Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

So fast - so weekly: everything is so hybrid today

txttxt

Hybrid Rainbow Tables




Bild 1.jpg


First of all I never saw a reason to pay for rainbow tables. There're projects, which will remain nameless (ophcrack *cough* ophcrack, sorry...) selling this stuff. But these are far less advanced than our free alternative here.

The first thing you have to get:
hash_{kinds of symbols}_{PW_lengths}_ID_chainlenth_chaincount_filename

That's it: Here they are: NTLM, MD5, LM. Latter is getting less important every day. So my personal mirror will just contain NTLM and MD5. I'm missing SHA1.
Maybe I can extend my NTLM collection from somewhere else, too. But if someone finds good SHA1 tables... let me know.

There's something smart I found. Obviously, if you enforce a password policy, people tend to search for the easiest and most obvious password (for them) to remember. If you enforce a numeric space, people will most often use the "1", not all numbers.
Therefore, to exploit this weakness, there're optimized rainbow tables now. These are called Hybrid Rainbow Tables. I also guess you need rcracki for these. Not Abel or some lesser sophisticated GUI crackers. I'll try it out. In any case you can convert the tables into a general Cain/Ophcrack/rcrack compatible format. That'll slow the process down a little, but I guess with a CUDA-enabled bt4-beta... a fast success is very likely. Makes sense from a crypto-logic standpoint to optimize even rainbow tables to exploit the human side of security. This happened with password-lists for online cracking purposes, now it happened with rainbow-tables for offline cracking.

You can contribute to the freerainbowtables project. I'll do that. Helps to get a deeper understanding... and my server isn't doing a lot with its CPU, normally. Even if there's some kind of DDoS. (Here a note to these kids: 4 seconds. Is that all?)


Have fun,
wishi

update: found SHA1 tables, too. Mirrored them. rti2rto needs Windows or a 64 Bit System.

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.