<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; ophcrack</title> <atom:link href="http://www.ghacks.net/tag/ophcrack/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Theoretical Cryptography Part I &#8211; MD5</title><link>http://www.ghacks.net/2008/02/07/theoretical-cryptography-part-i-md5/</link> <comments>http://www.ghacks.net/2008/02/07/theoretical-cryptography-part-i-md5/#comments</comments> <pubDate>Thu, 07 Feb 2008 19:30:39 +0000</pubDate> <dc:creator>Stefan</dc:creator> <category><![CDATA[Knowledge]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[aes]]></category> <category><![CDATA[DES]]></category> <category><![CDATA[hash]]></category> <category><![CDATA[md5]]></category> <category><![CDATA[ophcrack]]></category> <category><![CDATA[sha]]></category> <category><![CDATA[Theoretical Cryptography]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2008/02/07/theoretical-cryptography-part-i-md5/</guid> <description><![CDATA[Since Martin constantly manages to cover all ongoing news regarding cryptography and security I myself planned on writing about "any time soon", I had to look for other topics on the subject I could cover. So I decided to make good use of all the time I spend studying this kind of stuff and share this knowledge with you. And I would be very grateful, if someone could tell me in return how to defeat shirred fabrics with my sewing machine... but that's a whole different matter.]]></description> <content:encoded><![CDATA[<p>Since Martin constantly manages to cover all ongoing news regarding cryptography and security I myself planned on writing about &#8220;any time soon&#8221;, I had to look for other topics on the subject I could cover. So I decided to make good use of all the time I spend studying this kind of stuff and share this knowledge with you. And I would be very grateful, if someone could tell me in return how to defeat shirred fabrics with my sewing machine&#8230; but that&#8217;s a whole different matter.</p><p>So for the first Part of this &#8211; hopefully ongoing &#8211; series, I decided to look at the MD5 hash algorithm. It&#8217;s one of the most commonly used cryptographic algorithms out there and I would claim that nearly everyone has a password somewhere that is stored with an MD5 or similar hash.</p><p><span
id="more-3142"></span>MD5 stands for Message-Digest Algorithm 5, and is &#8211; as already mentioned and you probably already knew &#8211; a hash algorithm.</p><p>The MD5 hash algorithm is in simple terms a deterministic function (or blackbox) that will calculate a 128-Bit hash value from a given string of well-nigh any length &#8230; yeah, I had to read this sentence over a few times, and it&#8217;s just rubbish. If I wanted to write something like that, I could&#8217;ve gone Wikipedia. So let&#8217;s crack this one open.</p><p>You feed the MD5-Box a string of any length you want. This &#8220;string&#8221; doesn&#8217;t have to be alphanumeric of course, any stream of bits and bytes is just fine, like the bitstream of a file, for instance. The output string has always a length of 128 bits and is usually noted as a string of 32 octets, like this one: &#8220;B5A8AD3A9CDD6A6953FCBE6975FDE734&#8243; (try guessing what I typed in though).</p><p>One of the most important things about hashes is, that they are so-called one-way-functions, meaning, they only encrypt stuff, and can&#8217;t &#8211; and must not &#8211; be decrypted. So hashes are often used for storing passwords in a databases. The same plaintext will always be hashed to the same cipher text with MD5, so all you have to do to check if your password and the stored (hashed) password are identical is to compute the hash of the given password and compare it with the stored one.</p><p>There are several demands a good hash-function has to meet in order not to get cracked in the first two hours of its lifetime.<br
/> The first one is, that a minor change in the plaintext (like &#8220;ghacks&#8221; and &#8220;gHacks&#8221;) should have a big impact on the computed hash (&#8220;D1B81FBDEB51C3A850E37177A5A22498&#8243; and &#8220;DB3E20DC88EF0B6CA6A8FD5DA448D323&#8243;). If the difference would be only minor, and I know the plaintext and hash of &#8220;ghacks&#8221; (which I do, of course), and have the hash of &#8220;gHacks&#8221; without the knowledge of its plaintext, I could easily guess it.</p><p>The second very important demand is that a hash-function produces a much smaller memory imprint than the original stream. If you hash an 11MB installer to verify its integrity and have to download another 10MB of hash file as well, it&#8217;s pretty useless. There are lots of other points to keep an eye on, but these will (and have to) suffice.</p><p>As I mentioned already, hash-functions such as MD5 are most commonly used to store passwords without actually storing them in plaintext, and to verify the integrity of files. When you put a file online, just compute the hash and publish it together (but separate) with the file. Ever user would be able to determine if the downloaded file has been tampered with by simply comparing the hash of the downloaded file with the one published on the website.</p><p>Now I&#8217;d like to say something about security and known (and partly successful) attacks against hashes and MD5 in particular.<br
