Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: Super Password Guesser

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    "Island Bartender" KG4CGC's Avatar
    Join Date
    Mar 2007
    Location
    EM84ru, Easley SC
    Posts
    51,711

    Super Password Guesser

    http://arstechnica.com/security/2012...rd-in-6-hours/

    25-GPU cluster cracks every standard Windows password in <6 hours

    A password-cracking expert has unveiled a computer cluster that can cycle through as many as 350 billion guesses per second. It's an almost unprecedented speed that can try every possible Windows passcode in the typical enterprise in less than six hours.
    The five-server system uses a relatively new package of virtualization software that harnesses the power of 25 AMD Radeon graphics cards. It achieves the 350 billion-guess-per-second speed when cracking password hashes generated by the NTLM cryptographic algorithm that Microsoft has included in every version of Windows since Server 2003. As a result, it can try an astounding 958 combinations in just 5.5 hours, enough to brute force every possible eight-character password containing upper- and lower-case letters, digits, and symbols. Such password policies are common in many enterprise settings. The same passwords protected by Microsoft's LM algorithm—which many organizations enable for compatibility with older Windows versions—will fall in just six minutes.
    I'm just wondering, who will be the first to get their hands on one? Governments or organized crime?

  2. #2
    Witch Doctor
    Join Date
    Apr 2010
    Posts
    387
    Deleted
    Last edited by WN9HJW; 08-23-2013 at 08:05 PM.

  3. #3
    Conch Master KJ3N's Avatar
    Join Date
    Jul 2009
    Location
    A secret cave in northern Delaware.
    Posts
    9,127
    Quote Originally Posted by WN9HJW View Post
    What's the difference ?
    With Republicans in charge? Nothing.

    See? Two can play this game. :roll:
    "People Who Don't Want Their Beliefs Laughed at Shouldn't Have Such Funny Beliefs" -AD5MB

    "If someone tells you he believes in and talks to an invisible bunny named Harvey, you put him on medication and a regimen of therapy. If someone tells you he believes in and talks to God, well, that's perfectly acceptable. Why that's the case is impossible for me to fathom." - WP2XX



    Latest ClubLog entries.

  4. #4
    Pope Carlo l NQ6U's Avatar
    Join Date
    Jun 2010
    Location
    Maritime Mobile
    Posts
    30,081
    Quote Originally Posted by WN9HJW View Post
    What's the difference ?
    Bzzzzzzzzt! Cliche. Please try again.

  5. #5
    Orca Whisperer n2ize's Avatar
    Join Date
    Dec 2007
    Location
    Crestwood, New York
    Posts
    33,899
    I don't want a wing wong.
    I keep my 2 feet on the ground, and my head in the twilight zone.

  6. #6
    Orca Whisperer n2ize's Avatar
    Join Date
    Dec 2007
    Location
    Crestwood, New York
    Posts
    33,899
    Quote Originally Posted by KG4CGC View Post
    http://arstechnica.com/security/2012...rd-in-6-hours/

    25-GPU cluster cracks every standard Windows password in <6 hours




    I'm just wondering, who will be the first to get their hands on one? Governments or organized crime?
    The first to get their hands on one is the one who already has it.
    I keep my 2 feet on the ground, and my head in the twilight zone.

  7. #7
    Administrator N8YX's Avatar
    Join Date
    Feb 2007
    Location
    Out in the sticks
    Posts
    26,167
    We built one of those four years ago. An 8-character credential - regardless of composition - took about two hours to break. This construct leveraged a combination of brute-force and rainbow tables techniques.
    "Everyone wants to be an AM Gangsta until it's time to start doing AM Gangsta shit."

  8. #8
    Orca Whisperer n2ize's Avatar
    Join Date
    Dec 2007
    Location
    Crestwood, New York
    Posts
    33,899
    Quote Originally Posted by KG4CGC View Post
    http://arstechnica.com/security/2012...rd-in-6-hours/

    25-GPU cluster cracks every standard Windows password in <6 hours




    I'm just wondering, who will be the first to get their hands on one? Governments or organized crime?
    So, is a standard Window$ password limited to only 8 charachters ? At 350 billion brute force guesses per second it comes to about 5.4 hours to generate all possible 8 charachter passwords from a 95 charachter set. Now, if we double the amount of charachters allowed to 16 characters and assume the same guess rate it will take an astounding 3.5 x 1016 hours (think how many years that is) to generate every possible password. Even if we increase the size of the password to just 10 charachters it will take 47518,8 hours or approx 8000x the number of hours required for an 8 charachter password. Even a 12 charachter password would require approximately 428 million hours.

    Sooo... it seems like this method is thwarted by using passwords larger than 8 charachters, preferably > 10 charachters.
    Last edited by n2ize; 12-11-2012 at 09:39 AM.
    I keep my 2 feet on the ground, and my head in the twilight zone.

  9. #9
    Conch Master W5GA's Avatar
    Join Date
    Jun 2008
    Posts
    8,550
    I tried something like this at a bank I worked at once upon a time, using a piece of software. To crack every employees password took my desktop PC about 2 hours. This was in the days of W95/98.
    When the government's boot is on your throat, whether it is a left boot or a right boot is of no consequence. — GARY LLOYD

    The nation we live in is the nation we have built by design, each successive generation raising the wall of tyranny a little higher. - Chris Griffin

  10. #10
    Banned
    Join Date
    Oct 2009
    Location
    Oregon, IL
    Posts
    7,717
    We have Gmail at work. We now have an option to have a 6 character word sent to us via cellphone text so when we correctly place the password, we have to get the text word correct. So there is a second layer of protection for that email.

    Dunno if they can crack that or not.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •