Showing posts with label Password Cracking. Show all posts
Showing posts with label Password Cracking. Show all posts

Wednesday, 22 May 2013

Password Cracking


In this post I am going to tell you how passwords are cracked using softwares.
Password cracking softwares use the hit-and-trial method. These softwares use every key combination available and try out that password. Although this takes a very long time this is very effective. This is why it is recommended to use both upper and lower case in your password as these passwords can be rarely cracked using these softwares.

It is also recommended not to use personal details like name, mobile numbers, birth dates etc. as passwords as these can be easily cracked and sometimes without using password cracking softwares.



Thursday, 16 May 2013

How to create an excellent password

 



Now a days ids with simple passwords can be hacked very easily. So to keep your ids secure you should have a very good password that cannot be cracked easily.
These are a few steps to create an excellent password:

1.Try to use both letters and numbers.                                                                                                    These type of passwords can be cracked but not easily. For example kooltrix007
2.Use both upper and lower case                                                                                                     These passwords are the most difficult to crack as they have both upper and lower case. For example    
KoOLTriX007
3.Don't use your name or mobile number as password                                                                       This is a very common thing among people. They keep their name or number as their passwords. These ids 
  can easily be cracked especially by close people. Instead you can use dates as your passwords, such as  
  your birth date or any other important date.
P.S: Don't create such a password that even you forget it!! :P

Sunday, 28 April 2013

Password Cracking:John The Ripper

John the Ripper is a free password cracking software tool. Initially developed for the UNIX operating system, it currently runs on fifteen different platforms (eleven architecture-specific flavors of Unix, DOS, Win32, BeOS, and OpenVMS). It is one of the most popular password testing and breaking programs as it combines a number of password crackers into one package, autodetects password hash types, and includes a customizable cracker. It can be run against various encrypted password formats including several crypt password hash types most commonly found on various Unix flavors (based on DES, MD5, or Blowfish), Kerberos AFS, and Windows NT/2000/XP/2003 LM hash. Additional modules have extended its ability to include MD4-based password hashes and passwords stored in LDAP, MySQL, and others.

TYPES OF ATTACKS

  • One of the modes John can use is the dictionary attack. It takes text string samples (usually from a file, called a wordlist, containing words found in a dictionary), encrypting it in the same format as the password being examined (including both the encryption algorithm and key), and comparing the output to the encrypted string. It can also perform a variety of alterations to the dictionary words and try these. Many of these alterations are also used in John's single attack mode, which modifies an associated plaintext (such as a username with an encrypted password) and checks the variations against the encrypted hashes.
  • John also offers a brute force mode. In this type of attack, the program goes through all the possible plaintexts, hashing each one and then comparing it to the input hash. John uses character frequency tables to try plaintexts containing more frequently used characters first. This method is useful for cracking passwords which do not appear in dictionary wordlists, but it does take a long time to run.