Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor

Mandiant Unveils NTLMv1 Rainbow Table

Image © Arstechnica
Security researchers gain a new tool as Mandiant releases an NTLMv1 rainbow table to illustrate the protocol’s weaknesses and accelerate deprecation efforts.

Security firm Mandiant has released a rainbow table intended to recover Net-NTLMv1 passwords, a move designed to showcase the weaknesses of the deprecated hashing scheme and pressure organizations to migrate away from NTLMv1. The data set is hosted in Google Cloud and consists of precomputed hash-to-password mappings that can map a stolen Net-NTLMv1 hash back to its plaintext password.

Rainbow tables exploit NTLMv1’s limited keyspace, making the construction of cross-hash tables straightforward compared with newer hashing methods. While rainbow tables have existed for years, the new release highlights the potential for faster password recovery using consumer hardware rather than specialized gear.

In a statement, Mandiant said the NTLMv1 rainbow table could enable defenders and researchers (and, regrettably, malicious actors as well) to recover passwords in under 12 hours using hardware costing less than $600. The organization argues that releasing these tables lowers the barrier for demonstrating NTLMv1’s insecurity without requiring sensitive data uploads to third parties or expensive equipment.

Security experts caution that NTLMv1 persists in some high-assurity networks due to legacy applications and downtime concerns. The guidance remains clear: disable Net-NTLMv1 where possible and migrate to NTLMv2 or other modern authentication mechanisms to reduce the risk of credential compromise.

 

Arstechnica

Notícias relacionadas

Divergência MME e Aneel sobre cessão de postes
Brisanet dobra base móvel em 2025
Vivo anuncia Rogério Takayanagi como VP de engenharia e serviços
GT fará minuta da Política Nacional de Infraestruturas Críticas
Oi: Justiça prorroga blindagem de pagamentos até abril
Rogerio Takahyanagi assume Vivo como VP Engenharia

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais