Adam Israel (stone@mcs.net)
Fri, 4 Dec 1998 15:10:32 -0600
>PWL files encrypt multiple streams with the same RC4 stream. The RC4
>stream is initialized with a 9-round MD5 of the password. A program
>called "glide" (available on most hacker sites) can recover the first 56
>bytes of the stream, revealing most passwords. There is a way you can
>turn off password caching; I don't remember the details right now.
>Anyone?
Actually, unless there's been a revision, Glide only works on the original
release of win95. They changed the format of the .pwl file with a security
update and in the first service release.
Adam
The following archive was created by hippie-mail 7.98617-22 on Sat Apr 10 1999 - 01:17:37