Passwordspro

Содержание:

Rotating the Encryption Key(Feature available only in Enterprise Edition)

Even if you are sure of managing the encryption key securely outside of PMP, one of the best practices is to periodically change the encryption key. PMP provides an easy option to automatically rotate the encryption key.

14.1 How does the key rotation process work?

PMP will look for the current encryption key present in the file pmp_key.key, available in the path specified in the manage_key.conf file, present under the <PMP_HOME>/conf folder. Only if it is present in the specified path, the rotation process will continue. Before rotating the encryption key, PMP will take a copy of the entire database. This is to avoid data loss, if anything goes wrong with the rotation process.

During the key rotation process, all passwords and sensitive data will be decrypted first using the current encryption key and subsequently encrypted with the new key. Later, the new key will be written in the pmp_key.key file present in the location as specified in the manage_key.conf file. At the end of successful key rotation, PMP will write the new encryption key in the same file that contains the old key. If any error occurs while writing the key, the rotation process will be aborted.

14.2 Steps to rotate the encryption key (if you are NOT using High Availability)

  1. Ensure that the current encryption key (pmp_key.key file) is present in the location as specified in the manage_key.conf file. Also, ensure that PMP gets the read/write permission while accessing the pmp_key.key file.
  2. Stop the PMP server.
  3. Open the command prompt and navigate to <PMP-Installation-Folder>/bin directory. Execute RotateKey.bat (in Windows) or sh RotateKey.sh (in Linux).
  4. Based on the number of passwords managed and other parameters, the rotation process will take a few minutes to complete.
  5. Start mthe PMP server once you see the confirmation message.

14.3 Steps to rotate the encryption key (if you are USING High Availability)

  1. Navigate to Admin >> General >> High Availability in the PMP web interface. Make sure High Availability and Replication Status are alive.
  2. Check if the current encryption key (pmp_key.key file) is present in the location as specified in the manage_key.conf file. Also, ensure that PMP gets the read/write permission when accessing the pmp_key.key file.
  3. Stop the PMP Primary server and make sure PMP Secondary server is running.
  4. Open the command prompt in the PMP Primary installation, navigate to the
    /bin directory and execute RotateKey.bat (in Windows) or sh RotateKey.sh (in Linux).
  5. Based on the number of passwords managed and other parameters, the rotation process will take a few minutes to complete. You will see confirmation message ons successful completion of the rotation process
  6. Copy the new encryption key from the Primary installation and paste it in the location, as specified in the manage_key.conf file. This is the location from where the Standby will fetch the pmp_key.key file.
  7. Now, start the Primary and the Standby servers.

Password Management Features Matrix

Standard Edition

  • Centralized password vault
  • Manual resource addition
  • Import resources from CSV files
  • Import resources from KeePass
  • Import resources from active directory
  • Password policies
  • Password sharing and management
  • Audit and instant notifications
  • User / User group management
  • Local authentication
  • RADIUS authentication
  • AD / Azure AD / LDAP integration
  • Export passwords for offline access
  • Password reset listener
  • Backup and recovery provisions
  • Remote RDP, SSH, and Telnet sessions
  • Two-factor authentication — OTP sent via email
  • Rebranding
  • Mobile access (Android, iOS, Windows)
  • Browser extensions (Chrome, Firefox, IE)
  • VNC support for collaboration
  • Transfer approver privileges
  • IIS AppPool password reset
  • IIS Web.Config discovery
  • Password protected exports
  • Backup file encryption
  • IP restrictions- Web access
  • Managing unidentified email addresses
  • Emergency measures
  • Personalization of user interface(Night-mode theme)
  • Notification Email IDs

Premium Edition

  • All Features of Standard Edition
  • AD / Azure AD Sync — User groups & OUs
  • Auto Logon Helper
  • Password access control workflow
  • Admin dashboard (Live feeds, reports and graphs)
  • Password action notifications (Resource group-specific)
  • Remote Password Reset (On-demand, Scheduled, and Action-based) — List of supported platforms
  • Agent-based password reset
  • Canned reports
  • Two-factor authentication — PhoneFactor, RSA SecurID, Google Authenticator, Duo security, YubiKey, Microsoft Authenticator,Okta Verify
  • High availability
  • Privileged session recording
  • AD / Azure AD Sync — User groups & OUs
  • Privacy settings
  • Password reset plugin
  • User Sessions
  • Trash Users 
  • IP Restrictions — API access and Agent Access 
  • Disable Password Resets for Privileged Accounts 
  • Password Reset using SSH Command Sets

Enterprise Edition

  • All features of Premium edition
  • Data Encryption and Protection with SafeNet HSM
  • MS SQL server as backend database
  • Password management API (XML RPC, SSH CLI)
  • Privileged accounts discovery
  • Active directory sync — resources
  • LDAP Sync — User and User Groups
  • SAML 2.0 support
  • Remote SQL sessions with auto logon
  • Role customization
  • Ticketing system integration-ServiceDesk Plus On-Demand, ServiceDesk Plus MSP, ServiceDesk Plus, ServiceNow, JIRA Service Desk
  • Custom password reset listeners
  • Scheduled export of encrypted HTML files
  • SIEM integration — SNMP traps & Syslog messages generation
  • Email templates for notification configuration
  • Landing Server Configuration
  • Federated Identity Management
  • Smart Card / PKI / Certificate Authentication
  • Two-factor Authentication — RADIUS
  • Custom Reports
  • Out-of-the-box compliance reports (PCI DSS, NERC-CIP, ISO/IEC 27001, GDPR)
  • SQL query reports
  • Privileged session shadowing and termination
  • SQL server failover clustering
  • RESTful API
  • EAR support while using MS SQL as backend database
  • Purging selective session recordings
  • File transfers over remote desktop sessions
  • Secure cloud storage options
  • CI/CD Platform Integration — Jenkins, Ansible, Chef, Puppet

Матрица функций управления паролями

Версия Standard

  • Централизованное хранилище паролей
  • Ручное добавление ресурсов
  • Импорт ресурсов из CSV-файлов
  • Импорт ресурсов из KeePass
  • Импорт ресурсов из Active Directory
  • Политики паролей
  • Общий доступ к паролям и управление паролями
  • Аудит и мгновенные уведомления
  • Управление пользователями/группами пользователей
  • Локальная проверка подлинности
  • Проверка подлинности RADIUS
  • Интеграция со службами AD/Azure AD/LDAP
  • Синхронизация со службами AD/Azure AD — группы пользователей и подразделения
  • Экспорт паролей для автономного доступа
  • Прослушиватель для сброса паролей
  • Возможности резервного копирования и восстановления
  • Удаленные сеансы RDP, SSH, Telnet и SQL
  • Двухфакторная проверка подлинности — отправка OTP по электронной почте
  • Ребрендинг
  • Мобильный доступ (Android, iOS, Windows)
  • Расширения браузера (Chrome, Firefox, IE)
  • Проверка действительности цифровых сертификатов
  • Поддержка VNC для целей сотрудничества
  • Передача привилегий утверждающего
  • Сброс пароля IIS AppPool
  • Определение IIS Web.Config
  • Группы сертификатов SSL
  • Защищенные паролем операции экспорта
  • Шифрование файлов резервной копии
  • IP-ограничения — веб-доступ
  • Управление не идентифицированными адресами электронной почты
  • Экстренное реагирование
  • Персонализация пользовательского интерфейса (тема ночного режима)
  • Идентификаторы электронной почты для уведомления

Версия Premium

  • Все возможности версии Standard
  • Модуль поддержки автоматического входа
  • Рабочий процесс управления доступом к паролям
  • Информационная панель администратора (прямые трансляции, отчеты и графики)
  • Уведомления о действиях с паролями (по группам ресурсов)
  • Удаленный сброс пароля (по требованию, плановый и в зависимости от действий) — список поддерживаемых платформ
  • Сброс пароля на основе агентов
  • Готовые отчеты
  • Двухфакторная проверка подлинности — PhoneFactor, RSA SecurID, Google Authenticator, Duo security, YubiKey, Microsoft Authenticator, Okta Verify
  • Режим высокой доступности
  • Запись привилегированного сеанса
  • Поддержка SAML 2.0
  • Подписание сертификата Microsoft CA
  • Интеграция с CMDB для синхронизации с сертификатом SSL
  • Параметры конфиденциальности
  • Плагин для сброса паролей
  • Ключи SSH и сертификаты SSL
  • Сеансы пользователя
  • Пользователи корзины
  • IP-ограничения — доступ API и доступ агента
  • Отключение функции сброса паролей для привилегированных учетных записей
  • Сброс пароля при помощи наборов команд SSH
  • Интеграция с платформой CI/CD — Jenkins, Ansible

Версия Enterprise

  • Все возможности версии Premium
  • Шифрование данных и защита при помощи SafeNet HSM
  • MS SQL server в качестве серверной базы данных
  • API управления паролями (XML RPC, SSH CLI)
  • Определение привилегированных учетных записей
  • Синхронизация с Active Directory — ресурсы
  • Синхронизация с LDAP — пользователь и группы пользователей
  • Автоматизированное определение SSH/SSL
  • Управление жизненным циклом пар ключей SSH
  • Периодическая ротация ключей SSH
  • Управление сертификатами SSL
  • Развертывание и отслеживание сертификатов SSL
  • Сканирование уязвимостей SSL
  • Оповещения об истечении срока действия сертификатов SSL
  • Управление жизненным циклом сертификатов с помощью Let’s Encrypt
  • Настройка ролей
  • Интеграция с системой отправки запросов — ServiceDesk Plus On-Demand, ServiceDesk Plus MSP, ServiceDesk Plus, ServiceNow, JIRA Service Desk
  • Индивидуальные прослушиватели для сброса паролей
  • Плановый экспорт зашифрованных файлов HTML
  • Интеграция с SIEM — ловушки SNMP и формирование сообщений системных журналов
  • Шаблоны электронных писем для настройки уведомлений
  • Конфигурация целевого сервера
  • Управление федеративными удостоверениями
  • Проверка подлинности смарт-карт/PKI/сертификатов
  • Двухфакторная проверка подлинности — RADIUS
  • Настраиваемые отчеты
  • Готовые отчеты о соответствии требованиям (PCI DSS, NERC-CIP, ISO/IEC 27001, GDPR)
  • Отчеты об опросах SQL
  • Теневое копирование и завершение привилегированных сеансов
  • Отказоустойчивая кластеризация SQL Server
  • RESTful API
  • Ротация ключей шифрования
  • Поддержка EAR при использовании MS SQL в качестве серверной базы данных
  • Очистка выборочных записей сеансов
  • Подписание сертификатов с помощью индивидуального корневого ЦС
  • Отслеживание истечения срока действия доменов
  • Передача файлов в рамках сеансов удаленных настольных рабочих столов
  • Безопасные опции облачного хранения

Managing PMP Encryption Key (from PMP 6402 onwards)

PMP uses AES-256 encryption to secure the passwords and other sensitive information in the password database. The key used for encryption is auto-generated and is unique for every installation. By default, this encryption key is stored in a file named pmp_key.key under the <PMP_HOME>/conf folder. For production instances, PMP does not allow the encryption key to be stored within its installation folder. This is done to ensure that the encryption key and the encrypted data, in both live and backed-up database, do not reside together.

We strongly recommend that you move and store this encryption key outside of the machine, where PMP is installed, in another machine or an external drive. You can supply the full path of the folder, where you want to move the pmp_key.key file, manually move the file to that location and delete any reference within PMP server installation folder. The path can be a mapped network drive or an external USB (hard drive / thumb drive) device.

PMP will store the location of the pmp_key.key in a configuration file named manage_key.conf, present under the <PMP_HOME>/conf folder. You can also edit that file directly to change the key file location. After configuring the folder location, move the pmp_key.key file to that location and ensure the file or the key value is not stored anywhere within the PMP installation folder.

PMP requires the pmp_key.key folder to be accessible with necessary permissions, to read the pmp_key.key file, when it starts up every time. After a successful start-up, it does not need access to the file anymore and the device with the file can go offline.

World’s Largest Organizations Rely on Password Manager Pro

The IT divisions of some of the World’s largest organizations and Fortune 500 companies rely on Password Manager Pro to control access to their IT infrastructure. Over 300,000 IT admins and end users log in to Password Manager Pro on a typical day and manage millions of privileged passwords.

Password Storage, Management & Workflow

Centralized Password Vault

Store all your enterprise passwords — privileged accounts, shared accounts, firecall accounts and others in the secure, centralized repository.

Shared Administrative Password Management

Securely manage shared accounts such as ‘Administrator’ on Windows, ‘root’ on Unix/Linux, ‘enable’ on Cisco, ‘sa’ on SQL and others.

Password Access Control Workflow

Request-release controls for password retrieval. Provision for granting time-limited access, exclusive privilege and concurrency controls.

Password Sharing, User Provisioning & Management

Password Ownership & Sharing

Well-defined ownership for the passwords stored in the centralized vault. Provision for selective sharing of passwords on need basis.

Role-based Access Controls

Fine-grained restrictions on managing resources and passwords stored in PMP. Restrictions are enforced based on predefined user roles.

Remote Password Reset

Automated Password Resets

Reset the passwords of remote resources from Password Manager Pro web-interface as and when required or automatically through scheduled tasks.

Wide Range of Target Systems

Supports out-of-the-box a wide range of target systems, databases, network devices for access control and automatic password resets.

Application-to-Application Password Management

Any application or script can query PMP and retrieve passwords to connect with other applications or databases, eliminating hard-coded passwords.

Post-Password Reset Custom Script Execution

Option to automatically execute custom scripts to carry out any follow-up action after a password reset action.

Privileged Session Management, Remote Access & Auto Logon

First-in Class Remote Login

Users can launch highly secure, reliable and completely emulated Windows RDP, SSH and Telnet sessions from browser without any plug-in or agent software.

Privileged Session Recording

Privileged sessions launched from PMP can be completely video recorded, archived and played back for forensic audits.

Automatic Login to Target Systems, Websites

Automatically log on to the target systems, websites and applications directly from the PMP web interface without copying and pasting of passwords.

Audit, Compliance & Reports

Comprehensive Audit Trails & Reporting

Complete record of ‘who’, ‘what’ and ‘when’ of password access. Intuitive reports on entire password management scenario in your enterprise.

Real-time Notifications, SIEM Integration

Real-time alerts on the occurrence of various password events enabling integration with Security Information and Event Management (SIEM) solutions

PCI DSS Compliance Reporting

Reports on the violations with respect to the use and management of privileged passwords based on the requirements of PCI-DSS.

Secure and Enterprise Ready

Extremely Secure & Reliable

All passwords & sensitive data are encrypted using AES 256-bit encryption. Dual encryption for extra security. Can be configured to run in FIPS 140-2 compliant mode.

Two-Factor Authentication

Enforcing two successive stages of authentication for logging in to PMP. Usual authentication is the first stage. Various options provided for the second stage.

Mobile Access

Retrieve passwords and approve requests on the go. Provision for secure offline access.Android App    iPhone App   

Disaster Recovery & High Availability

High Availability Architecture

Uninterrupted access to enterprise passwords through the deployment of redundant server and database instances. (A single Premium or Enterprise Edition license is enough for High Availability).

Secure Offline Access

Retrieve passwords even when there is no internet connectivity. The offline copy is as secure as the online version. Offline access is available in mobile app too.

PasswordsPro v3.1.2.2 Portable – для восстановления паролей к хэшам

Описание     Отзывы    (1)      

PasswordsPro – профессиональная программа для восстановления паролей к хэшам.

Программа имеет открытый API, который позволяет легко дополнить программу любым алгоритмом хэширования. Она имеет удобный интерфейс, не требует установки, использует несколько видов атак и содержит множество настроек, позволяющих гибко и эффективно восстанавливать забытые пароли.

Также программа поддерживает плагины, с помощью которых можно существенно расширить ее возможности, и в составе программы уже имеется более 10 готовых плагинов с различными полезными функциями по работе с хэшами, паролями и словарями. Программа имеет удобный интерфейс, не требует установки, а также содержит множество настроек.

Программа предназначена для восстановления паролей к хэшам, поддерживает свыше 180 различных алгоритмов хэширования и имеет следующие возможности:

Возможности:

  • 7 видов атак для восстановления паролей к хэшам;
  • Максимальное количество хэшей в лицензионной версии 10 миллионов;
  • Комфортная и быстрая работа с огромными списками хэшей;
  • Восстановление паролей длиной до 127 символов;
  • Восстановление паролей к неполным хэшам всех видов;
  • Восстановление паролей в кодировке Unicode;
  • Поддержка модулей хэширования сторонних разработчиков;
  • Поддержка плагинов;
  • Редактирование хэшей пользователей и другой информации;
  • Добавление хэшей в список из текстового файла, через диалоговое окно или из буфера обмена;
  • Копирование хэшей и найденных паролей в буфер обмена;
  • Экспорт хэшей в текстовый или в HTML-файл;
  • Поиск нужной информации в списке пользователей с хэшами;
  • Проверка текущего пароля на всех пользователях из списка или только на выделенных пользователях;
  • Верификация хэшей пользователей и их паролей;
  • Автоматическое накопление найденных паролей в файле “PasswordsPro.dic”;
  • Сортировка списка с хэшами;
  • Экспорт хэшей c найденными паролями в формате, привычном для форума InsidePro Software;
  • Поддержка “скрытого” режима работы программы, при котором она не видна на панели задач.

Типы хэшей, поддерживаемые программой:
— MySQL
— MySQL5
— DES(Unix)
— MD2
— MD4
— MD4(HMAC)
— MD4(Base64)
— MD5
— MD5(APR)
— MD5(Unix)
— MD5(HMAC)
— MD5(Base64)
— MD5(phpBB3)
— MD5(WordPress)
— MD5_HMAC($salt,MD5_HMAC($salt,$pass))
— SHA-1
— SHA-1(HMAC)
— SHA-1(Base64)
— SHA-1(Django)
— SHA-256
— SHA-256(Unix)
— SHA-256(Django)
— SHA-256(md5($pass))
— SHA-256(PasswordSafe)
— SHA-384
— SHA-384(Django)
— SHA-512
— SHA-512(Unix)
— Haval-128
— Haval-160
— Haval-192
— Haval-224
— Haval-256
— Tiger-128
— Tiger-160
— Tiger-192
— RipeMD-128
— RipeMD-160
— MaNGOS
— Whirlpool
— RAdmin v2.x
— Lineage II C4
— Domain Cached Credentials
— md5(md5($pass))
— md5($pass.$salt)
— md5($salt.$pass)
— md5(sha1($pass))
— md5($hex_salt.$pass)
— md5(md5(md5($pass)))
— md5(md5($pass).$salt)
— md5(md5($salt).$pass)
— md5($salt.md5($pass))
— md5($salt.$pass.$salt)
— md5(md5($salt).md5($pass))
— md5(md5($pass).md5($salt))
— md5(md5($pass).$const_salt)
— md5($salt.md5($salt.$pass))
— md5($salt.md5($pass.$salt))
— md5($salt.md5($pass).$salt)
— md5(sha1(md5(sha1($pass))))
— md5($hex_salt.$pass.$hex_salt)
— md5($username.md5($pass).$salt)
— md5(md5($username.$pass).$salt)
— sha1(md5($pass))
— sha1($salt.$pass)
— sha1($pass.$salt)
— sha1($username.$pass)
— sha1($salt.sha1($pass))
— sha1($username.$pass.$salt)
— sha1($salt.sha1($salt.sha1($pass)))

Что нового:

— Исправлена ошибка, связанная с проверкой паролей из буфера обмена.
— Увеличено максимальное количество модулей хэширования, которые можно одновременно загрузить в программу.
— Добавлены новые модули хэширования:
SHA-256(RuneScape).dll
SHA1($salt.$pass.$salt).dll

Migrating PMP Installations

If you want to move the PMP installation from one machine to another, or to a different location within the same machine, follow the procedure detailed below:

17.1 Prerequisites

Do not remove the existing installation of PMP until the new installation works fine. This is to ensure a backup and to overcome any disaster/data corruption during the movement.

If you are using the PostgreSQL database bundled with PMP:

  1. Take a backup of the current database and install the same version of PMP (as the one you are currently running) in the new machine.
  2. Restore the backup data in the new installation.

If you are using MySQL as the backend database:

  1. Stop the PMP server / service, if running.
  2. If you have installed PMP to run as a startup service, remove it as a service before proceeding further. (See the table below for the procedure to remove it as a service)
  3. Take a zip of the entire PMP installation folder and move the zip to a different machine or to a different location in the same machine as required.
  4. Now, install it to run as a service.
Installing as a Startup Service in Windows Installing as a Startup Service in Linux

To install as a service using batch file:

  1. Open the console and navigate to the <PMP_Installation_Folder>/bin directory.
  2. Execute the command pmp.bat install.

To remove as service using batch file:

  1. Open the console and navigate to the <PMP_Installation_Folder>/bin directory.
  2. Execute the command pmp.bat remove.
  1. Login as a root user.
  2. Open the console and navigate to the
    /bin directory.
  3. Execute sh pmp.sh install.
    (In Ubuntu, execute bash pmp.sh install)

To remove as service:

Execute the script sh pmp.sh remove
(In Ubuntu, execute bash pmp.sh remove)

What Problems Does Password Manager Pro Solve?

If you are an IT Administrator responsible for securely managing your IT infrastructure, check yourself:

  • Are you drowning in a pile of privileged passwords? Do you store administrative passwords in spreadsheets & flat files?
  • Do you find it difficult to track who has access to which accounts?
  • Do you laboriously logon to each application separately to periodically change passwords?

If yes, you certainly need Password Manager Pro!

Administrative/Privileged passwords are literally aplenty in enterprises. Servers, databases, switches, routers, firewalls and any other hardware or software, could have equally large number of administrative passwords. These passwords are insecurely stored in spreadsheets, text files and even as printouts and are shared by a group of administrators.

This traditional practice brings with it a host of issues such as:

  • Insecure storage of passwords inviting security threats
  • Uncontrolled super-user privileges
  • No role-based access control; internal controls become fragile
  • Lack of accountability for actions
  • No provision for enforcing standard password practices/policies
  • No centralized control

Password Manager Pro solves all these problems by providing a secure system to store, administer, and share passwords.

What are the Licensing Options for Password Manager Pro?

There are three license types:

  • Evaluation download valid for 30 days capable of supporting a maximum of 2 administrators. You can test Enterprise edition features.
  • Free Edition licensed software allows you to have 1 administrator and manage up to 10 resources. Valid forever.
  • Registered Version — Licensing is based on two factors:
  1. Number of Administrators
  2. Type of Edition — Standard, Premium or Enterprise

Note:

Password Manager Pro comes with five user roles — Administrator, Password Administrator, Privileged Administrator, Password Auditor and Password User. The term ‘administrator’ denotes Administrators, Password Administrators and Privileged Administrators. So, licensing restricts the number of administrators as a whole, which includes Administrators, Password Administrators and Privileged Administrators. There is no restriction on the number of Password Users and Password Auditors. To get more details on the five user roles, refer to this section of our help documentation.

  • Standard Edition — If your requirement is to have a secure, password repository to store your passwords and selectively share them among enterprise users, Standard Edition would be ideal.
  • Premium Edition — Apart from storing and sharing your passwords, if you wish to have enterprise-class password management features such as  remote password synchronization, password alerts and notifications, application-to-application password management, reports, high-availability and others, Premium edition would be the best choice.
  • Enterprise Edition — If you require more enterprise-class features like auto discovery of privileged accounts, integration with ticketing systems and SIEM solutions, jump server configuration, application-to-application password management, out-of-the-box compliance reports, SQL server / cluster as backend database, Enterprise edition will be ideal.

Updating Web Server Certificates using Password Manager Pro Web Console

If you want to use PMP web console to update the web server certificates, follow the below steps:

  1. Navigate to Admin >> Configuration >> Password Manager Pro Server.
  2. In the Password Manager Pro Server page that opens, install your keystore file belonging to the SSL certificate and/or change the default PMP server port.
  3. To update your SSL certificate, select the type of the keystore file (JKS, PKCS12 or PKCS11) from the Keystore type drop down menu.
  4. Browse the keystore file from your system and upload it in the Keystore Filename field.
  5. Enter the password of your keystore file beside the Keystore Password field.
  6. If you want to change the default PMP server port, enter the port number against the Server Port field.
  7. Click Save.

Restart Password Manger Pro after saving the changes.

System Requirements

The below table provides an overview of the hardware and software configurations required by Password Manager Pro:

Hardware Operating systems Web interface

Note: For Session Recordings, the disk space requirement may vary based on the usage levels.

Linux

  • Ubuntu 9.x and above
  • CentOS 4.4 and above
  • Red Hat Linux 9.0
  • Red Hat Enterprise Linux 7.x
  • Red Hat Enterprise Linux 6.x
  • Red Hat Enterprise Linux 5.x

Note: In general, PMP works well with any flavor of Linux and can also be run on VMs of the above operating systems.

HTML client requires one of the following browsers** to be installed in the system:

  • Microsoft Edge (on Windows)
  • Chrome, Firefox, and Safari (on Windows, Linux and Mac)

** Password Manager Pro is optimized for 1280 x 800 resolution and above.

Database

  • PostgreSQL 9.5.3, bundled with the product.
  • Supports MS SQL Server 2008 and above. SQL server should be installed in Windows 2008 Server and above.

See this document for more details on the software and hardware requirements for Password Manager Pro, based on your organization’s size.

Astroburn Pro 3.0.0.0172 Final + Portable [2012, Запись, копирование дисков]

Год выпуска: 2012Жанр: Запись, копирование дисковРазработчик: Astroburn.comСайт разработчика: http://www.astroburn.com/Язык интерфейса: Мультиязычный (русский присутствует)Тип сборки: Standard + PortableРазрядность: 32/64-bitОперационная система: Windows 2000, XP, Vista, 7 Описание: Astroburn — удобный инструмент для записи и мастеринга CD, DVD и Blu-ray дисков. Astroburn позволяет записывать, копировать, стирать все виды оптических носителей: CD-R/RW, DVD-R/RW, DVD+R/RW, BD-R/RE и DVD-RAM. Программа также поддерживает практически все устройства записи оптических дисков. Используя Astr …

Программы / Системные приложения / Работа с данными, жестким диском и носителями информации
Подробнее  

Starting and Shutting Down PMP

8.1 In Windows

Using the Start Menu Using the Tray Icon
  1. Navigate to Start >> Run  press Win+r. The Run box appears. Type services.msc and hit Enter.
  2. Locate the Password Manager Pro service in the Services console.
  3. You can start, stop or restart the service from the services console.
  1. Once you have successfully installed PMP in your system, you will find the icon in the windows tray area on the far right end of your task bar.
  2. Right click the tray icon and click the desired operation:
    • Stop the PMP Service
    • Launch the PMP web console
Installing PMP as a Startup Service Starting & Stopping the Server as a Service
  1. Login as a root user.
  2. Open the console and navigate to the <PMP_Home>/bin directory.
  3. Execute «sh pmp.sh install»
    (In Ubuntu, execute as «bash pmp.sh install»).
  4. To uninstall, execute the script «sh pmp.sh remove».

