ok - i'm stuck on this one. for our password cracking while pen-testing, we use LC5 - however i just obtained password hashes that we have found out are 17 characters in length - we just asked the auditee to find out - because LC5 was reporting that the LM String was *empty*. i have not had to use John or Cain, or others in awhile (so i'm a loser, but i want to be a whiner, i mean winner - heh), but has anyone had success with those, or other tools against longer password hashes?

heading off to re-learn about John and Cain.

for those who don't know anything about John, Cain or others:

http://en.wikipedia.org/wiki/Passwor...cking_programs

tia - for your time and repsonse(s).