L0phtCrack Is Now Open Source
l0phtcrack.gitlab.io
l0phtcrack.gitlab.io
Looks like they sold and committed to a bunch of cracking rigs before sourcing enough GPUs right before prices skyrocketed, and were suddenly on the hook for a lot more than they could realistically pay for. Hopefully Jeremi manages to pull through. It's a fantastic company that makes a fantastic product. I'd love to buy some new rigs when they get their supply chain issues figured out.
_ _
((___))
[ x x ] __________________________
\ / _ _/ Thanx DilDog!! \
(' ') \__________________________/
(U) ... DilDog is this you?I'm sUre I'm not alone in having fond memories seeing this. :)
PS: (2 decades since Boston madness!)
- https://www.schneier.com/blog/archives/2007/08/new_german_ha...
- https://www.gesetze-im-internet.de/stgb/__202c.html
However, it seems it is not about owning the tools, but rather about creating them.
I.e. you make one opsec mistake now, nobody's perfect - and then many years later when someone will finally care, this will be used to identify you, there's loads of examples like that of investigations/convictions where the people did know how to use "Tor, socks proxies, VPNs, SSH tunnels" and used them properly almost always.
Mudge was a musical prodigy and an alum of BBN, one of the key players in creating ARPAnet. His bio is fascinating, and you can find a good treatment of it here: https://www.cybersecurityeducationguides.org/peiter-zatko/
[1] The Crumbling Tunnel:
http://phrack.org/issues/53/12.html
[2] Smashing The Stack For Fun And Profit:
Given the number of people, including myself, who consider reading that article a truly formative experiences, you might argue it's one of the most famous/influential articles in programming.
- Wikipedia
Every project should have a concise (one or two sentence) description in the GitHub README and the website's homepage. Even the most well-known tools.
But L0phtCrack is a very well known tool. If you've never heard of it and have been following security stuff for decades, that's really on you.
At some point, a tool is so ubiquitous that it's just odd to not have encountered it. You don't see many accountants that haven't heard of Excel, webdevs that haven't heard of Apache, construction workers that haven't heard of a hammer, or cybersec workers who haven't heard of L0phtCrack.
L0phtCrack has been decreasingly relevant in the past 10 years or so -- it wasn't available for awhile and some free tools are similar so you were basically buying the rainbow tables -- but if you were in security in the Windows 2000 or Windows XP era, you know of this tool. There was a lot of discussion for years around and about password crackers after rainbow tables became a thing.
It's not like not knowing what Wireshark or nmap is, but it is like saying that you've never even heard of Kismet or John the Ripper. Or like being a DBA for decades that never heard of Informix. Or a programmer for "decades" that has never even heard of Delphi. Like what were you doing in the early 2000s to have completely missed the death of Borland and Pascal and the popular variants? These are big enough events in the industry that if you're in it you're going to be aware of it.
But it's like the Elvis Presley of password crackers.
I'm a millionaire now though so shrug
Also my stock positions predate wsb by like 7 years.
Why did we all get caught? Smart enough to figure that out in your teens, dumb enough to think you can get away with it...
In my case I was operating with a dumbass friend who left a "calling card" on one of the compromised machines.
It's as much social engineering as anything else.
But as a result of my demonstrative flexing cyber-security activity — I was granted with 'root' credentials on the school's SUSE Linux server… Which apparently at the same time was used as an ISP router for an entire city block.
This granted responsibility, unsurprisingly, turned out to be an extremely effective step to cool my eagerness to hack into all things.
Good times were had by non-sysadmins around the world
FYI though, it was a password brute force tool that many of us used for various (mostly innocent) myschevios purposes 15-20 years ago.
I guess their main claim to fame was being the first “hacker” group to do PR moderately well and transition into decent careers. Not really even an interesting footnote in history.
The number of candles on my birthday cake seems to change the fastest. I ask for hexadecimal whenever possible.
This just feels like you have an axe to grind.
the history of mudge and l0pht are more interesting than they are useful. if you want to get 202X security chops though, digging up the past isnt really the way. its more of a thing to do a deep dive into because youre interested, not because you expect anything out of it.
there are other researchers like gruqg who chronicle the exploits of old teams like l0pht and ACIDBITCHEZ under the guise of teaching the new wave about LOL hacking (living off the land), but i personally think they are doing it more for the reasons one writes a history book; cause its interesting.
if you want to learn LOL, read mandiant APT markers. thats how modern hacking is done, its really not at all like it used to be. i myself am happy to offer the following ocunterpoint though; the number one ranked hackerone bugbounty is dawgyg, an ex blackhat whose come in and dominated the bb scene in a huge way. i counter my counter point with the thousands of guys who make a solid living doing bug bounty who do not posess the old skills. they arent a requirement to make it in modern sec, because things are just different.
they were a bunch of badass cowboys who became the first to "make it". big boy jobs, wide spread respect in the community, inspiring a generation like egypt etc who went on to do metasploit work.
i am keen as a BEAN for grugqs book to come out, because to me, its fascinating, interesting and inspiring. mudge has been my personal hero since i found out about him when i was in highschool, but that was long after their reign was done and they were corporate.
i think the following anology works well too; lopht are comparable to van halen; when they both burst onto their scenes, almost noone else was doing what they did, and noone else before had gotten as big.
but time marches on, and other people do something new, and suddenly evh isnt as flashy as the new crop.
I also start every semester off with the opening scene of Hackers - the best hacking movie ever made :)
I'm a decade older, and am relieved to see this.
> Hackers - the best hacking movie ever made :)
Counterpoint: _Sneakers_: the thinking person's hacking movie.
Lacks the soundtrack. I always work to music to help focus.
Great soundtrack. Respect.
Nevertheless, nice of them to open source it.
> at this point it is more a museum relic than anything practical