Affichage des articles dont le libellé est password. Afficher tous les articles
Affichage des articles dont le libellé est password. Afficher tous les articles

Durvasav: Bruteforce Password Cracker

Durvasav bruteforce password cracker is a simple bruteforce password hash cracker program written in C language. It is a console program released under GNU GPL version 3 and runs on Windows. This tool is used to extract plain text from any standard hashes. It uses the OpenSSL library for generating hashes.



Durvasav allows us to compare thousands of hashes to a hash table at a time. It supports MD4, MD5, SHA0, SHA1, SHA224, SHA256, SHA384 and SHA512 standard hashing algorithms. You can also produce hash tables of all these hashes for different character sets or generate wordlists for reverse hash lookup.



Features:

Supports MD4, MD5, SHA0, SHA1, SHA224, SHA256, SHA384 and SHA512.
Uses fast OpenSSL library.
Includes wide variety of character sets and a custom character set.
Performs ‘pseudo’ operation.
Hash table generation.
Generates bruteforce password table.
Import and compare hash tables containing thousands of hashes.
Maximum password length of 12 characters (will increase it).
Wordlist generation for all characters.
Compatible with Windows 32bit and 64bit.

You can either choose from predefined character sets or a custom character set of your own.

[0…9] – Numeric from 0-9.
[a…z] – Small letters from a-z.
[A…Z] – Capital letters from A-Z.
[0…z] – 0-9 numeric and a-z alphabets.
[0…Z] – 0-9 numeric and A-Z alphabets.
[a…Z] – All small and capital letters.
[0..a..Z] – All numbers, small letters and capital letters.
[All] – All numbers, small letters, capital letters and all special characters.
[Custom] – Select this if you want use a custom character set.



~ mardi 27 septembre 2016 0 commentaires

Brutus: The Password Cracker

Brutus is one of the most powerful, fastest and most flexible remote passwords cracking tool available freely that you can get your hands on. Brutus password cracker bangs against network services of remote systems trying to guess passwords by using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NNTP, and more. It is only available for Windows 9x, NT and 2000 and other versions of Windows.



Brutus was written originally to help me check routers etc. for default and common passwords.

Features

Brutus version AET2 is the current release and includes the following authentication types:

HTTP (Basic Authentication)
HTTP (HTML Form/CGI)
POP3
FTP
SMB
Telnet

Other types such as IMAP, NNTP, NetBus etc are freely downloadable from this site and simply imported into your copy of Brutus. You can create your own types or use other peoples.



The current release includes the following functionality:

Multi-stage authentication engine
60 simultaneous target connections
No username, single username and multiple username modes
Password list, combo (user/password) list and configurable brute force modes
Highly customizable authentication sequences
Load and resume position
Import and Export custom authentication types as BAD files seamlessly
SOCKS proxy support for all authentication types
User and password list generation and manipulation functionality
HTML Form interpretation for HTML Form/CGI authentication types
Error handling and recovery capability inc. resume after crash/failure.



~ mercredi 24 août 2016 0 commentaires

10 Most Recommended Tools For Password Recovery

Whenever confidentiality and access levels are defined, password is used to give certain access to users. User protects their personal details with strong passwords. However, many password cracking tools have been created to crack the passwords.



There are many password cracking tools available for free and paid as well. Today we are going to discuss about some most recommended password cracking tools that security professionals uses.

Aircrack

It is used to recover wireless keys. It implements the best known cracking algorithms once enough encrypted packets are gathered. Aircrack is a suite of tools for 802.11 a/b/g WEP and WPA cracking. The suite comprises of many tools like airodump, aireplay, aircrack, airdecap for capturing wireless communications packets.


Cain and Abel

Cain and Abel is Windows-only password cracking tools that many cyber security professional uses to recover passwords. It sniffs the network, cracks encrypted password using dictionary. This tool is able to attack by brute force and cryptanalysis techniques and can also record VoIP communications, uncover cache passwords, revealing password boxes and analyzing routing protocols.


