New research has shown that password material from two widely used enterprise platforms can be transformed into formats suitable for offline cracking tools. A Silent Signal analysis of IBM i found that the QSYRUPWD API can be reverse engineered to recover reusable verifier data, including DES-derived values, SHA-1-related values, and NT hashes, even on systems using QPWDLVL 4. The author reported that exploiting the issue requires highly privileged *ALLOBJ and *SECADM authorities, but warned that anyone holding both permissions can extract credential material without knowing or resetting users’ passwords.
A separate Pentagrid study detailed how modern ASP.NET Core Identity password hashes can be correctly parsed into Hashcat-compatible input, including configurable v3 hashes that vary by PRF, iteration count, salt length, and subkey length. The researchers said many existing converters fail because they assume default parameters, while their approach supports v2 and v3 hashes using PBKDF2-HMAC-SHA1, SHA256, and SHA512. Supporting Hashcat documentation and example hash references underscore that once credential data is converted into recognized formats, organizations face increased password-auditing and password-cracking exposure if hashes are leaked or exported.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Silent Signal published analysis concluding that IBM i QSYRUPWD output can be reverse engineered into offline-crackable credential material on systems using QPWDLVL 2 and even QPWDLVL 4. The research showed that highly privileged administrators with *ALLOBJ and *SECADM can recover reusable verifier material, including NT hashes, from the API output.
Pentagrid published research explaining how to correctly parse ASP.NET Core Identity v2 and v3 password hashes into Hashcat-compatible format, including support for non-default v3 parameters. The article also warned that older Microsoft .NET PBKDF2 defaults may be weaker than OWASP recommendations if hashes are exposed.
The Hashcat wiki published its example hashes reference page, providing sample hash formats used for identification and cracking workflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
blog.silentsignal.eu
Open sourcepentagrid.ch
Open sourcehashcat.net
Open sourcehashcat.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.