[Previous entry: "Working the web: Warchalking"] [Main Index] [Next entry: "Howto install linux on a SS40G"]
07/09/2002 Entry: "Cracking MS SQL Server passwords"
Cracking MS SQL Server passwords
Flawed hash routine, salted with a time based seed leaves MS SQL server vulnerable.
By Thomas C Greene in Washington
Posted: 08/07/2002 at 14:00 GMT
The inner workings of the undocumented pwdencrypt() hash function in Microsoft SQL Server have been revealed in a paper by security researcher David Litchfield of Next Generation Security Software (NGSS).