<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tool to generate 'phash' style hashed passwords? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/534234#M109959</link>
    <description>&lt;P&gt;Okay thanks maybe I should explain the behind the scenes&lt;/P&gt;
&lt;P&gt;\&lt;/P&gt;
&lt;P&gt;The problem here is my end user probably does not know openssl or could be on a device with no openssl tool ( iOS,&amp;nbsp; Android, etc&amp;nbsp; ) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was hoping we had a web user interface that would allow for "enter your password", click submit, and then forward me the hash back or the complete user config string&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;e.g&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;set template ORGTEMPLATE config shared local-user-database user john.doe phash $1$test$yV9NHGfaOtf.r/6W1Nqer/&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;# and that is an example do complain about my weak salt string &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now I'm trying to get them to move to a centralized authenticator serves or RADIUS-aaS ( e.g jumpcloud ) since they&amp;nbsp; have numerous users with various domains and contractors&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me keep probing around, I know a password generator tools that salts the passwords has to exist somewhere. Just have to find it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Mar 2023 18:12:45 GMT</pubDate>
    <dc:creator>kfelixdeft</dc:creator>
    <dc:date>2023-03-13T18:12:45Z</dc:date>
    <item>
      <title>Tool to generate 'phash' style hashed passwords?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/14970#M10980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a need to create password hashes offline, is there a tool or script available to take a cleartext password and generate a phash?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, the audit team wants to be able to select a password and generate the hash, so we can later paste into a firewall when provisioning the 'audit' user, even though I would never know what their password actually is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something that could run on MS-Windows, batch or Perl script would be easiest.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 18:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/14970#M10980</guid>
      <dc:creator>snocc</dc:creator>
      <dc:date>2013-06-21T18:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Tool to generate 'phash' style hashed passwords?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/14971#M10981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use the "request password-hash" command on the CLI of the firewall to generate these.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@lab-firewall&amp;gt; request password-hash username user password test1234&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$1$tjlcdrco$q/rIosAGEBWJQtFeRy9AX0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 18:45:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/14971#M10981</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2013-06-21T18:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tool to generate 'phash' style hashed passwords?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/14972#M10982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's an off-box method to do something similar: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.insidepro.com/hashes.php?lang=eng"&gt;http://www.insidepro.com/hashes.php?lang=eng&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;$1$tjlcdrco$q/rIosAGEBWJQtFeRy9AX0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;The $ is a delimiter.&amp;nbsp; 1=MD5(Unix) hash type.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;rIosAGEBWJQtFeRy9AX0=the hash&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;If you go to that website, and type out a cleartext password &amp;amp; salt (I don't think the user name is needed on this site), and then click "Generate".&amp;nbsp; You can scroll down to MD5(Unix) and see the generated hash.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;They provide a little more "behind the scenes" detail here:&amp;nbsp; &lt;A href="http://wiki.insidepro.com/index.php/MD5%28Unix%29"&gt;http://wiki.insidepro.com/index.php/MD5%28Unix%29&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 19:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/14972#M10982</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-06-21T19:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Tool to generate 'phash' style hashed passwords?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/533608#M109897</link>
      <description>&lt;P&gt;Does anybody have a new link to the offline phash generator? I'm looking for a means to give my customer access to a tool to generate the phash and then he|she can send me the phash to add to a user profile.&amp;nbsp; Right now they I'm generating random passwords with openssl or pyhton and sending the password back to the end-user. I rather not continue to do this since I know the password.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 17:17:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/533608#M109897</guid>
      <dc:creator>kfelixdeft</dc:creator>
      <dc:date>2023-03-08T17:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Tool to generate 'phash' style hashed passwords?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/533685#M109900</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196139"&gt;@kfelixdeft&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'm not sure that you can do this anymore like you used to be able to. You could build out a web portal that uses the firewall's API to gather the generated password hash however, then simply have them send you the output so that you can add it to the configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 22:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/533685#M109900</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-03-08T22:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Tool to generate 'phash' style hashed passwords?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/533725#M109907</link>
      <description>&lt;P&gt;As you are writing down "openssl" as a phash generator, I believe most of users can do that on their computer.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;Here is one example:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;I used my Windows 10 machine with ubuntu on it (ubuntu was installed by WSL)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;c:\&amp;gt;ubuntu&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;root@MyWindows:~# openssl passwd -5 -salt sampleSALT Password123&lt;BR /&gt;$5$sampleSALT$g.faXa7FXwSPDL6dW6fkoNQt7kueN/yfSV3moRtUxE6&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;On PA device:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Configure new admin user with phash which I generated on the above&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@PA-VM_OS10(active)# set mgt-config users sampleadmin permissions role-based superuser yes&lt;/P&gt;
&lt;P&gt;[edit]&lt;BR /&gt;admin@PA-VM_OS10(active)# set mgt-config users sampleadmin phash $5$sampleSALT$g.faXa7FXwSPDL6dW6fkoNQt7kueN/yfSV3moRtUxE6&lt;/P&gt;
&lt;P&gt;[edit]&lt;BR /&gt;&lt;BR /&gt;admin@PA-VM_OS10(active)# commit&lt;/P&gt;
&lt;P&gt;Commit job 159 is in progress. Use Ctrl+C to return to command prompt&lt;BR /&gt;..........55%.70%98%.................100%&lt;BR /&gt;Configuration committed successfully&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;To test this new admin:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Number of failed attempts since last successful login: 0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sampleadmin@PA-VM_OS10(active)&amp;gt; show admins&lt;/P&gt;
&lt;P&gt;Admin From Client Session-start Idle-for Session-expiry&lt;BR /&gt;---------------------------------------------------------------------------------------------&lt;BR /&gt;* sampleadmin 172.30.10.22 CLI 03/09 13:16:31 00:00:00s 04/08 13:16:31&lt;/P&gt;
&lt;P&gt;sampleadmin@PA-VM_OS10(active)&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;sampleadmin@PA-VM_OS10(active)&amp;gt; configure&lt;BR /&gt;Entering configuration mode&lt;BR /&gt;[edit]&lt;BR /&gt;sampleadmin@PA-VM_OS10(active)# show mgt-config users sampleadmin&lt;BR /&gt;sampleadmin {&lt;BR /&gt;permissions {&lt;BR /&gt;role-based {&lt;BR /&gt;superuser yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;phash $5$sampleSALT$g.faXa7FXwSPDL6dW6fkoNQt7kueN/yfSV3moRtUxE6;&lt;BR /&gt;}&lt;BR /&gt;[edit]&lt;BR /&gt;sampleadmin@PA-VM_OS10(active)#&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 04:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/533725#M109907</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2023-03-09T04:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tool to generate 'phash' style hashed passwords?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/534234#M109959</link>
      <description>&lt;P&gt;Okay thanks maybe I should explain the behind the scenes&lt;/P&gt;
&lt;P&gt;\&lt;/P&gt;
&lt;P&gt;The problem here is my end user probably does not know openssl or could be on a device with no openssl tool ( iOS,&amp;nbsp; Android, etc&amp;nbsp; ) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was hoping we had a web user interface that would allow for "enter your password", click submit, and then forward me the hash back or the complete user config string&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;e.g&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;set template ORGTEMPLATE config shared local-user-database user john.doe phash $1$test$yV9NHGfaOtf.r/6W1Nqer/&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;# and that is an example do complain about my weak salt string &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now I'm trying to get them to move to a centralized authenticator serves or RADIUS-aaS ( e.g jumpcloud ) since they&amp;nbsp; have numerous users with various domains and contractors&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me keep probing around, I know a password generator tools that salts the passwords has to exist somewhere. Just have to find it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 18:12:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tool-to-generate-phash-style-hashed-passwords/m-p/534234#M109959</guid>
      <dc:creator>kfelixdeft</dc:creator>
      <dc:date>2023-03-13T18:12:45Z</dc:date>
    </item>
  </channel>
</rss>

