Check how fast it takes to brute force your password
hackosis.com
hackosis.com
I think that there is a typical password length, so you could improve the sorting based upon a multi-dimensional rating scheme. I'd use expected password length and commonness of a word as factors. Mixing these real words with computer generated words might speed up brute force attacks.
However, I'm not sure how to integrate ordered wordfiles with rainbow tables. Any ideas?
that's great that you've made that list though.. i wanted word frequency tables for my startup which is an entirely unrelated type of project. if i hadn't found this i would have compiled it myself; thanks much :)
while your list doesn't have frequencies, i guess i can use the position in the list as a proxy for frequencies. but it's not optimal. any chance you can put up a list which also has the counts?
After 3 attempts most high security sites block you out and others introduce a captcha (which though crackable through crackable will introduce a delay). Any site is going to take note (or go down) of 25 billion hits/hr that too on a single account (does total traffic/hour on a site like google.com sum to this? )
The time taken is only to generate the permutations, not to crack a password.
The numbers give make no sense, because doesn't state which hash is using, and the difference may be huge:
~/john-1.7.2/run$ ./john --test Benchmarking: Traditional DES [128/128 BS SSE2]... DONE Many salts: 906828 c/s real, 908646 c/s virtual Only one salt: 805504 c/s real, 805504 c/s virtual
Benchmarking: BSDI DES (x725) [128/128 BS SSE2]... DONE Many salts: 31271 c/s real, 31334 c/s virtual Only one salt: 30617 c/s real, 30617 c/s virtual
Benchmarking: FreeBSD MD5 [32/32]... DONE Raw: 8617 c/s real, 8652 c/s virtual
Benchmarking: OpenBSD Blowfish (x32) [32/32]... DONE Raw: 415 c/s real, 416 c/s virtual
Benchmarking: Kerberos AFS DES [48/64 4K MMX]... DONE Short: 186368 c/s real, 186741 c/s virtual Long: 528588 c/s real, 531779 c/s virtual
Benchmarking: NT LM DES [128/128 BS SSE2]... DONE Raw: 6575K c/s real, 6588K c/s virtual
Which I find unbelieveable is that lots of web applications use simple MD5-passwords(not the FreeBSD MD5 based version but just MD5 hashes) without even using salts, which makes them almost instantly crackable using Rainbow tables.
It's almost comparable in my mind to saying, if you get physical access to the machine you can do exploits X, Y, and Z. Well, yeah, if you can get that far, you've pretty much won.
I observed that if you mention your password has random Alpha Numeric the time taken to break jumps to thousands of days.