Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 13:30

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 6 posts ] 
Author Message
 Post subject: Ventrilofp password crack
PostPosted: 19 Apr 2009 10:11 

Joined: 19 Apr 2009 08:45
Posts: 11
Hello, new to the forums. I took a look at your Ventfp tool and have to say its pretty cool. I had a question that i was unable to find the answer too at least with search.
Maybe i am doing something wrong (which is probably the case) but i was wondering if this program can crack a ventrilo servers join password. If it can how would i go about doing that?


I originally took a look at this program for this specific purpose, so if anyone knows a way to achieve a password break on a ventrilo join password please let me know.


Top
 Profile  
 
 
 Post subject: Re: Ventrilofp password crack
PostPosted: 19 Apr 2009 12:01 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
I have replied to the other post


Top
 Profile  
 
 Post subject: Re: Ventrilofp password crack
PostPosted: 19 Apr 2009 19:22 

Joined: 19 Apr 2009 08:45
Posts: 11
yes, i saw that : ( thanks for the quick reply.


Top
 Profile  
 
 Post subject: Re: Ventrilofp password crack
PostPosted: 20 Apr 2009 04:41 

Joined: 19 Apr 2009 08:45
Posts: 11
Now that takes care of user password for entry, is it possible to get the admin password once connected to the server? i'm still confused about this subject, in another post it seems like someone got a hold of one but it was encrypted and thus pointless. (Due to Ventrilo's custom encryption?)


Top
 Profile  
 
 Post subject: Re: Ventrilofp password crack
PostPosted: 20 Apr 2009 15:25 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
uhmm I try to explain it in easier words.
if the target software is not affected by specific vulnerabilities which can allow (as direct or indirect effect) the retrieving of sensible informations like an admin password the only alternative if "guessing the password".
password guessing simply means "brute forcing" and/or "wordlist checking" which stands for the continuous trying of different passwords (sequential chars in the first case and fixed words in the second one) one after the other.

in ventrilo 3.x there is a simple mechanism which automatically bans the client if it tries more than 5 admin passwords and, in any case, all these attemps are logged and easily recognizable by the admin.

the uncertain results, the abnormous volume of time needed, the risks showed above and other factors makes the "password guessing" (referred to network services) only a theorical security problem.


Top
 Profile  
 
 Post subject: Re: Ventrilofp password crack
PostPosted: 21 Apr 2009 04:54 

Joined: 19 Apr 2009 08:45
Posts: 11
O ok, i see what you mean now.


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 6 posts ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
cron