Who's Online
There are currently, 69 guest(s) and 0 member(s) that are online.
You are Anonymous user. You can register for free by clicking here
|  |
The Professional Security Testers Warehouse for the GPEN GSEC GCIH GREM CEH QISP Q/ISP OPST CPTS: Passwords
[ Go to Home | Select a New Topic ] |
|
RainbowCrack 1.4 is released Posted by cdupuis on Wednesday, 22 July 2009 @ 12:03:41 EDT (1287 reads) Topic Passwords
What's New
[July 22, 2009]RainbowCrack 1.4 is released This version focus on more effective rainbow table file format. New features:
- New compact rainbow table file format (.rtc) reduce rainbow table size by 50% to 56.25%
- New rt2rtc utility convert rainbow table from raw file format (.rt) to compact file format (.rtc)
- New rtc2rt utility convert rainbow table from compact file format (.rtc) to raw file format (.rt)
- The rcrack/rcrack_cuda program support both .rt and .rtc rainbow table file format
- Conversion from non-perfect to perfect rainbow table is supported by rt2rtc utility
Smaller rainbow table significantly improve table lookup performance!
Introduction
RainbowCrack is a general propose implementation of Philippe Oechslin's faster time-memory trade-off technique. It cracks hashes with rainbow tables. Features:
- Full time-memory tradeoff tool suites, including rainbow table generation, sort, conversion and lookup
- Support rainbow table of any hash algorithm
- Support rainbow table of any charset
- Support rainbow table in raw file format (.rt) and compact file format (.rtc)
- Computation on multi-core processor support
- Computation on GPU (via NVIDIA CUDA technology) support (not freely available)
- Computation on multi-GPU (via NVIDIA CUDA technology) support (not freely available)
- Runs on Windows XP 32-bit and Windows Vista 32-bit
- Command line user interface
A brute force hash cracker generate all possible plaintexts and compute the corresponding hashes on the fly, and then compare the hashes with the target hash. The plaintext is found if one of them match, otherwise the intermediate computation results are discarded. A time-memory tradeoff hash cracker need a precomputation stage, at the time all plaintext/hash pair within the selected hash algorithm, charset, plaintext length range are computed and the results are stored in files called rainbow table. It is time consuming to do this kind of computation. Once the one time precomputation is finished, hashes within the table can be cracked with much better performance than a brute force cracker.
Performance
We compare performance of different GPU based hash cracking methods. The first is direct GPU based brute force; the second is GPU based time-memory tradeoff hash cracking implemented in RainbowCrack software. The time-memory tradeoff approach is always hundreds of times faster.  Performance data of RainbowCrack software is calculated based on test results of rainbow table "md5_ascii-32-95#1-7", "ntlm_ascii-32-95#1-7" and "lm_ascii-32-65-123-4#1-7" as listed in rainbow table page.
VISIT: http://project-rainbowcrack.com/ for all the details
L0phtCrack 6 has been Released Posted by cdupuis on Wednesday, 27 May 2009 @ 23:06:23 EDT (908 reads) Topic Passwords
Anonymous writes "
 L0phtCrack is Back L0phtCrack 6 is packed with powerful features such as scheduling, hash extraction from 64 bit Windows versions, multiprocessor algorithms, and networks monitoring and decoding. Yet it is still the easiest to use password auditing and recovery software available.
Password Scoring L0phtCrack 6 provides a scoring metric to quickly assess password quality. Passwords are measured against current industry best practices, and are rated as Strong, Medium, Weak, or Fail.
Pre-computed Dictionary Support Pre-computed password files is a must have feature in password auditing. L0phtCrack 6 supports pre-computed password hashes. Password audits now take minutes instead of hours or days.
Windows & Unix Password Support L0phtCrack 6 imports and cracks Unix password files. Perform network audits from a single interface.
Remote password retrieval L0phtCrack 6 has a built-in ability to import passwords from remote Windows, including 64-bit versions of Vista, Windows 7, and Unix machines, without requiring a third-party utility.
Scheduled Scans System administrators can schedule routine audits with L0phtCrack 6. Audits can be performed daily, weekly, monthly, or just once, depending on the organization's auditing requirements.
Remediation L0phtCrack 6 offers remediation assistance to system administrators on how to take action against accounts that have poor passwords. Accounts can be disabled, or the passwords can be set to expire from within the L0phtCrack 6 interface. Remediation works for Windows user accounts only.
