HeadlinesBriefing favicon HeadlinesBriefing.com

Mandiant Cracks Weak Admin Passwords in 12 Hours

Ars Technica - All content •
×

Security firm Mandiant released a rainbow table that cracks Microsoft NTLMv1 admin passwords in under 12 hours using consumer hardware. This precomputed database targets the outdated Net-NTLMv1 protocol, which remains in use despite its well-known vulnerabilities. The tool is hosted on Google Cloud and is meant to lower the barrier for security professionals.

NTLMv1's weakness has been public since the late 1990s, yet it persists in sensitive networks due to legacy app dependencies and migration inertia. Industries like healthcare and industrial control often can't afford the downtime to upgrade. Mandiant's release provides concrete proof of the risk, aiming to push organizations to finally retire the deprecated function.

The table helps attackers solve a Windows authentication challenge, then rapidly crack the resulting hash. Researchers and admins have welcomed the tool, saying it gives them ammunition to convince decision-makers. With Microsoft only announcing NTLMv1's deprecation last year, Mandiant's release is a timely nudge for laggards to secure their networks.