| Openwall Project | /home Owl JtR Pro crypt pam_passwdqc tcb phpass scanlogd popa3d msulogin / Linux BIND / articles presentations / services donations / wordlists passwords / NEWS community lists Wiki CVSweb mirrors signatures / books | |
| bringing security into open environments | ||
|
Software you can find here:
Openwall software releases and other related files are also available from the Openwall file archive and its mirrors. You are encouraged to use the mirrors, but be sure to verify the signatures on software you download.
The more experienced users and software developers may use our CVSweb server to browse through the source code for most pieces of Openwall software along with revision history information for each source file.
We publish articles, make presentations, offer professional services, and accept donations.
We also maintain a wordlists collection for use with password crackers such as John the Ripper and with password recovery utilities, and a collection of pointers to password recovery resources on the Net.
Finally, we host community resources such as mailing lists and wiki for users of Openwall software and for other Open Source and computer security folks.
If you would like to be notified of updates to this website and the packages hosted here, you can subscribe to the announcement mailing list by sending an empty message to <announce-subscribe at lists.openwall.com> or entering your e-mail address below. You will be required to confirm your subscription by "replying" to the automated confirmation request that will be sent to you. You will be able to unsubscribe at any time and we will not use your e-mail address for any other purposes or share it with a third party. The list traffic is very low (1-2 messages a month). You may review past announcements here.
You may also follow us on Twitter.
In this snapshot, the kernel has been updated to OpenVZ's latest from their "RHEL5 testing" branch (2.6.18-194.11.3.el5.028stab071.3) with minor additional changes. CD bootup and the installer have been improved some further. The e2fsprogs, diffutils, bison, man-pages, man, diffstat, gawk, cdrkit, iptables, sed, grep, ltrace, hdparm, mktemp, vsftpd, acct, file, and m4 packages have been updated to new upstream versions. Assorted minor improvements have been made and/or bugfixes applied to several other packages. Please refer to the Owl-current change log for more information on some of these changes.
Petur Ingi Egilsson wrote a step-by-step guide entitled John the Ripper on a Ubuntu 10.04 MPI Cluster.
Steven M. Christensen of Sunfreeware has produced packages of JtR 1.7.6 for many versions of Solaris, both SPARC and x86, including both 32-bit and 64-bit builds.
GI John - Grid implemented John the Ripper, a curious non-Openwall project - has been updated to build upon JtR 1.7.6-jumbo-3.
A Python package re-implementing some algorithms from passwdqc has been created by Alastair Houghton. It is found on the passwdqc contributed resources list.
Detailed tutorials on cracking/auditing SHA-crypt hashed user passwords on recent Ubuntu, Fedora, and Solaris 10 systems have been posted to the john-users mailing list, separately for Linux (using Fedora 12 as the specific example) and for Solaris 10. These include optional OpenMP parallelization instructions and examples (to use multiple CPUs and/or CPU cores).
The jumbo patch for John the Ripper has been updated further to revision 1.7.6-jumbo-3, and the MPI parallelization patch has been updated to apply on top of this revision.
We've setup a collection of papers, source code, etc. related to bitslice implementations of DES (focusing on the S-boxes).
John the Ripper's implementation of OpenBSD-style Blowfish-based crypt(3) hashes is being parallelized with OpenMP (which is readily available with recent C compilers, including with gcc). This is expected to be made official with the next development release. Meanwhile, there's a patch on the wiki, and here are benchmarks on 8-way x86-64 systems (Core i7 and Dual quad-core Xeon) and 32-way UltraSPARC T2 (quad-core, 8 threads per core).
ElcomSoft's Microsoft SQL Server password change/reset and WiFi WPA/WPA2-PSK password security auditing products have also been added to the collection.
We've setup a web page with screenshots demonstrating the uses and setup of passwdqc on Openwall GNU/*/Linux, as well as a wiki page with password strength policy considerations aimed at systems administrators deploying and configuring passwdqc.
We have also setup the passwdqc-users mailing list. Please use it to share your experience with passwdqc and ask questions. The subscription instructions are found right on the passwdqc homepage.
Social bookmarking buttons have been added to most pages on the Openwall website, as well as on the Wiki. Please use these to add your favorite Openwall web pages to your favorite social websites.
New community wiki pages have been created on topics related to John the Ripper password cracker: How to retrieve and audit password hashes from remote Linux servers and Sample password hash encoding strings.
magnum has contributed a new MPI patch for John the Ripper, which supports parallelization of cracking modes other than "incremental". Older MPI patches were limited to just the "incremental" mode.
The jumbo patch for JtR 1.7.5 has been updated to revision 2.
A wiki page on passwdqc (our password/passphrase strength checking and policy enforcement toolset) has been setup with pointers to user-created OS-specific instructions and packages of passwdqc.
On a related note, a Python interface to crypt_blowfish by Daniel Holth has been added to the contributed resources list on the crypt_blowfish homepage.
Martin F. Krafft adopted the passwdqc Debian package and brought it up to date. Our password/passphrase strength checking and policy enforcement toolset now integrates nicely with PAM on Debian systems, and command-line utilities as well as the shared library providing the functionality will soon be available in separate packages.
Support for "generic" MD5-based hashes (optionally salted or/and iterated) has been added to the jumbo patch (starting with 1.7.4-jumbo-2), due to code contributed by JimF.
|
2426474 |