passwords

Jerome Alet alet at unice.fr
Thu Mar 23 10:21:10 GMT 2000


On Thu, 23 Mar 2000, William Deakin wrote:
> I'm not sure that this is completely true. It is *possible* to unencrypt
> the passwords in the passwd and/or shadow file (this is what some crackers
> 
> spend alot of time trying to do) and is the reason why there is a separate
> 
> passwd and shadow file. However, it is not straightforward and depends of
> the OS and implementation/version.

Could you say more ?

AFAIK it's only possible to do a brute force attack on these passwords:
encrypt all possible characters combinations and compare the encrypted
strings: that's very long, and generally considered impossible or near
impossible (depending on the number of characters possible and the
encryption algorithm)

bye,
Jerome



More information about the samba-ntdom mailing list