NEWS

Passwords hacked in no time

  • 53 Replies
  • 15089 Views

Karasin Black

  • *
  • Newb
  • *
  • Posts: 23
« on: <06-06-11/0232:08> »
http://www.zdnet.com/blog/hardware/cheap-gpus-are-rendering-strong-passwords-useless/13125

"The results are startling. Working against NTLM login passwords, a password of “fjR8n” can be broken on the CPU in 24 seconds, at a rate of 9.8 million password guesses per second. On the GPU, it takes less than a second at a rate of 3.3 billion passwords per second."
"Wherever there is light, there must be shadow"
- Tao of Shinsei

Stahlseele

  • *
  • Omae
  • ***
  • Posts: 760
  • Elfen haben doofe Ohren.
« Reply #1 on: <06-06-11/0727:10> »
Shit, gotta make sure nobody at works sees this . . Our Password Rules are strict and dumb and complicated enough as it is <.<
"In the absence of orders, go find something and kill it." - Field Marshall Erwin Rommel
"In a free society, diversity is not disorder. Debate is not strife. And dissent is not revolution." - George W. Bush

FastJack

  • *
  • Administrator
  • Prime Runner
  • *****
  • Posts: 6374
  • Kids these days...
« Reply #2 on: <06-06-11/0756:00> »
Well, I think I know what to get for my next PC tower now... ;)

Stahlseele

  • *
  • Omae
  • ***
  • Posts: 760
  • Elfen haben doofe Ohren.
« Reply #3 on: <06-06-11/0909:29> »
*pats his new GTX580 3072*
"In the absence of orders, go find something and kill it." - Field Marshall Erwin Rommel
"In a free society, diversity is not disorder. Debate is not strife. And dissent is not revolution." - George W. Bush

CanRay

  • *
  • Freelancer
  • Mr. Johnson
  • ***
  • Posts: 11141
  • Spouter of Random Words
« Reply #4 on: <06-06-11/0956:16> »
Great, as if I wasn't paranoid enough as it is...
Si vis pacem, para bellum

#ThisTaserGoesTo11

Stahlseele

  • *
  • Omae
  • ***
  • Posts: 760
  • Elfen haben doofe Ohren.
« Reply #5 on: <06-06-11/1309:32> »
Dr.Strange-Data. Or how i learned to stop worrying and to love the hack.
"In the absence of orders, go find something and kill it." - Field Marshall Erwin Rommel
"In a free society, diversity is not disorder. Debate is not strife. And dissent is not revolution." - George W. Bush

CanRay

  • *
  • Freelancer
  • Mr. Johnson
  • ***
  • Posts: 11141
  • Spouter of Random Words
« Reply #6 on: <06-06-11/1559:26> »
Dr.Strange-Data. Or how i learned to stop worrying and to love the hack.
I've stayed away from learning about hacking.

Nuclear weaponry on the other hand...
Si vis pacem, para bellum

#ThisTaserGoesTo11

hobgoblin

  • *
  • Omae
  • ***
  • Posts: 523
  • Panda!
« Reply #7 on: <06-06-11/1715:01> »
NTLM is a poor example as it is known to be weak. Hell, these days it is there mostly as backwards compatibility in networks where older windows install are used side by side with new ones.

https://secure.wikimedia.org/wikipedia/en/wiki/NTLM

Btw, i read something recently claiming that a password based on a full sentence was very secure. This because spaces can show up in all kinds of places, and the number of characters grow quickly. Question is if some of the password systems around can actually handle a proper length.
« Last Edit: <06-06-11/1718:37> by hobgoblin »
Want to see my flash new jacket?

Stahlseele

  • *
  • Omae
  • ***
  • Posts: 760
  • Elfen haben doofe Ohren.
« Reply #8 on: <06-06-11/2053:39> »
There is no security anymore.
Even with the most perfectly secure password, there is cloud computing.
you can rent time on amazons server farm for what ever you want.
so if you are willing to plop down some money, the server farm will reduce the work time for cracking a given password from years to hours . .
"In the absence of orders, go find something and kill it." - Field Marshall Erwin Rommel
"In a free society, diversity is not disorder. Debate is not strife. And dissent is not revolution." - George W. Bush

CanRay

  • *
  • Freelancer
  • Mr. Johnson
  • ***
  • Posts: 11141
  • Spouter of Random Words
« Reply #9 on: <06-06-11/2125:01> »
At the rate we're going, I'm going to need a retinal scan, palmprint scan, colonoscopy, and DNA test just to turn on my personal computer...
Si vis pacem, para bellum

#ThisTaserGoesTo11

FastJack

  • *
  • Administrator
  • Prime Runner
  • *****
  • Posts: 6374
  • Kids these days...
« Reply #10 on: <06-06-11/2238:59> »
There is no security anymore.
Even with the most perfectly secure password, there is cloud computing.
you can rent time on amazons server farm for what ever you want.
so if you are willing to plop down some money, the server farm will reduce the work time for cracking a given password from years to hours . .
Rent? Why would you rent something Apple is giving away for free?

Add to that the changes coming with Windows 8.

Welcome to the future, hackerz.

Stahlseele

  • *
  • Omae
  • ***
  • Posts: 760
  • Elfen haben doofe Ohren.
« Reply #11 on: <06-07-11/0847:35> »
There is no security anymore.
Even with the most perfectly secure password, there is cloud computing.
you can rent time on amazons server farm for what ever you want.
so if you are willing to plop down some money, the server farm will reduce the work time for cracking a given password from years to hours . .
Rent? Why would you rent something Apple is giving away for free?

Add to that the changes coming with Windows 8.

Welcome to the future, hackerz.
Because THAT iShit is NOT cloud COMPUTING . .
It's basically Cloud Storage with a bit of (anti)social webworking implemented . .
Cloud COMPUTING is something like SETI@Home for example, where the computing power of several hundred thousand computers(or in the case of the amazon, several dozend server farms), is used to do real computing of stuff.
"In the absence of orders, go find something and kill it." - Field Marshall Erwin Rommel
"In a free society, diversity is not disorder. Debate is not strife. And dissent is not revolution." - George W. Bush

CanRay

  • *
  • Freelancer
  • Mr. Johnson
  • ***
  • Posts: 11141
  • Spouter of Random Words
« Reply #12 on: <06-07-11/1107:41> »
You know, with the PSN hacked, there was a big chance for some major cloud computing using the PS3s like they do with those ghetto Supercomputers using multiple Consoles...
Si vis pacem, para bellum

#ThisTaserGoesTo11

Xzylvador

  • *
  • Prime Runner
  • *****
  • Posts: 3666
  • Ask me about NERPS! 30% Sales!
« Reply #13 on: <06-07-11/1517:12> »
Who cares if you could generate 10 trillion passwords per second? If the server you're trying to brute force only accepts one retry every 3 seconds, it'll still take years and years until you reach the right guess.

hobgoblin

  • *
  • Omae
  • ***
  • Posts: 523
  • Panda!
« Reply #14 on: <06-07-11/1639:53> »
Who cares if you could generate 10 trillion passwords per second? If the server you're trying to brute force only accepts one retry every 3 seconds, it'll still take years and years until you reach the right guess.
This was applied to a password harsh file. Funny thing is that if your dealing with a server, you may be able to trick it into reading out such files to you even tho it is not in the normal paths the server handles.

Then it a matter of applying rainbow tables and brute force techniques to find a matching hash. This then tells you the plain text password.
Want to see my flash new jacket?