Updated Vista/Windows 7 Style UI The user interface is improved and updated. More information is available about each user account, including password age, lock-out status, and whether the account is disabled, expired, or never expires. Information on L0phtCrack 6's current session is provided in an "immediate window" with a reporting tab providing up-to-the-minute status of the current auditing session
More Info and Download "
L0phtCrack is back! Posted by cdupuis on Thursday, 19 March 2009 @ 12:32:31 EDT (670 reads) Topic Passwords
Lou writes "L0phtCrack is back! At a special information session at SOURCE Boston (Thursday, 10:15am), the team that brought you L0phtCrack will be releasing version 6 of the highly-acclaimed Windows password auditing tool. Come to the session to learn about this release, its new features and platform support, and the story of the product from the days of the L0pht, to @stake, Symantec, and finally back to the L0pht.
Expect www.l0phtcrack.com to go live soon! "
RainbowCrack 1.3 has been released Posted by cdupuis on Friday, 13 February 2009 @ 15:42:17 EST (1081 reads) Topic Passwords
What's New
[February 12, 2009] RainbowCrack 1.3 is released
RainbowCrack 1.3 is released, with following new features:
- Multicore processor support
- Overlapped computation and harddisk read
- Improved hash algorithm performance of NTLM and MD5
- Fully backward compatible with existing rainbow tables generated by earlier versions of RainbowCrack
- Other enhancements
A proof of concept implementation of GPU accelerated RainbowCrack is also provided, with the use of CUDA technology.
Introduction
RainbowCrack is a general propose implementation of Philippe Oechslin's faster time-memory trade-off technique. In short, the RainbowCrack software is a hash cracker that use time-memory tradeoff algorithm.
A brute force hash cracker generate all possible plaintexts and compute the corresponding hashes on the fly, and then compare the hashes with the target hash. The plaintext is found if one of them match, otherwise the intermediate computation results are discarded.
A time-memory tradeoff hash cracker need a precomputation stage, at the time all plaintext/hash pair within the selected hash algorithm, charset, plaintext length range are computed and the results are stored in files called rainbow table. It is time consuming to do this kind of computation. Once the one time precomputation is finished, hashes within the table can be cracked with much better performance than a brute force cracker.
Download
Documentation
[TODO] Documentation for RainbowCrack 1.3 are not ready yet. Lots of documentation for RainbowCrack 1.2 are outdated, I am planning to renew all of them in following weeks.
Rainbow Table
LM configuration #6 table set
| hash algorithm |
LM |
| charset |
alpha-numeric-symbol32-space = [ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()-_+=~`[]{}|:;"'<>,.?/ ] (Because the LM hash algorithm convert all lowercase characters in password into uppercase, it is not necessary to include lowercase characters in charset of any LM tables.) |
| plaintext length range |
1 to 7 (Because the LM hash algorithm break 14 character password into two 7 character chunks and hash them seperately, the 1 to 7 plaintext length configuration is capable of crack password up to 14 characters.) |
| keyspace |
7555858447479 (2^42.8) |
| table size |
64 GB |
| success rate |
0.999 |
| table generation commands |
rtgen_lm_cfg6.txt |
| performance |
30 LM hashes with random plaintexts are generated to test these 64 GB table set. A total of 3 tests are run, with 10 hashes used in each run. The total program runtime to crack all hashes are as follows: RainbowCrack 1.2 on Core2 Duo E7300 Test 1 (10 LM hashes): 1045.89 seconds Test 2 (10 LM hashes): 1552.02 seconds Test 3 (10 LM hashes): 1325.65 seconds RainbowCrack 1.3 on Core2 Duo E7300 Test 1 (10 LM hashes): 516.11 seconds Test 2 (10 LM hashes): 771.69 seconds Test 3 (10 LM hashes): 740.38 seconds As the possible plaintext number is 7555858447479, and the time to crack the hashes is 516.11 seconds in Test 1 of RainbowCrack 1.3. The equivalent plaintext search speed is 7555858447479/516.11 = 14640 Million plaintexts/second. |
FreeRainbowTables.com news Posted by cdupuis on Friday, 28 November 2008 @ 21:12:30 EST (782 reads) Topic Passwords
FreeRainbowTables.com has recently moved to the BOINC platform for generation of rainbow tables.
We are happy to share the news with our users, and we hope you will continue to help us generate more rainbow tables.
It is easy to htlp us in the generation of high quality rainbow tables. Simply visit our download page ( http://www.freerainbowtables.com/en/download/ ) and follow the instructions.
Thanks
/JA
Brute forcing just got a little smarter at AWLG.org Posted by cdupuis on Wednesday, 26 November 2008 @ 14:04:13 EST (791 reads) Topic Passwords
NOTE FROM CLEMENT: Matt has been a PST member for a while and he sent me the following news:
Sender's Name: Matt Sender's Email: matt@awlg.org
http://awlg.org/index.gen
I just wanted to make you and your associates aware of a new online web app I've coded called the Associative Word List Generator (AWLG) located at AWLG.org.
Basically, AWLG will take user words and phrases and search the internet for words associated with the user's input. As such, AWLG allows people to generate relevant word lists with minimal effort.
These word lists can then be used for ethical brute forcing, keyword generation, etc.
For a flash demo, visit http://www.awlg.org/awlg/whatis.gen
I'd be glad to answer any questions you may have.
Also, please feel free to share what you know about this tool with anyone you wish, as AWLG is officially in beta now.
Thanks,
Matt G. matt@awlg.org http://awlg.org/index.gen
fgdump (2.0.0) and pwdump (1.7.1) has been released Posted by boss on Monday, 28 April 2008 @ 12:46:37 EDT (3986 reads) Topic Passwords
Anonymous writes "Folks,
The foofus.net team is pleased to announce updates to both fgdump (2.0.0) and pwdump (1.7.1), which incorporate a number of new features, the most significant of which is that both tools now support 64-bit targets.
We are also pleased to announce the creation of a mailing list for the purposes of tool support, bug reports, feature requests and new revision announcements. This mailing list currently covers fgdump, pwdump and medusa. Feel free to sign up at http://lists.foofus.net/listinfo.cgi/foofus-tools-foofus.net.
For all the details on the latest fgdump and pwdump releases, please visit their home pages:
http://www.foofus.net/fizzgig/fgdump
http://www.foofus.net/fizzgig/pwdump
As always, please contact me with any bug reports or feature requests.
--f fizzgig@foofus.net"
SShatter -- A brute force tool for SSH Posted by boss on Saturday, 06 October 2007 @ 21:19:52 EDT (990 reads) Topic Passwords
New version of PWDUMP6 and FGDump have been released Posted by boss on Thursday, 21 June 2007 @ 22:42:09 EDT (943 reads) Topic Passwords
Anonymous writes "I am pleased to announce a new version of pwdump6 and its more powerful brother fgdump. Both programs are now at version 1.6.0.
The primary change in both packages is that they will once again, for the time being, sneak by antivirus more easily. This is strictly to allow the majority of the userbase, who are legitimate pen-testing users, to carry out their work unfettered. Feel free to read my brief dissertation on the subject (particularly folks from AV vendor land!) on the site. AV will eventually catch up and we'll have to play this game all over again, but for now, this should help some.
fgdump was also fixed to correct a problem when running locally - if you've received the infamous "error 2" message before, you should find that no longer occurs! As always, for pwdump6 users, I recommend highly that you switch to fgdump - I doubt you will regret it. :)
The relevant links are:
http://www.foofus.net/fizzgig/fgdump
and
http://www.foofus.net/fizzgig/pwdump
As always, email me with any questions, concerns or suggestions.
--fizzgig "
fgdump 1.5.0 and pwdump 1.5.0 Released! Posted by boss on Tuesday, 27 March 2007 @ 17:32:37 EDT (944 reads) Topic Passwords
Anonymous writes "Good day pen-test folks,
I am pleased to announce the release of pwdump6 1.5.0 as well as fgdump 1.5.0 at the following locations:
http://www.foofus.net/fizzgig/fgdump http://www.foofus.net/fizzgig/pwdump For those unfamiliar with the tools, allow me to briefly summarize.
pwdump6 is an updated version of the classic Windows password hash dumper pwdump3e. It has been updated to circumvent DEP which caused crashes on newer operating systems, and has also had several features added to make it more usable.
fgdump is a more powerful version of pwdump6 that performs cached credential dumps of a target host as well as stopping several brands of antivirus while the dumps are running. It is also fully multi-threaded and supports several means of targeting large numbers of hosts. I recommend using fgdump for most pen-test activities, as it has served us well over the past couple of years.
Version 1.5.0 of both programs takes advantage of some changes which makes them less likely to be detected by antivirus, at least as of today. This will be particularly helpful to those of you dealing with recent, more aggressive AV solutions. I have also updated the README file for pwdump6 to give some examples, as it seems some folks were having a hard time figuring out how to get started with it.
As always, I welcome feedback and suggestions, and am certainly willing to help you troubleshoot if you find yourself facing problems.
Enjoy!
--fizzgig"
HalfLMChallenge Rainbow Tables Posted by boss on Saturday, 27 January 2007 @ 08:33:21 EST (788 reads) Topic Passwords
Anonymous writes "HalfLMChallenge rainbow tables are now available on RainbowCrack-online. These can be used against sniffed hashes, acquired by Cain & Abel. http://www.oxid.it/ Details regarding the tables can be found below or on http://www.rainbowcrack-online.com/?x=lm
HALFLMCHALLENGE Character set > alpha-numeric-symbol32-space (will crack mixalpha-numeric-symbol32-space-1-7) [ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()-_+=~`[]{}|:;"',.?/ ] Plaintext length range [ 1-7 ] Server Challenge [ 1122334455667788 ] Rainbow chain length [ 10000 ] Rainbow chain count [ 134200000 ] Used Diskspace [ 59,99 Gb ] Nr. of Rainbow Tables [ 30 ] Needed time to generate (one cpu) [ 1 year and 8 months ] Max cryptanalysis time [ 55 min ] Current Succesrate [ 99,39 % ] Status [ Complete Set ]
OTHER INTERESTING STATS:
Tables: 4.9 TB Supported Algorithms: 13 (CiscoPIX, LanManager, MD4, MD5, NTLM, MySQL123, MySQLSHA1, SHA1, HalfLMChallenge, LMChallenge, NTLMChallenge, MSCache, Oracle) All our sets are 100% complete, view and compare.. Can't decide? Contact Us How long would it take one computer to generate these sets? Around 64 years! It's only taken us about 3 years to generate these tables. Any questions can be mailed to contact@rainbowcrack-online.com "
Free RainbowCrack Cracker online Posted by boss on Friday, 26 January 2007 @ 16:44:23 EST (738 reads) Topic Passwords
cdupuis writes " This website is an advanced distributed cracking system powered by rainbowtables, wordlists and other techniques.
At this moment, we have 16/21 computers online and working to crack hashes using 0.353515625 Tb rainbowtables.
Rainbow tables implementation base is taken from open source tool which is located at www.antsight.com/zsl/rainbowcrack/
We provide free limited usage of our system but it is strongly adivised that you read our FAQ.
For more up to date information, contact us on irc. Our channel is located at irc.Plain-Text.info #rainbowcrack
Visit the site at: http://www.plain-text.info/index/ "
Free Rainbow Tables Project Posted by boss on Thursday, 28 December 2006 @ 21:42:35 EST (711 reads) Topic Passwords
Hak5 Rainbow Tables Lan Manager ALL available for Download Posted by boss on Wednesday, 27 December 2006 @ 11:13:32 EST (837 reads) Topic Passwords
cdupuis writes " Hak5 Rainbow Table - LM All 1-7 120GB Complete
The Hak5 RainbowTables project has finished generating the 120GB LM All tableset, and they are now available for public download via torrent.
Direct questions can be made on the RainbowTables chatroom, irc.hak5.org #RainbowTables The torrent download is available here: File Information: LM All Rainbow Tables
Brought to you by the community members of Hak5 (http://www.hak5.org) and RainbowTables (http://hak5.org/wiki/index.php?title=Community_Rainbow_Tables). Without them, these tables wouldn't exist.
For more information on how to use these files, please visit http://www.antsight.com/zsl/rainbowcrack/
Technical Details - Charset: all(ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()-_+=~`[]{}|:;"'<>,.?/)
- Plaintext Length Range: 1-7
- Key Space: 68^1 + 68^2 + 68^3 + 68^4 + 68^5 + 68^6 + 68^7 = 6823331935124
- Success Rate: 1 - (1 - calc_success_probability(6823331935124, 9000, 8000000000/8)) ^ 8 = 0.9990
- Mean/Max cryptanalysis time: 197.0106s/915.2542s*
- Max Disk Access Time: 3802.2s*
"
PWDumpX 1.1 has been released -- Dumps the domain cache Posted by boss on Friday, 22 December 2006 @ 19:44:51 EST (3887 reads) Topic Passwords
|
 |
Login
Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.
Big Story of Today
There isn't a Biggest Story for Today, yet.
Old Articles
| Tuesday, December 12 | | · | fgdump 1.4.0 and pwdump6 1.4.3 released |
| Tuesday, December 05 | | · | Distributed Rainbow Tables Generator -- Lend them your CPU cycles |
| Tuesday, November 28 | | · | New Windows tool - PWDumpX v1.0 |
| Tuesday, November 14 | | · | Cain & Abel v3.8 released |
| Monday, October 30 | | · | Free Rainbow Tables Available for Download |
| Friday, October 20 | | · | Version 1.3 of Medusa is now available |
| Thursday, May 11 | | · | Version 1.7.1 of John the ripper is out |
| Thursday, May 04 | | · | Version 1.1 of Medusa is now available |
| Thursday, March 30 | | · | OphCrack 2.2 Released |
| Sunday, March 19 | | · | PWDump6 Version 1.2 Beta has been released |
| Thursday, February 09 | | · | John The Ripper 1.7 release is out |
| Wednesday, February 08 | | · | Free online rainbowtables password cracking |
| Thursday, January 26 | | · | John the Ripper version 1.7 has been released |
| Monday, January 16 | | · | Bob the Butcher Distributed Password Cracker |
| Tuesday, January 10 | | · | PWDump6 and FGDump |
Older Articles
|