Collecting LastPass password hashes
LastPass, while a cloud-hosted service, maintains a local copy of your password vault, which is protected by your vault passphrase. The location for this vault will vary based on the operating system and even browser, but thankfully, LastPass has documented these locations for us on their support site, at this link as of April 2024: https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/FAQ_Data_Storage.html&_LANG=enus. Unlike KeePass, LastPass is a commercial service, which means we need to pay for this service. During the signup process, something very interesting happens – we are prompted to create a vault password that meets specific requirements, including length and complexity, as shown in Figure 9.2:
Figure 9.2 – LastPass vault password requirements
It is interesting that LastPass has increased these vault password requirements in recent years,...