PaulDotCom mailing list archives

Tools for password analysis


From: digitallachance at gmail.com (Francois Lachance)
Date: Fri, 27 Nov 2009 13:46:43 -0600

I am currently doing a password audit for my employer. I am somewhat
shocked at the success rate Opthcrack liveCD returns with the free
small rainbow table in an AD network that has the complex password GPO
setting turned on - 96% after 5:50hrs

Now that I have all those juicy passwords, I would like to do some
kind of analysis to make recommendations to management. My first
recommendation will probably be to increase the minimum password
length.

I have two questions for the list:
1.  What tools can I use to do that analysis?
2. Is there a way to force better complex password rules than what
Microsoft provides in Windows 2003?

Thanks!

-- 
Sent from my mobile device


Current thread: