Kaspersky researcher cracks Flame malware password
networkworld.com
networkworld.com
Full Analysis of Flame's Command & Control servers by Kaspersky Lab Expert http://www.securelist.com/en/blog/750/Full_Analysis_of_Flame...
What? How did they crack this if brute force failed? That's scary as hell.
More likely they used a table of known existing passwords and variations on the them?
so it's a combination of luck, computing power (they probably have a farm of gpus), and careful selection of templates (probably guided by analysis of known passwords).
What better way for kaspersky to promote themselves?
How is it possible to crack 900gage!@# in a few hours?
No idea what the current state of cracking is, but probably they used some rules based approach (like John the Ripper used to have) to massively reduce the search space.
It's still actively maintained.
If you look at public password compromises, the components of this password "900", "gage", and "!@#" each appear pretty frequently. So using a data-driven approach to build context free grammars based on real-world passwords you've found or already cracked will get passwords like this every time.
Basically, everyone thinks they're clever when they choose a password, but for the most part people are all being "clever" in the same way. If you think up your password, chances are you've lost.
A single ATI 5970 can compute 2300M SHA-1 hashes per second. So you're looking at about two and a half hours to run through the entire keyspace. Fewer on a farm (which Amazon will rent to you for a few bucks). That's assuming you know the dictionary, of course.
Of course, if the password is hashed with bcrypt or scrypt it will take much longer, although I'm not sure how to do that calculation.
That's a little faster than howsecureismypassword.net's estimate (154 octillion years on a desktop PC to crack "correct horse battery staple" (without quotes)).
Each of those sets will bring you up in entropy, from two quadrillion up to nine quintillion permutations. That would take the ATI 5970 about 4306184595 seconds, or 136.4 years. If you spread that out over 100 cards that would only take you 1.3 years to crack.
Maybe that's too close to call, so you can always change your password every 60 days to mitigate people with more money/time on their hands. If anyone ever wants my password that bad they should just give me the money they'd spend on cracking and i'll give them my password ;)
$ cat final/english-words.* | perl -le'@wl=map{ s/\s//g; tr/A-Z/a-z/; (/^[a-z0-9]+$/ and length$_ > 3 and length$_ < 7) ? $_ : () } <>; push @a, $wl[int rand(@wl)] for 1..4; print "@a"'
rymmes weekly calvin cimbalWhat I recommend is that people use diceware (http://www.diceware.com) to create a six-word passphrase, which they use to secure a password manager. Then use the password manager to generate random 12-character (alpha+numeric+symbol) passwords for each login.
(50^10 + smaller terms) * 256 bits (SHA256 size) Number of hashes * size of hash to store.
Obviously this isn't how it's actually done. The best page I found describing the process is: http://www.freerainbowtables.com/en/faq/
The forum is fascinating: http://www.freerainbowtables.com/phpBB3/uncracked-hashes-f23...
Even assuming you could store each possibility in a single byte, which you can't, that would still take about 86PB to store. Considering you would need to store both the key and the hash in order to have a useful table, it seems you would actually need to have a few exabytes dedicated to this.
There is a diminishing-returns limit to how small your rainbow table can be before it starts getting both false positives and false negatives, and bigger password domain makes it worse, but they require less than 1 bit per covered password.
Cracking a hashed algorithm computed in SHA-512 or even BCrypt is a different story from MD5.
http://www.google.com/search?q=900gage!%40%23&hl=en&...
{restricted date to before a few days ago}
Google search result says that that appeared on 21 Nov 2010.
See it here from google's cache: http://goo.gl/Yctw3
[1] http://www.nytimes.com/2012/06/01/world/middleeast/obama-ord...
Who the heck lives at 900 Gage Road, though?
_____________
[1] There's no doubt that the US has developed cyberweapons, cyberweapons have been used under Obama, or that flame is one of such a class of weapons. The attribution of flame is sort of a moot point re: "It was reported in the nytimes that this is indeed a cyberweapons". Viz:
"Mr. Obama decided that the cyberattacks should proceed..." "The United States government...acknowledged developing cyberweapons"...and now "another cyberweapon called Flame that was recently discovered to have attacked" etc. per NYT.