/> Due to the reduction (a 2MB file gets reduced to a 32-octet hash), information gets lost. This gets perfectly clear, if you take a look at the numbers. There are only 2^128 possible hash values, but infinite possible plaintexts. So in a best-case-scenario, after hashing plaintext numbers (2^128)+1 you have at least two plaintexts getting mapped on one and the same hash value.</p><p>So the first attack tries to make use of this very fact. When the same hash value is calculated from two different plaintexts, it is called a collision. Depending on the scenario of the attack using collisions, the birthday paradox comes in handy as well, increasing the attackers chance of success.</p><p>That would mean that you do not attempt to break the encryption or guess the user&#8217;s password when trying to crack a password, but just try to create another password that leads to the very same hash value, granting you access to the account. Of course, knowledge of the hashed password is required, but without that information, most attacks on modern ciphers are more than just tricky.</p><p>Edit: please take a look at comments for more clarification on the types of attacks mentioned above.</p><p>The second attack is based on a brute-force attack, which is basically &#8220;try all possible keys/passwords&#8221;. Depending on the numbers this could take some time. Let&#8217;s say you&#8217;ve already acquired the target hash value and your machine is able to try 100 keys per ms. That would make 100.000 keys per second, and 6.000.000 keys per minute. 2^128 hash values. That&#8217;s 3.4E38. We&#8217;re talking &#8220;age of the universe in seconds&#8221;-numbers here.</p><p>But there&#8217;s more to it than meets the eye. There are several options to reduce the available possibilities. Can you reduce the amount of possible plaintexts maybe? Maybe the password only allows to be 8 alphanumeric letters long? Can you have a look at the used algorithm and find something that may help you further? Do you know part of the plaintext? Maybe a name of son/wife/pet? Then you could combine it with a dictionary-attack. Every bit of information helps reducing the number of possibilities further, which in the end leads to a situation like this:</p><p>The following is a description of an attack to crack the user passwords of windows accounts (up to XP), and implemented in a near-perfect way by <a
href="http://ophcrack.sourceforge.net/">ophcrack</a>. If interested, do make sure to check this <a
href="http://elliottback.com/wp/cracking-windows-passwords-with-ophcrack-and-rainbow-tables/">tutorial</a>, it&#8217;s quite fascinating and yet unbelievably scary.</p><p>Windows saves hash values of the user passwords, but if a password is longer than 7 signs, it gets broken up into chunks of length &lt;= 7. Then the chunks get converted to uppercase only. Microsoft used DES for creating the hashes, but there&#8217;s no difference regarding this kind of attack.</p><p>So the attacker knows pretty much about the plaintext and can reduce its possibilities by a great deal. Now a computer starts calculating all possible hash values for this particular range of plaintexts (up to 7 digits, uppercase, numbers and some special characters only) and stores them in a database. Once finished, the database is from about 0.7 to 4 GB in size and can be easily transported using a thumb drive or a DVD.</p><p>Now all the attacker needs is a few minutes alone with the target computer and it&#8217;s done. Again, check the tutorial mentioned above, it kinda blew my mind. 1.7 minutes was the average time in this experiment for cracking a password to your windows account. Ouch.</p><p>Since I read and heard all of the above some time ago, I started wondering about the benefits and risks of using MD5. Most security experts discourage the use of MD5 nowadays for its known vulnerability to collision attacks. It should be replaced by something like the SHA-1 or since it is kind of outdated as well the even newer SHA-512. But that doesn&#8217;t help against the attack last mentioned, apart from increasing the possible hash values to even greater dimensions.</p><p>After some time, I found this very helpful article about spicing up your hashs to be more secure. I have to say though, these tips are NOT increasing the security of your hash function in a mathematical way. Luckily, the real world&#8217;s not all about math, so I think they are an easy way to get some extra security.</p><p>Edit: Please keep in mind that the tutorial posted here is not a perfect implementation of salts. It&#8217;s &#8211; as always &#8211; a source for ideas, not a perfect solution. But I always like it more if it&#8217;s explained like that, easy and understandable and in a rather digestible way. Please correct me if I&#8217;m mistaken.</p><p>If you want to screw around with MD5 a bit, here&#8217;s a link to an applet where you can do just that (SHA-1 as well). Switch to MD5, enter some text and press &#8220;Text digest&#8221;. Try guessing my hash from above (reaaaal easy), if you like and post the answer in the comments. First to score gets a cookie ;)</p><p>Stay tuned for upcoming ramblings about encryption and stuff. Maybe AES will be next.