tech

Mandiant releases rainbow table that cracks weak admin password in 12 hours

Windows laggards still using the vulnerable hashing function: Your days are numbered.

Mandiant releases rainbow table that cracks weak admin password in 12 hours

TL;DR

  • Mandiant has released a database of NTLMv1 rainbow tables to help security professionals demonstrate the protocol's insecurity.
  • These tables allow for the cracking of NTLMv1-protected administrative passwords in under 12 hours using consumer hardware.
  • Despite being deprecated and having known weaknesses since 1999, NTLMv1 is still in use in sensitive networks due to legacy applications, migration costs, and inertia.
  • The release of these tables aims to provide security professionals with 'ammunition' to convince decision-makers to migrate to more secure hashing algorithms.
  • Microsoft introduced the more secure NTLMv2 in 1998 and only recently announced plans to deprecate NTLMv1.
  • Mandiant advises organizations to immediately disable the use of Net-NTLMv1.