Bob,
He said it right... In reality, he has found a value that generates a
hash that is the same as the stored password hash. It is possible that
his proposed password value is in fact different from the actual
password value that was used to create the profile, but as long as the
hash values match, he is considered authenticated....
-Eric DeLong
-----Original Message-----
From: midrange-l-bounces@xxxxxxxxxxxx
[mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of Bob P. Roche
Sent: Monday, June 22, 2009 1:53 PM
To: Midrange Systems Technical Discussion
Subject: Re: AS400 Automatic Sending of New Password?
No, you can encrypt a dictionary to compare values, You have effectively
decrypted some those words, but have not broke the encryption. You don't
know the whole possible list you only know the ones that match your
encrypted list.
From:
John Earl <johntearl@xxxxxxxxxxxxx>
To:
Midrange Systems Technical Discussion <midrange-l@xxxxxxxxxxxx>
Date:
06/22/2009 01:49 PM
Subject:
Re: AS400 Automatic Sending of New Password?
Sent by:
midrange-l-bounces@xxxxxxxxxxxx
Charles,
Breaking encryption <> decryption
That is a distinction without a difference. Either way, you know what
the encrypted information is.
jte
As an Amazon Associate we earn from qualifying purchases.