Возможности

Поддержка любых типов хэшей

В настоящее время программа поддерживает хэши следующих типов:

  • MySQL
  • MySQL5
  • DES(Unix)
  • MD4
  • MD4(HMAC)
  • MD5
  • MD5(HMAC)
  • MD5(Unix)
  • MD5(APR)
  • SHA-1
  • SHA-1(HMAC)
  • SHA-256
  • SHA-384
  • Domain Cached Credentials
  • Haval-128
  • Haval-160
  • Haval-192
  • Haval-224
  • Haval-256
    и др.

Дополнительно к этим типам программа поддерживает хэши со всех популярных
движков форумов (чего, кстати говоря, в таком объеме не умеет ни одна
аналогичная программа в мире) — vBulletin, phpBB3, SMF, IPB, myBB и др. Вот
некоторые из этих алгоритмов (в синтаксисе PHP):

  • md5($pass.$salt)
  • md5($salt.$pass)
  • md5(md5($pass))
  • md5(md5($pass).$salt)
  • md5($salt.md5($pass))
  • md5($salt.$pass.$salt)
  • md5(md5($salt).$pass)
  • md5(md5($salt).md5($pass))
  • sha1($username.$pass)
    и др.

Также сторонними разработчиками уже написано немало дополнительных модулей
хэширования, а именно: MD2, MS SQL, Oracle DES, Oracle SHA-1, RipeMD-128 и др.,
которые доступны в дистрибутиве программы или на
форуме программы, на котором уже опубликованы различные модули — к примеру,
есть модуль для зашифрованных паролей к Lineage II C4.

Конечно же, этими алгоритмами возможности программы не ограничиваются, т.к. в
нее можно достаточно просто добавить любой другой алгоритм и ниже вы
увидите, как легко это сделать.

Дополнительные возможности

Одна из многих уникальных особенностей программы — то, что она поддерживает
неполные хэши всех видов. А такая ситуация возникает нередко, ведь в БД
различных сервисов для экономии места (или для усложнения аудита) часто
сохраняется не весь хэш от пароля, а его часть (к примеру, половина), т.к. для
достоверной проверки вводимого пароля и этого вполне достаточно, но вот при
попытке восстановить пароли к таким хэшам практически все программы-брутфорсеры
пасуют, сообщая что «хэши имеют неизвестный или неправильный формат».
PasswordsPro же успешно работает с хэшами любой длины.

Восстановление паролей в Unicode кодировке — эта особенность также позволяет
использовать программу там, где не справляются другие брутеры.

Встроенные в программу дополнительные инструменты (генератор хэшей, генератор
паролей, конвертер Base64-текста, генератор словарей и др.) позволяют не выходя
из PasswordsPro автоматизировать множество задач, постоянно возникающих при
работе с паролями — от чистки и сортировки словарей до генерации случайных
паролей по маске.

Заключение

Ну что ж, мы воочию убедились, что программа PasswordsPro в умелых руках
(особенно «укомплектованная» большим количеством хороших словарей и
Rainbow-таблиц) — это реально боевая машина пехоты (в смысле — специалиста по
аудиту), смело пробирающаяся по туманному миру хэшей, ломая их направо и налево.
Но и она не всесильна, к сожалению.

В этом таинственном мире есть такие места, где PasswordsPro (как и другие
программы) просто «буксует», перебирая хэши, алгоритмы которых пока не позволяют
получить скорость перебора выше нескольких тысяч, сотен и даже десятков паролей
в секунду.

Есть над чем подумать и в отношении коллизий — о них много говорят, но пока
никто не нашел ни одной пары разных паролей, дающих одинаковый SHA-1 или
MD5-хэш. Первая же найденная пара таких паролей даст бесценную информацию о том,
как разные биты этих паролей «пробегают» по всем ступенькам хэширования,
трансформируясь в одинаковый результат.

Конечно же, и существующие в программе атаки еще не до конца раскрыли свой
потенциал, так что направлений развития программы — масса. От создания новых
модулей хэширования и оптимизации существующих (к примеру, задействование
видеопроцессоров для перебора паролей) до увеличения «интеллектуальности» самих
атак.

Поэтому так и хочется воскликнуть: «PasswordsPro — все только начинается»!

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *