| Server IP : 178.105.222.151 / Your IP : 216.73.216.38 Web Server : nginx/1.28.3 System : Linux MNK 7.0.0-15-generic #15-Ubuntu SMP PREEMPT_DYNAMIC Wed Apr 22 16:06:43 UTC 2026 x86_64 User : www-data ( 33) PHP Version : 8.5.4 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : OFF Directory : /usr/share/doc/python3-passlib/html/lib/ |
Upload File : |
<!DOCTYPE html>
<html lang="en" data-content_root="../">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>passlib.hash.msdcc - Windows’ Domain Cached Credentials — Passlib vlatest Documentation</title>
<link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=fa44fd50" />
<link rel="stylesheet" type="text/css" href="../_static/classic.css?v=2bf1fcf8" />
<script src="../_static/documentation_options.js?v=c6e86fd7"></script>
<script src="../_static/doctools.js?v=9bcbadda"></script>
<script src="../_static/sphinx_highlight.js?v=dc90522c"></script>
<link rel="icon" href="../_static/logo.ico"/>
<link rel="index" title="Index" href="../genindex.html" />
<link rel="search" title="Search" href="../search.html" />
<link rel="copyright" title="Copyright" href="../copyright.html" />
<link rel="next" title="passlib.hash.msdcc2 - Windows’ Domain Cached Credentials v2" href="passlib.hash.msdcc2.html" />
<link rel="prev" title="passlib.hash.nthash - Windows’ NT-HASH" href="passlib.hash.nthash.html" />
</head><body>
<div class="related" role="navigation" aria-label="Related">
<h3>Navigation</h3>
<ul>
<li class="right" style="margin-right: 10px">
<a href="../genindex.html" title="General Index"
accesskey="I">index</a></li>
<li class="right" >
<a href="../py-modindex.html" title="Python Module Index"
>modules</a> |</li>
<li class="right" >
<a href="passlib.hash.msdcc2.html" title="passlib.hash.msdcc2 - Windows’ Domain Cached Credentials v2"
accesskey="N">next</a> |</li>
<li class="right" >
<a href="passlib.hash.nthash.html" title="passlib.hash.nthash - Windows’ NT-HASH"
accesskey="P">previous</a> |</li>
<li class="nav-item nav-item-0"><a href="../contents.html">Passlib latest Documentation</a> »</li>
<li class="nav-item nav-item-1"><a href="index.html" >API Reference</a> »</li>
<li class="nav-item nav-item-2"><a href="passlib.hash.html" accesskey="U"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hash</span></code> - Password Hashing Schemes</a> »</li>
<li class="nav-item nav-item-this"><a href=""><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.msdcc</span></code> - Windows’ Domain Cached Credentials</a></li>
</ul>
</div>
<div class="document">
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="passlib-hash-msdcc-windows-domain-cached-credentials">
<span id="index-0"></span><h1><a class="reference internal" href="#passlib.hash.msdcc" title="passlib.hash.msdcc"><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.msdcc</span></code></a> - Windows’ Domain Cached Credentials<a class="headerlink" href="#passlib-hash-msdcc-windows-domain-cached-credentials" title="Link to this heading">¶</a></h1>
<div class="block-title admonition danger">
<p class="admonition-title">Danger</p>
<p><strong>This algorithm is not considered secure by modern standards.</strong>
It should only be used when verifying existing hashes,
or when interacting with applications that require this format.
For new code, see the list of <a class="reference internal" href="../narr/quickstart.html#recommended-hashes"><span class="std std-ref">recommended hashes</span></a>.</p>
</div>
<div class="versionadded">
<p><span class="versionmodified added">Added in version 1.6.</span></p>
</div>
<p>This class implements the DCC (Domain Cached Credentials) hash, used
by Windows to cache and verify remote credentials when the relevant
server is unavailable. It is known by a number of other names,
including “mscache” and “mscash” (Microsoft CAched haSH). Security wise
it is not particularly strong, as it’s little more than <a class="reference internal" href="passlib.hash.nthash.html"><span class="doc">nthash</span></a>
salted with a username. It was replaced by <a class="reference internal" href="passlib.hash.msdcc2.html"><span class="doc">msdcc2</span></a>
in Windows Vista.
This class can be used directly as follows:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="gp">>>> </span><span class="kn">from</span> <span class="nn">passlib.hash</span> <span class="kn">import</span> <span class="n">msdcc</span>
<span class="gp">>>> </span><span class="c1"># hash password using specified username</span>
<span class="gp">>>> </span><span class="nb">hash</span> <span class="o">=</span> <span class="n">msdcc</span><span class="o">.</span><span class="n">hash</span><span class="p">(</span><span class="s2">"password"</span><span class="p">,</span> <span class="n">user</span><span class="o">=</span><span class="s2">"Administrator"</span><span class="p">)</span>
<span class="gp">>>> </span><span class="nb">hash</span>
<span class="go">'25fd08fa89795ed54207e6e8442a6ca0'</span>
<span class="gp">>>> </span><span class="c1"># verify correct password</span>
<span class="gp">>>> </span><span class="n">msdcc</span><span class="o">.</span><span class="n">verify</span><span class="p">(</span><span class="s2">"password"</span><span class="p">,</span> <span class="nb">hash</span><span class="p">,</span> <span class="n">user</span><span class="o">=</span><span class="s2">"Administrator"</span><span class="p">)</span>
<span class="go">True</span>
<span class="gp">>>> </span><span class="c1"># verify correct password w/ wrong username</span>
<span class="gp">>>> </span><span class="n">msdcc</span><span class="o">.</span><span class="n">verify</span><span class="p">(</span><span class="s2">"password"</span><span class="p">,</span> <span class="nb">hash</span><span class="p">,</span> <span class="n">user</span><span class="o">=</span><span class="s2">"User"</span><span class="p">)</span>
<span class="go">False</span>
<span class="gp">>>> </span><span class="c1"># verify incorrect password</span>
<span class="gp">>>> </span><span class="n">msdcc</span><span class="o">.</span><span class="n">verify</span><span class="p">(</span><span class="s2">"letmein"</span><span class="p">,</span> <span class="nb">hash</span><span class="p">,</span> <span class="n">user</span><span class="o">=</span><span class="s2">"Administrator"</span><span class="p">)</span>
<span class="go">False</span>
</pre></div>
</div>
<div class="admonition seealso">
<p class="admonition-title">See also</p>
<ul class="simple">
<li><p><a class="reference internal" href="../narr/hash-tutorial.html#password-hash-examples"><span class="std std-ref">password hash usage</span></a> – for more usage examples</p></li>
<li><p><a class="reference internal" href="passlib.hash.msdcc2.html"><span class="doc">msdcc2</span></a> – the successor to this hash</p></li>
</ul>
</div>
<section id="interface">
<h2>Interface<a class="headerlink" href="#interface" title="Link to this heading">¶</a></h2>
<dl class="py class">
<dt class="sig sig-object py" id="passlib.hash.msdcc">
<em class="property"><span class="k"><span class="pre">class</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">passlib.hash.</span></span><span class="sig-name descname"><span class="pre">msdcc</span></span><a class="headerlink" href="#passlib.hash.msdcc" title="Link to this definition">¶</a></dt>
<dd><p>This class implements Microsoft’s Domain Cached Credentials password hash,
and follows the <a class="reference internal" href="passlib.ifc.html#password-hash-api"><span class="std std-ref">PasswordHash API</span></a>.</p>
<p>It has a fixed number of rounds, and uses the associated
username as the salt.</p>
<p>The <a class="reference internal" href="passlib.ifc.html#passlib.ifc.PasswordHash.hash" title="passlib.ifc.PasswordHash.hash"><code class="xref py py-meth docutils literal notranslate"><span class="pre">hash()</span></code></a>, <a class="reference internal" href="passlib.ifc.html#passlib.ifc.PasswordHash.genhash" title="passlib.ifc.PasswordHash.genhash"><code class="xref py py-meth docutils literal notranslate"><span class="pre">genhash()</span></code></a>, and <a class="reference internal" href="passlib.ifc.html#passlib.ifc.PasswordHash.verify" title="passlib.ifc.PasswordHash.verify"><code class="xref py py-meth docutils literal notranslate"><span class="pre">verify()</span></code></a> methods
have the following optional keywords:</p>
<dl class="field-list simple">
<dt class="field-odd">Parameters<span class="colon">:</span></dt>
<dd class="field-odd"><p><strong>user</strong> (<em>str</em>) – <p>String containing name of user account this password is associated with.
This is required to properly calculate the hash.</p>
<p>This keyword is case-insensitive, and should contain just the username
(e.g. <code class="docutils literal notranslate"><span class="pre">Administrator</span></code>, not <code class="docutils literal notranslate"><span class="pre">SOMEDOMAIN\Administrator</span></code>).</p>
</p>
</dd>
</dl>
<p>Note that while this class outputs lower-case hexadecimal digests,
it will accept upper-case digests as well.</p>
</dd></dl>
</section>
<section class="html-toggle" id="format-algorithm">
<h2>Format & Algorithm<a class="headerlink" href="#format-algorithm" title="Link to this heading">¶</a></h2>
<p>Much like <code class="xref py py-class docutils literal notranslate"><span class="pre">lmhash</span></code> and <code class="xref py py-class docutils literal notranslate"><span class="pre">nthash</span></code>, MS DCC hashes
consists of a 16 byte digest, usually encoded as 32 hexadecimal characters.
An example hash (of <code class="docutils literal notranslate"><span class="pre">"password"</span></code> with the account <code class="docutils literal notranslate"><span class="pre">"Administrator"</span></code>) is
<code class="docutils literal notranslate"><span class="pre">25fd08fa89795ed54207e6e8442a6ca0</span></code>.</p>
<p>The digest is calculated as follows:</p>
<ol class="arabic simple">
<li><p>The password is encoded using <code class="docutils literal notranslate"><span class="pre">UTF-16-LE</span></code>.</p></li>
<li><p>The MD4 digest of step 1 is calculated.
(The result of this step is identical to the <a class="reference internal" href="passlib.hash.nthash.html#passlib.hash.nthash" title="passlib.hash.nthash"><code class="xref py py-class docutils literal notranslate"><span class="pre">nthash</span></code></a>
of the password).</p></li>
<li><p>The unicode username is converted to lowercase,
and encoded using <code class="docutils literal notranslate"><span class="pre">UTF-16-LE</span></code>.
This should be just the plain username (e.g. <code class="docutils literal notranslate"><span class="pre">User</span></code>
not <code class="docutils literal notranslate"><span class="pre">SOMEDOMAIN\\User</span></code>)</p></li>
<li><p>The username from step 3 is appended to the
digest from step 2; and the MD4 digest of the result
is calculated.</p></li>
<li><p>The result of step 4 is encoded into hexadecimal,
this is the DCC hash.</p></li>
</ol>
</section>
<section id="security-issues">
<h2>Security Issues<a class="headerlink" href="#security-issues" title="Link to this heading">¶</a></h2>
<p>This algorithm is should not be used for any purpose besides
manipulating existing DCC v1 hashes, due to the following flaws:</p>
<ul class="simple">
<li><p>Its use of the username as a salt value (and lower-case at that),
means that common usernames (e.g. <code class="docutils literal notranslate"><span class="pre">Administrator</span></code>) will occur
more frequently as salts, weakening the effectiveness of the salt in
foiling pre-computed tables.</p></li>
<li><p>The MD4 message digest has been severely compromised by collision and
preimage attacks.</p></li>
<li><p>Efficient brute-force attacks on MD4 exist.</p></li>
</ul>
<p class="rubric">Footnotes</p>
<aside class="footnote-list brackets">
<aside class="footnote brackets" id="id1" role="doc-footnote">
<span class="label"><span class="fn-bracket">[</span>1<span class="fn-bracket">]</span></span>
<p>Description of DCC v1 algorithm -
<a class="reference external" href="http://openwall.info/wiki/john/MSCash">http://openwall.info/wiki/john/MSCash</a></p>
</aside>
</aside>
</section>
</section>
<div class="clearer"></div>
</div>
</div>
</div>
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="../contents.html">
<img class="logo" src="../_static/masthead.png" alt="Logo of Passlib"/>
</a></p>
<search id="searchbox" style="display: none" role="search">
<h3 id="searchlabel">Quick search</h3>
<div class="searchformwrapper">
<form class="search" action="../search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script>
<h3><a href="../contents.html">Table of Contents</a></h3>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="../index.html">Introduction</a></li>
<li class="toctree-l1"><a class="reference internal" href="../narr/index.html">Walkthrough & Tutorials</a></li>
<li class="toctree-l1 current"><a class="reference internal" href="index.html">API Reference</a><ul class="current">
<li class="toctree-l2"><a class="reference internal" href="passlib.apache.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.apache</span></code> - Apache Password Files</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.apps.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.apps</span></code> - Helpers for various applications</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.context.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.context</span></code> - CryptContext Hash Manager</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.crypto.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.crypto</span></code> - Cryptographic Helper Functions</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.exc.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.exc</span></code> - Exceptions and warnings</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.ext.django.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.ext.django</span></code> - Django Password Hashing Plugin</a></li>
<li class="toctree-l2 current"><a class="reference internal" href="passlib.hash.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hash</span></code> - Password Hashing Schemes</a><ul class="current">
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#overview">Overview</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#unix-hashes">Unix Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#other-modular-crypt-hashes">Other “Modular Crypt” Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#ldap-rfc2307-hashes">LDAP / RFC2307 Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#sql-database-hashes">SQL Database Hashes</a></li>
<li class="toctree-l3 current"><a class="reference internal" href="passlib.hash.html#ms-windows-hashes">MS Windows Hashes</a><ul class="current">
<li class="toctree-l4"><a class="reference internal" href="passlib.hash.lmhash.html"><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.lmhash</span></code> - LanManager Hash</a></li>
<li class="toctree-l4"><a class="reference internal" href="passlib.hash.nthash.html"><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.nthash</span></code> - Windows’ NT-HASH</a></li>
<li class="toctree-l4 current"><a class="current reference internal" href="#"><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.msdcc</span></code> - Windows’ Domain Cached Credentials</a></li>
<li class="toctree-l4"><a class="reference internal" href="passlib.hash.msdcc2.html"><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.msdcc2</span></code> - Windows’ Domain Cached Credentials v2</a></li>
</ul>
</li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#cisco-hashes">Cisco Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#other-hashes">Other Hashes</a></li>
</ul>
</li>
<li class="toctree-l2"><a class="reference internal" href="passlib.hosts.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hosts</span></code> - OS Password Handling</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.ifc.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.ifc</span></code> – Password Hash Interface</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.pwd.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.pwd</span></code> – Password generation helpers</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.registry.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.registry</span></code> - Password Handler Registry</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.totp.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.totp</span></code> – TOTP / Two Factor Authentication</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.utils.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.utils</span></code> - Helper Functions</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="../other.html">Other Documentation</a></li>
</ul>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="related" role="navigation" aria-label="Related">
<h3>Navigation</h3>
<ul>
<li class="right" style="margin-right: 10px">
<a href="../genindex.html" title="General Index"
>index</a></li>
<li class="right" >
<a href="../py-modindex.html" title="Python Module Index"
>modules</a> |</li>
<li class="right" >
<a href="passlib.hash.msdcc2.html" title="passlib.hash.msdcc2 - Windows’ Domain Cached Credentials v2"
>next</a> |</li>
<li class="right" >
<a href="passlib.hash.nthash.html" title="passlib.hash.nthash - Windows’ NT-HASH"
>previous</a> |</li>
<li class="nav-item nav-item-0"><a href="../contents.html">Passlib latest Documentation</a> »</li>
<li class="nav-item nav-item-1"><a href="index.html" >API Reference</a> »</li>
<li class="nav-item nav-item-2"><a href="passlib.hash.html" ><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hash</span></code> - Password Hashing Schemes</a> »</li>
<li class="nav-item nav-item-this"><a href=""><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.msdcc</span></code> - Windows’ Domain Cached Credentials</a></li>
</ul>
</div>
<div class="footer" role="contentinfo">
© <a href="../copyright.html">Copyright</a> 2008-2025, Assurance Technologies, LLC. Last Updated 2025-12-21.
Created using <a href="https://www.sphinx-doc.org/">Sphinx</a> 8.2.3.
</div>
</body>
</html>