200 for that matter) isn't that much money. Especially when you are talking about a corporation's IT department. If you are paying your IT guy 100K a year and he has to spend all day sifting through 100 mediocre programs to find the two or three good ones, you have just cost the company more than 300 bucks. I suppose you could make the argument that no IT guy making 100K+ a year should need to sift through 100 programs, since they would already know which ones they want to use... but that's a different argument I guess.
That's the thing here. Its made for IT security persons, and they probably will enjoy the convenience and other features it delivers. As a webmaster I could probably code all the scripts and code I would need, but sometimes its just more convenient to buy them in one package and dedicate your time on the more important stuff. You get more done that way aswell.
Seriously? If you're a security consultant, you're charging between $125-$250/hr. Tool pays for itself within 4-6 hours of work. Fucking moron.
Exactly why are you paying this guy 100k a year? For 100k, He really should be looking at all the available "tools", as some will expose vulnerabilities that others will miss, etc. It might be different if you were only paying the guy 25K a year. At that rate, you might not expect the person to be too bright. (In fact, as is well known. If you pay peanuts, all you will get is monkeys!)
A windows-only binary?
The world has changed since then...
Also:
> Attention Overseas Customers
(etc)
What do overseas customers have to do with USA law?
And to think I was actually going to consider buying it.
Ok, so where is the torrent of the real release, where your download isn't also tracked.
---- Booth was a patriot ----
They don't want to be sued because of what you do with it.. Pretty normal CYA these days when people are getting sued just for downloading a song.
---- Booth was a patriot ----
They haven't killed that off, yet. We will see what happens now that they own Altiris and have pretty much merged it with that division, but so far it wasn't destroyed by the acquisition of norton.
---- Booth was a patriot ----
Oh, so now you are saying that the world is flat and the Earth revolves around the sun?
..." in front of them too!
See. I can make things up and put "Oh, so now you are saying
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
Shouldn't it be..... if you pay peanuts, all you will get is elephants?
For Windows my personal favorite was PGP Firewall - it was one of the most powerful firewall solutions I've ever come across for Windows. It was later aquired by McAfee and much like Norton they completely butchered it. Another good firewall was NeoWatch combined with NeoTrace, pretty entertaining and very capable (although it didn't firewall applications).
And in four to six hours of work with another tool that costs nothing?
While I'm aware this tool is supposed to be good, the cost in comparison to some other tools is ridiculous. That's the point. It's never about how long it will take to pay for it.
Moron.
Richard Steven Hack - This sig is TOO GODDAMN SHORT TO DO ANYTHING USEFUL WITH! MORONS!
Did you bother to follow the link? You'll find out that the top 10 or so are multifunctional. I use about 3 or 4 of them.
The thing is, I would say L0phtCrack is the mediocre program compared to some of the specialized software on this list.
Under US law, crypto is equiv. to munition and is subject to the same export laws per say
Touche, my friend.
I was trying out the old, well-worn Republican way of attacking opponents.
"Doing what i can, with what i have." ~ Burt Gummer
I got the option too, but in a faithless attempt to get my option pages fixed and to use again html tags I let the Ads show. I don't want to close my actual profile, which always means a troll/alterego is born (inside my tender user expectations) for that site. Wonder if anyone is behind the admin account in this site
May I remind you Veritas is now (since 2005) part of Symantec.
Symantec is much more than just consumer anti virus and personal firewalls.
NeoTrace! Yeah, that was a wicked program. It doesn't work anymore, does it?
You say "was" your favorite...does that mean it's not available anymore?