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/02/07/theoretical-cryptography-part-i-md5/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>How to display all Windows passwords</title><link>http://www.ghacks.net/2007/02/23/how-to-display-all-windows-passwords/</link> <comments>http://www.ghacks.net/2007/02/23/how-to-display-all-windows-passwords/#comments</comments> <pubDate>Fri, 23 Feb 2007 09:42:31 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Hacking]]></category> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[nt]]></category> <category><![CDATA[ophcrack]]></category> <category><![CDATA[windows-nt]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2007/02/23/how-to-display-all-windows-passwords/</guid> <description><![CDATA[Just a few days ago I was describing a method that would allow anyone to change passwords for all windows accounts using a boot cd and a program called NT Passwords. This is great if it does not matter if you change the password for, lets say, the administrators account. It might however be sometimes important to get into an account without the owner of the account knowing - and he would surely find out if his password would not be working anymore.]]></description> <content:encoded><![CDATA[<p>Just a few days ago I was describing a method that would allow anyone to change passwords for all windows accounts using a boot CD and a program called <a
href="http://www.ghacks.net/2007/02/21/recover-windows-xp-passwords/" title="recover NT passwords" target="_blank">NT Passwords</a>. This is great if it does not matter if you change the password for, lets say, the administrators account. It might however be sometimes important to get into an account without the owner of the account knowing &#8211; and he would surely find out if his password would not be working anymore.</p><p><img
src="http://www.ghacks.net/files/screens/2007/02/ophcrack.jpg" title="ophcrack windows nt password recovery" alt="ophcrack windows nt password recovery" align="left" height="124" width="250" /></p><p><a
href="http://ophcrack.sourceforge.net/" title="ophcrack" target="_blank">Ophcrack</a> is a tool that is able to quickly display Windows NT account passwords using Rainbow Tables instead of brute forcing the passwords. While it could take years to brute force a password that uses letters, numbers and special chars it takes only minutes to do so with Ophcrack.</p><p>Ophcrack can be downloaded with several different table sets. The default live cd is able to reveal passwords with alphanumeric chars only. If no passwords are revealed using this method you should download different table sets which support other chars as well.</p><p><span
id="more-1230"></span><img
src="http://www.ghacks.net/wp-content/uploads/2007/02/ophcrack-600x394.jpg" alt="ophcrack" title="ophcrack" width="600" height="394" class="alignnone size-medium wp-image-53615" /></p><blockquote><p>Runs on Windows, Linux/Unix, Mac OS X, &#8230;<br
/> » Cracks LM and NTLM hashes.<br
/> » Free tables available for Windows XP and Vista.<br
/> » Brute-force module for simple passwords.<br
/> » Audit mode and CSV export.<br
/> » Real-time graphs to analyze the passwords.<br
/> » LiveCD available to simplify the cracking.<br
/> » Loads hashes from encrypted SAM recovered from a Windows partition, Vista included.<br
/> » Free and open source software (GPL).</p></blockquote><p>Two additional table sets can be downloaded from the Ophcrack website. The first is 720 megabytes and should only be used on machines with at least 500 megabytes of ram. A smaller one with only 388 megabytes can be downloaded for machines with less than that amount of ram.</p><p>A new version of Ophcrack was released just four days ago.</p><p>Update: Ophcrack has not been updated for some time. The last update dates back to 2009 which was a bug fix release.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2007/02/23/how-to-display-all-windows-passwords/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Ophcrack 2.0 Windows Password Recovery</title><link>http://www.ghacks.net/2005/12/10/ophcrack-20-windows-password-recovery/</link> <comments>http://www.ghacks.net/2005/12/10/ophcrack-20-windows-password-recovery/#comments</comments> <pubDate>Sat, 10 Dec 2005 08:43:55 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Tools]]></category> <category><![CDATA[ophcrack]]></category> <category><![CDATA[password recovery]]></category> <category><![CDATA[Windows]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=212</guid> <description><![CDATA[Ophcrack is a Windows password cracker based on a time-memory trade-off using rainbow tables. This is a new variant of Hellman's original trade-off, with better performance. It recovers 99.9% of alphanumeric passwords in seconds.]]></description> <content:encoded><![CDATA[<p><a
href="http://ophcrack.sourceforge.net/" target="_blank">Ophcrack</a> is a Windows password cracker based on a time-memory trade-off using rainbow tables. This is a new variant of Hellman&#8217;s original trade-off, with better performance. It recovers 99.9% of alphanumeric passwords in seconds.</p><p><img
src="http://www.ghacks.net/files/screens/200512/oph.jpg" alt="windows password cracker" /></p><p><span
id="more-212"></span>You can download a .iso file that contains a live cd. In case you forgot your password you boot from the live cd and try to recover the password using the live cd.</p><p>[tags]windows, password recovery, lost password, freeware[/tags]</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2005/12/10/ophcrack-20-windows-password-recovery/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> </channel> </rss>
