UGN Security
Posted By: champatram how to crack shadowed password files? - 09/04/04 11:33 AM
Is it posible to crack shadowed password files. If so how to go about it. If not is there some other alternative to it.
Posted By: sinetific Re: how to crack shadowed password files? - 09/08/04 03:32 AM
Yes, if you can get access to the file where the passwords are stored, root access. In shadowed password files the actual encrypted string are stored in /etc/shadow which is 600(rw-------) only read/writable by root. Unlike the file /etc/passwd, which is 644(rw-r--r--) so that other programs and program users can access it inorder to gain certain operating privledges. In older systems with unshadowed password files by overflowing certain cervices you could gain acess to reading the /etc/passwd file by becoming the user 'webserver' or 'ftp' or the name of whichever systems daemon you were able to become by exploiting it.

There are a few examples of different ways to get access to the shadowed file using C programming functions here .
Posted By: sinetific Re: how to crack shadowed password files? - 09/08/04 09:49 AM
Oh yeah once you get access a cracker like john the ripper should work.
Posted By: sool Re: how to crack shadowed password files? - 11/08/04 01:18 PM
Hi
Can someone crack this passwd file, cause I have hard time cracking it.

http://www31.brinkster.com/opsloppers/passwd.txt
Posted By: sinetific Re: how to crack shadowed password files? - 11/08/04 02:01 PM
The passwd file on *nix systems contains no password information on systems that use shadowed password files(all recent systems). There is nothing in that file to be cracked.

root::0:1:Superuser::
ftp::201:201:::
somali:x:225037:102:::

try looking for a file called /etc/shadow like previously stated. or maybe acutally read what was posted.
© UGN Security Forum