Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: ShadowAce

I prefer John the Ripper. Used to use crack, but I gave it up. ;)

It's a classic dictionary brute force.

You encrypt the dictionary one word at a time, and compare the hashes. The chance of collision is so small that when you match hashes, you can be sure you've found your password.

Rainbow supports a precomputed has database, which can speed this up immensely... no need to re-encrypt on the fly, you just compare to the DB.

Windows hashes of short passwords (6 chars or less) are especially vulnerable, because the LM Hash is stored in 2 pieces of 8 bytes each (pretty sure it's 8, not worth looking up for the point of this convo). If you use a short password, someone only has to crack half as many bytes. (A 7 byte password is strong, because there are 2 bytes of padding added, making the total stored length 9 bytes.)

Oops!


428 posted on 08/30/2005 8:21:29 AM PDT by adam_az (It's the border, stupid!)
[ Post Reply | Private Reply | To 419 | View Replies ]


To: adam_az
The chance of collision is so small that when you match hashes, you can be sure you've found your password

Actually a collision is also a match. It doesn't matter what the password is just that the hash needs to match. So if you hit a collision you in essence have a working password.

434 posted on 08/30/2005 8:28:09 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 428 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson