Path: utzoo!utgpu!jarvis.csri.toronto.edu!mailrus!sharkey!cfctech!teemc!ka3ovk!ki4pv!cdis-1!tanner From: tanner@cdis-1.UUCP (Dr. T. Andrews) Newsgroups: comp.unix.questions Subject: Re: passwds and crypt(3)... Message-ID: <0000041@cdis-1.UUCP> Date: 5 Jan 90 20:20:13 GMT References: <21966@adm.BRL.MIL> <1990Jan4.202253.27867@athena.mit.edu> Organization: CDI-DLD Lines: 16 X-Phone: +1 904 736 0866 X-Snail: 1409 E New York Ave; DeLand, FLA 32724 In <1990Jan4.202253.27867@athena.mit.edu>, jik@athena.mit.edu (Jonathan I. Kamens) writes... ) [ scheme to encrypt all probable passwords with all seeds ] Given a password file for a machine with fewer than 4096 users, a considerable savings of resources may be had by simply encrypting all probable passwords with only the seeds actually present in the password file. For a system with 10 legitimate users, you should need at most 10 encryptions \(em less if two or more passwords share a seed. For a system with 4000 legitimate users, this doesn't work out as well. Concentrate on password-guessing for "root" or the owner of the files in which you are interested. -- {attctc gatech!uflorida}!ki4pv!cdis-1!tanner {bpa uunet}!cdin-1!cdis-1!tanner