Mandiant releases rainbow table to crack NTLMv1 passwords

Security firm Mandiant has unveiled a rainbow table that enables cracking of administrative passwords protected by the outdated NTLMv1 hashing algorithm in under 12 hours using affordable hardware. The tool targets lingering use of this vulnerable protocol in sensitive networks. Mandiant hopes it will push organizations to abandon the deprecated function.

Security researchers at Mandiant have introduced a new resource to highlight the dangers of the long-deprecated NTLMv1 hashing algorithm. Released on January 16, 2026, the rainbow table is a precomputed database of hash values mapped to plaintext passwords. It allows recovery of Net-NTLMv1 protected credentials—used in network authentication for services like SMB file sharing—in less than 12 hours on consumer-grade hardware costing under $600. The table is hosted on Google Cloud and works against passwords generated with the known plaintext challenge 1122334455667788.

NTLMv1 dates back to the 1980s, introduced with Microsoft's OS/2 operating system. Its weaknesses were first exposed in 1999 by cryptanalyst Bruce Schneier and researcher Mudge. Microsoft addressed these flaws with NTLMv2 in 1998 via Windows NT SP4. Despite this, and a recent announcement in August 2025 to deprecate NTLMv1, the protocol persists in some critical sectors. Industries like healthcare and industrial control systems often stick with legacy applications incompatible with newer algorithms, compounded by migration costs and operational inertia.

"By releasing these tables, Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1," the firm stated. Existing exploitation tools, such as Responder, PetitPotam, and DFSCoerce, can coerce Net-NTLMv1 hashes, but cracking them previously demanded significant resources or third-party services. Mandiant consultants still encounter NTLMv1 in active environments, leaving organizations open to easy credential theft.

Feedback from the security community has been positive. One infosec professional shared on Mastodon: "I’ve had more than one instance in my (admittedly short) infosec career where I’ve had to prove the weakness of a system and it usually involves me dropping a sheet of paper on their desk with their password on it the next morning. These rainbow tables aren’t going to mean much for attackers as they’ve likely already got them or have far better methods, but where it will help is in making the argument that NTLMv1 is unsafe."

Mandiant urges immediate disablement of Net-NTLMv1 and provides guidance on migration steps. The release serves as a wake-up call for laggards, emphasizing that continued use invites avoidable risks.

Makala yanayohusiana

A newly published zero-day exploit allows attackers with physical access to bypass BitLocker encryption on Windows 11 devices in seconds. The attack, named YellowKey, targets the default TPM-only configuration and grants full access to encrypted drives via a simple USB-based method.

Imeripotiwa na AI

Researchers have uncovered a large-scale compromise of Fortinet firewalls that exposed plaintext credentials for nearly 74,000 devices across 194 countries. The breach affects organizations including Oracle, Chevron, Lenovo, FedEx, and Fortinet itself, along with a NATO defense contractor.

A newly discovered flaw in Trend Micro's Apex One allows hackers to inject malicious code. The zero-day vulnerability is being actively exploited.

Imeripotiwa na AI

The FBI has issued a warning about a new phishing kit called Kali365 that targets Microsoft OAuth tokens. The kit is being offered on Telegram and uses AI-generated lures.

Ijumaa, 12. Mwezi wa sita 2026, 23:38:34

ShinyHunters exploits critical PeopleSoft zero-day vulnerability

Jumatano, 20. Mwezi wa tano 2026, 10:09:47

Microsoft warns of password reset exploits by hackers

Ijumaa, 8. Mwezi wa tano 2026, 11:45:07

Experts warn nearly half of passwords can be cracked quickly

Jumatano, 22. Mwezi wa nne 2026, 09:46:30

Microsoft patches critical ASP.NET Core vulnerability on macOS and Linux

Alhamisi, 16. Mwezi wa nne 2026, 01:10:06

TotalRecall Reloaded exposes Windows Recall security gap

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa