Reply to post: Before NTLM there was just LM

Use an 8-char Windows NTLM password? Don't. Every single one can be cracked in under 2.5hrs

Wellyboot Silver badge

Before NTLM there was just LM

NTLM was made backward compatible with the older MS Lan Manager (P O donkey S) and had a separate LM hash table which used passwords split into 2x 7 char blocks & padded with nulls. Dictionary attack times for the 7 chars was never very long and if the 2nd block was all nulls it gave the same hash every time. I believe the backward compatiblility could only be turned off once the entire AD domain was using NTLM2.

This was back in the early '90s when DES (56 bit) was standard and the US didn't allow export of anything better than 40 bit.

Some things scar the memory for life.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon