- It's the applications, stupid
- Will a whitelist save personal computing?
- Thousands of Web sites under attack
- To solve the unsolvable problem
- Re-thinking the security of virtual machines
- Security Development Lifecycle trumps code complexity
- Is your Web site FIPS compliant?
- Computer security: Why have least privilege?
- Strategic security: Get a handle on authentication
- Control user installs of software
January 18, 2007 | Comments: (0)
Phillip Oechslin responds to my Rainbow Table column
Rainbow Method and Table creator Phillip Oechslin emailed me regarding my recent column on Rainbow tables.
Here's his email.
Hello Roger,
I just saw your online article on CSO online in Australia.
I thought you might interested to know that rainbow tables can also be used to crack office documents. The default encryption scheme of Word and Excel has the same default as Windows password hashes, it is predictible (there is no salt or randomness).
We have a product that cracks a Word or Excel document in minutes, whatever the password (any length or complexity, since what we crack is not the password but the resulting 40 bit key that is used to encrypt the document).
I could get you a evaluation version if you wanted to test (would have to send you a DVD with the 4GB of tables). Alternatively I could crack a few documents for you.
There is info on this on our product page:
http://www.objectif-securite.ch/en/products.php
Well and you write: "Rainbow tables are closely related to a cracking technique pioneered by Philippe Oechslin".
Actually rainbow tables have been invented by Philippe Oechslin. I should know. I coined the name rainbow table in my research paper presented at Crypto 2003.
http://lasecwww.epfl.ch/pub/lasec/doc/Oech03.pdf
BTW, we have a large article in the February issue of Hackin9
(http://en.hakin9.org/) magazine about rainbow tables and how we optimize their implementation.
regards,
Philippe
Posted by Roger Grimes on January 18, 2007 06:42 AM
RATE THIS ARTICLE:
-

- COMMENTS
TOP STORIES
Hyperconnected users growingSteve Jobs to keynote WWDC
CSC settles kickbacks case
MS previews SMB software
What does HP-EDS really mean?
Mac Office 2008 SP1 released
HP buys EDS for $13.9 billion
Corporate IT spending slows
MS targets smartphone market
Sun to clarify JavaFX plan
ADDITIONAL RESOURCES

- Application Security: Threats and How to Counter Them
- Why Linux Threats Mean Business
- Minding the Machines: PC Disaster Recovery for the Enterprise

- Protect Your Data with SSL
- Prevent Your Next Microsoft Exchange Outage
- 11 Myths About Microsoft Exchange Backup & Recovery





