Authentication Encryption Algorithms Flashcards

1
Q

What is LM?

A

Lan Manager (AKA LANMAN), a authentication encryption method using a hash challenge similar to CHAP. Somewhat insecure, no longer used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is NTLM?

A

NT Lan Manager, passwords are more secure. Password is Unicode, up to 127 characters long, and is stored as a 128-bit MD4 hash.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is NTLMv2

A

Version 2 of NTLM, with a new password response. Uses MD4 password hash, HMAC-MD5 hash of username and server name, and has a variable-length challenge of timestamp, random data, and domain name.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are NLTM’s vulnerabilities?

A

Some Windows password databases contain LM hash versions of the passwords

Also vulnerable to credentials forwarding attack (use credentials of one computer to gain access to another)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a credentials forwarding attack?

A

Use credentials of one computer to gain access to another.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly