Developer(s) | Massimiliano Montoro |
---|---|
Stable release | |
Operating system | Microsoft Windows |
Type | Password cracking/Packet analysis |
License | Freeware |
Website | www.oxid.it/cain.html |
Cain & Abel is a very useful security tool used for decryption and decoding of passwords for a wide array of offline programs and network services. Built from the ground up to be extremely helpful to users who have forgotten passwords for some of their most-used apps on their home PC, Cain and Abel feature powerful decoding algorithms, extensive decrypting tools, and other. We open our Bibles for our study tonight to the fourth chapter of Genesis, the book of beginnings. Genesis chapter 4. As we come to chapter 4, we come to the story of Cain, the first person born in t. Penetration Test – Cain & Abel – ARP Poisoning ( Part 1 ) By Stephen Stinson September 30. The destination IP address must be resolved to a MAC address for transmission via the data link layer. When another host’s IP address is known, and its MAC address is needed, a broadcast packet is sent out on the local network.
Cain and Abel (often abbreviated to Cain) is a password recovery tool for Microsoft Windows. It can recover many kinds of passwords using methods such as network packet sniffing, cracking various password hashes by using methods such as dictionary attacks, brute force and cryptanalysis attacks.[1]Cryptanalysis attacks are done via rainbow tables which can be generated with the winrtgen.exe program provided with Cain and Abel.[2]Cain and Abel is maintained by Massimiliano Montoro[3] and Sean Babcock.
Features[edit]
- WEP cracking
- Speeding up packet capture speed by wireless packet injection
- Ability to record VoIP conversations
- Decoding scrambled passwords
- Calculating hashes
- Revealing password boxes
- Uncovering cached passwords
- Dumping protected storage passwords
- IP to MAC Address resolver
- Network PasswordSniffer
- LSA secret dumper
- Ability to crack:
- LM & NTLM hashes
- NTLMv2 hashes
- Microsoft Cache hashes
- Microsoft WindowsPWL files
- Cisco IOS - MD5 hashes
- Cisco PIX - MD5 hashes
- APOP - MD5 hashes
- CRAM-MD5 MD5 hashes
- OSPF - MD5 hashes
- RIPv2 MD5 hashes
- VRRP - HMAC hashes
- Virtual Network Computing (VNC) Triple DES
- MD2 hashes
- MD4 hashes
- MD5 hashes
- SHA-1 hashes
- SHA-2 hashes
- RIPEMD-160 hashes
- Kerberos 5 hashes
- RADIUS shared key hashes
- IKEPSK hashes
- MSSQL hashes
- MySQL hashes
- Oracle and SIP hashes
Status with virus scanners[edit]
Some virus scanners (and browsers, e.g. Google Chrome 20.0.1132.47) detect Cain and Abel as malware.
Avast! detects it as 'Win32:Cain-B [Tool]' and classifies it as 'Other potentially dangerous program',[4] while Microsoft Security Essentials detects it as 'Win32/Cain!4_9_14' and classifies it as 'Tool: This program has potentially unwanted behavior.'Even if Cain's install directory, as well as the word 'Cain', are added to Avast's exclude list, the real-time scanner has been known to stop Cain from functioning. However, the latest version of Avast no longer blocks Cain.
Symantec (the developer of the Norton family of computer security software) identified a buffer overflowvulnerability in version 4.9.24 that allowed for remote code execution in the event the application was used to open a large RDP file, as might occur when using the program to analyze network traffic.[5] The vulnerability had been present in the previous version (4.9.23) as well[6] and was patched in a subsequent release.
References[edit]
- ^'How to use Cain and Able'. Cybrary. Retrieved 2019-08-24.
- ^'ECE 9609/9069: Introduction to Hacking'. Whisper Lab. Archived from the original on 2019-08-24. Retrieved 2019-08-24.
- ^Zorz, Mirko (2009-07-07). 'Q&A: Cain & Abel, the password recovery tool'. Help Net Security. Retrieved 2019-08-24.
- ^Metev, Denis (2019-07-29). 'What Is Brute-Force And How to Stay Safe?'. Tech Jury. Retrieved 2019-08-24.
- ^'Attack: Massimiliano Montoro Cain & Abel .rdp File BO: Attack Signature - Symantec Corp'. www.symantec.com. Retrieved 2019-08-24.
- ^'Massimiliano Montoro Cain & Abel Malformed '.rdp' File Buffer Overflow Vulnerability'. www.securityfocus.com. Retrieved 2019-08-24.