THC Hydra

Most cyber security professional choose THC hydra when they need to crack remote authentication service using brute force attack. It can perform rapid dictionary attack against more than 50 protocols, which includes http, ftp, https, smb and several databases.


Ophcrack

It’s a Windows password cracking tool, although it can be run on Linux, Windows and Mac also. It includes many features like LM and NTLM hash cracking, GUI, can load hashes from encrypted SAM recovered from Windows partition and a live CD version.


Medusa

Medusa is a tool that fast, modular, and massively parallel brute force logger. It supports many protocols like AFP, cvs, ftp, http, imap, SSH and other.


Fgdump 

Fgdump is the tool for extracting NTLM and LanMan password hashesfrom Windows. Fpdump attempts to disable antivirus software before initiating. It then runs pwdump, cachedump (cached credentials dump), and pstgdump (protected storage dump). It is also capable of displaying password histories if available.


L0phtCrack

L0phtCrack is a Windows based password cracking tool, which attempts cracking using hashes. Hashes can be obtained from stand-alone Windows workstation, network servers or active directories.  It also has various methods of generating passwords (dictionary, brute force, etc).


RainbowCrack

The RainbowCrack tool is a hash cracking tool that makes use of a large-scale time-memory trade-off. An ordinary brute force cracker tries all possible plaintexts one by one, which can be time consuming for complex passwords. While, RainbowCrack uses a time-memory trade-off to do all the pre cracking-time computation and store the results in tables called "rainbow tables". It does take a long time to pre compute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the pre-computation is finished.


Brutus

Brutus is a free and Windows-only password cracker that uses dictionary against network services of remote system to recover password. It supports http, pop3, ftp, smb, telnet, imap and other protocols.


Wfuzz

Wfuzz is a brute forcing tool for Web Applications, cyber security professionals uses this tool for finding resources like directories, servlets, scripts, bruteforcing GET and POST parameters for different kinds of injections (SQL, XSS, LDAP, etc.) and brute forcing form parameters (user/password), fuzzing and more.



Password cracking tools are not limited to these only there are many other tools as well. Many cyber security professional recommends these tools to recover passwords.


~ samedi 25 juin 2016 0 commentaires

The most commonly used passwords on the internet - Research

The social networking site LinkedIn was the talking point of Infosec community this week because of the data breach of its 117 Million users. The site was initially hacked four years ago, but the results of hack are showing now. The data of its users is up for sales on dark web according to various sources.



This isn't the first time a major internet giant have fallen victim of data breach, which affected its millions of users all over the world. Last year Ashley Madison an online dating website was hacked which have led to the resignation of its CEO and destroyed the marriages of many people.
However, the question is how hackers are able to breach these highly secured websites and gain passwords of millions of users. Yes, mainly it's because of the lack of cyber security steps taken by those organizations, but the users are equally responsible for becoming a victim of these hacking attacks. 

EHacking researchers have seen that most of the passwords that are hacked previously are commonly used around the globe and most people doesn't care if their password isn't secure. The passwords leaked from the latest LinkedIn hack are similar to the hacks of past years. 

We have gathered the list of most commonly used passwords on the internet right now. List also includes the passwords leaked after the LinkedIn hack.  

RankPasswordFrequency
1123456753,305
2linkedin172,523
3password144,458
412345678994,314
51234567863,769
611111157,210
7123456749,652
8sunshine39,118
9qwerty37,538
1065432133,854
1100000032,490
12password130,981
13abc12330,398
14charlie28,049
15linked25,334
16maggie23,892
17michael23,075
1866666622,888
19princess22,122
2012312321,826
21iloveyou20,251
22123456789019,575
23Linkedin119,441
24daniel19,184
25bailey18,805
26welcome18,504
27buster18,395
28Passw0rd18,208
29baseball17,858
30shadow17,781
3112121217,134
32hannah17,040
33monkey16,958
34thomas16,789
35summer16,652
36george16,620
37harley16,275
3822222216,165
39jessica16,088
40ginger16,040
41michelle16,024
42abcdef15,938
43sophie15,884
44jordan15,839
45freedom15,793
4655555515,664
47tigger15,658
48joshua15,628
49pepper15,610

How to create a strong password

Creating a strong password needs the combination of alphabets, numbers, signs. Here are some examples: 

3Hghfwg-09;l or gTHncdsY93]ND 


~ jeudi 19 mai 2016 0 commentaires

Top 5 Password Cracking Tools

Password cracking tools are often refereed to as password recovery tools used to guess or restore a password from a data transmission system. Security researchers and penetration testers also use these tools to check the security of an application.

It is an undeniable fact that in cyber security passwords are the most vulnerable security links. But if the password is too complicated the user might not remember it. These tools are useful when user forgets their passwords but hackers also use them to crack passwords of systems and stole data.


There are many type of password cracking tools. Some uses dictionaries of their own to crack a password, those tools have a combination of words but it will take hours or even days if the users password is complicated one. Plus the success rate of these tools are also not very high.

 Programmers in past few years has introduced different password cracking tools in the market, some of them are highly successful in terms of results. Here we shortlisted the top 5 most successful password cracking tools available in the market.

1. Medusa

Medusa is a highly rated password cracking tool which runs on Linux OS. It is highly rated among network administrators who keep checking their firms passwords time by time to ensure they cannot be cracked easily. This tools can provide you a result about how strong your organizations passwords are. It supports  NNTP, FTP, CVS, HTTP, IMAP,  MYSQL, NCP,AFP,  POP3, MS SQL, PostgreSQL, pcAnywhere, rlogin, SMB, rsh, SMTP, SNMP, SSH, SVN, VNC, VmAuthd and Telnet. While cracking the password, host, username and password can be flexible input while performing the attack.

2. Wfuzz

Wfuzz cracks passwords with brute forcing another famous password cracking tool. Wfuzz can be used to find unlinked resources like servelts,scripts and directories.Wfuzz is based on dictionaries and ranges, user just had to choose where he want to bruteforce just by changing the part of URL or the post by keyword Fuzz. Some top features of Wfuzz are; Recursion, Multiple Injection points capability with multiple dictionaries, Output to HTML and many more.

3. Brutus

Brutus is a popular password cracking tool which can be used remotely. Brutus is available in the market since 2000, but it only works in Windows OS. It supports HTTP (Basic Authentication), HTTP (HTML Form/CGI), POP3, FTP, SMB, Telnet and other types such as IMAP, NNTP, NetBus, etc. The latest version of Brutus contains features like; HTTP (Basic Authentication), HTTP (HTML Form/CGI), POP3, FTP, Telnet, SMB. Another feature in this tool is that user can create their own authentication types. The tool is old but still it is providing desired results. 

4. John the Ripper

John the Ripper is another widely used open source password cracking tool, works on Linux, Windows, Unix, and Mac OS X. Its basic purpose is to detect weak passwords in Unix. A pro version of this tool is also available in the market right now with additional features, and its pretty cheap.

5. Cain and Abel

This tool operates on Microsoft OS only but the sucess rate is very high. The tool operates as a sniffer in the network, it cracks the encrypted passwords through the dictionary attacks, recording VoIP conversations, brute force attacks, cryptanalysis attacks,  revealing password boxes, uncovering cached passwords, decoding scrambled passwords, and analyzing routing protocols.

~ vendredi 4 septembre 2015 0 commentaires

System Passwords Revealed by London Rail Station during BBC Documentary

During a BBC documentary on Wednesday night, system passwords at one of London's busiest railway stations had been disclosed and were exposed to viewers.

The credentials were attached to the top of a controller’s monitor used at the rail station, the passwords were revealed at about 43 minutes into the programme.



The passwords were stuck to a monitor and were visible during a scene where the two business experts went into the control room at the rail station Waterloo in London. The screenshot seems to be of the workstation on a signaller's control desk‬ which appears to be running software that controls signals and trains over‪ the final approach to Waterloo station‬.


They were taken by the dynamic duo's travels to the Wessex Integrated Control Centre, located above the platform entrances at London Waterloo railway station, manned 24 hours a day by teams of controllers from both South West Trains and Network Rail.

However by knowing a password does not indicate that it can necessarily be exploited by anyone remotely. There is a possibility that the password is for the purpose of logging into the physical desktop computer. Nonetheless, you have reduced the point of a password if you have stuck it on the very device which needs the password.

Last week BBC News ran a story discussing fears that computer systems controlling the signal system in the UK could be vulnerable to hacking attacks.

However, it has not happened for the first time that an organization has made a blunder of letting a TV company into its offices, only to discover passwords have been exposed in the background.
French TV station TV5MONDE also made a mistake at the time they were discussing how its systems were recently hacked while revealing yet more passwords at the same time.


~ vendredi 1 mai 2015 0 commentaires

PACK - Password Analysis & Cracking Toolkit

PACK (Password Analysis and Cracking Toolkit) is a collection of utilities developed to aid in analysis of password lists in order to enhance password cracking through pattern detection of masks, rules, character-sets and other password characteristics. The toolkit generates valid input files for Hashcat family of password crackers.





Before we can begin using the toolkit we must establish a selection criteria of password lists. Since we are looking to analyze the way people create their passwords, we must obtain as large of a sample of leaked passwords as possible. One such excellent list is based on RockYou.com compromise. This list both provides large and diverse enough collection that provides a good results for common passwords used by similar sites (e.g. social networking). The analysis obtained from this list may not work for organizations with specific password policies. As such, selecting sample input should be as close to your target as possible. In addition, try to avoid obtaining lists based on already cracked passwords as it will generate statistics bias of rules and masks used by individual(s) cracking the list and not actual users.


The most basic analysis that you can perform is simply obtaining most common length, character-set and other characteristics of passwords in the provided list. In the example below, we will use 'rockyou.txt' containing approximately 14 million passwords. Launch statsgen.py with the following command line:

$ python statsgen.py rockyou.txt

                           _
StatsGen #.#.# | |
_ __ __ _ ___| | _
| '_ \ / _` |/ __| |/ /
| |_) | (_| | (__| <
| .__/ \__,_|\___|_|\_\
| |
|_| iphelix@thesprawl.org

[*] Analyzing passwords in [rockyou.txt]
[+] Analyzing 100% (14344390/14344390) of passwords
NOTE: Statistics below is relative to the number of analyzed passwords, not total number of passwords

[*] Length:
[+] 8: 20% (2966037)
[+] 7: 17% (2506271)
[+] 9: 15% (2191039)
[+] 10: 14% (2013695)
[+] 6: 13% (1947798)
...

[*] Character-set:
[+] loweralphanum: 42% (6074867)
[+] loweralpha: 25% (3726129)
[+] numeric: 16% (2346744)
[+] loweralphaspecialnum: 02% (426353)
[+] upperalphanum: 02% (407431)
...

[*] Password complexity:
[+] digit: min(0) max(255)
[+] lower: min(0) max(255)
[+] upper: min(0) max(187)
[+] special: min(0) max(255)

[*] Simple Masks:
[+] stringdigit: 37% (5339556)
[+] string: 28% (4115314)
[+] digit: 16% (2346744)
[+] digitstring: 04% (663951)
[+] othermask: 04% (576324)
...

