Commentary

George Hulme
 

Famous Password Auditing Tool, L0phtCrack Is Back

After a couple of years of rest, L0phtCrack, one of the most famous password auditing and recovery tools is back.

After a couple of years of rest, L0phtCrack, one of the most famous password auditing and recovery tools is back.L0phtCrack, originally built by L0pht Heavy Industries, cracks passwords at swift speeds by scanning through a dictionary of words, generating words to form probable passwords guesses, and also attempts to break passwords through brute-force attacks (trying every possible character combination). L0phtCrack also enables security managers to review the strength of employee passwords and disable accounts and force users to strengthen their passwords.

Some contend that tools such as L0phtCrack are just as easily used by criminals as they are by security professionals. And they are, but as we saw yesterday from Microsoft's recent honeypot data relating to passwords, security managers need to be able to audit passwords with the best tools possible.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Back in 1997 when L0pht Heavy Industries released L0phtCrack, the group was widely condemned for releasing a "hacking" tool. L0phtCrack became one of the most widely used "hacking tools" by legitimate businesses and government agencies, including the Government Accounting Office.

L0phtCrack became property of Symantec when Symantec acquired the security and auditing consulting firm @Stake in September 2004. @stake was founded in 2000 by members of L0pht. Symantec then retired L0phtCrack in 2007. At the time, Symantec wouldn't elaborate why it decided to terminate the tool, other than to say in a statement that L0phtCrack "no longer fits into Symantec's larger product portfolio and future strategy."

You can check out the L0phtCrack Web site here.

For my security and technology observations throughout the day, consider following me on Twitter.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links