[*] Advanced Masks:
[+] ?l?l?l?l?l?l?l?l: 04% (687991)
[+] ?l?l?l?l?l?l: 04% (601152)
[+] ?l?l?l?l?l?l?l: 04% (585013)
[+] ?l?l?l?l?l?l?l?l?l: 03% (516830)
[+] ?d?d?d?d?d?d?d: 03% (487429)

~ mercredi 26 mars 2014 0 commentaires

How To Create A Password That Won't Be Hacked


Every Internet user asked himself a question “What a password to use” at least once in his life. Social networks,e-mail, forums, and various website accountsrequire passwords from users. In order not to get caught up in dozens of passwords,we usually invent the most simple, easy ones, and write them everywhere, or almost everywhere. Simple combinations are the most common password variants for the majority of users. That is why even the most inexperiencedhacker can easily get access toyour mailbox, ICQ, or even youe-wallet. What you need to know the password could not steal your password? We answer this simple question.


So, what a really strong password should look like?
  • The length of your password must be of 10 characters at least
  • Your password should not be a word
  • Your password should contain letters, numbers, uppercase letters, and various additional characters
  • Your password should not be your cat's name, your date of birth, and it shouldn't overlap with information related to you or your family

If you store areally important information, which should not get into the hands of criminals in any way, then we recommend you to changepasswordsat least once a month. This is an additional security measure recommendedby Microsoft,which issuccessfully adopted by allmajor structures, including banks.

We offer you several ways to generate a strong password.

Perfect Passwords




This is a very simple and effective way to generate strong passwords. You do not have to install any software, register anywhere, and so on. Every time you visit a page,it generates random secure passwords visible only to you. Here you can create a password of 64 characters with a hexadecimal system, 63-character passwords with ASCII characters and consistedonly of numbers and English letters. If necessary, you use only a parof generated sequence. Anyone interested in the theoretical part of creating strong passwords can find a lot of information on the page, including the operating principles of thisservice.

PC Tools Secure Password Generator




This is a comfortable and easy to use web service. You determine the length of apassword, the parameters of certain characters inclusion and exclusion, and the number ofpasswords generated by the given parameters.

And finally, let us remind you what your password should NEVER look like:

  1. Never use simple letters and numbers combinations. In other words, forget about such passwords as 123, 0987, 1234567890, iiii, zzz, qwert etc. According to hackers, they can crack such a password in one minute.
  2. Never use personal information in passwords! Your name, surname, telephone number, date of birth, name of your wife, a pet nickname, etc. should not be specified here.
  3. Never use short passwords. No matter how complex a few characters of your password are, it will not be difficult to hack it if it is short.
  4. Never use monosyllabic words. Everything you can find in any English dictionary should not be your password. For example: love, mercedes, friendship, samsung, super_girls, dog, cat etc. won't obviously fit. No words, bearing some meaning at least.
  5. Do not use the same password everywhere. It is better to use two or three different ones.
  6. Do not keep your password in a folder of your computer. The best option would be if you remember it or write itdown on a piece of paper.
  7. Do not use curse words in the password - they are easy to find for a hacker.


Never let your computer be hacked just because of your weak passwords! 

About the Author
 
Posted on by Alex Strike, a copywriter at http://writing-help.com, interested in innovative technologies and concept gadgets. 



Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mercredi 17 avril 2013 0 commentaires

Mini Password Buffer Overflow Tut

Password Form Buffer Overflows

  • In this Lesson we will be learning how to do a Login/Password Form Buffer Overflow. This is a very basic version of a Buffer Overflow but just as effective. Basically what is happening here is that Password Forms usually have a limit on the number of Characters they are aloud input, but we will bypass this limit overloading the login and getting access to the Server!

  • To do this we will need a tool call WebDeveloper for Firefox, which you can download here

  • This is a very simple Hack so it only works on some Basic Authentication Logins, but its good know for the future if you find any!   So on firefox Go Tools>Web Developer>Forms>Remove Maximum Lengths Now type in a massively long code eg "aaaaaaaaaaaaaaaaaaaaaaaaa" and so on, and it should come up with an error page either showing the encrypted passwords, or clear text passwords on the server! 



Congratulations now you know a simple Form Buffer Overflow!

This tutorial is Written 100% by Lethalcode

~ lundi 22 août 2011 0 commentaires