Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Tue, 27 May 2008 20:28:28 -0400
From: bofh <goodb0fh@...il.com>
To: john-users@...ts.openwall.com
Subject: Re: 15 characters

On Tue, May 27, 2008 at 7:27 PM, Solar Designer <solar@...nwall.com> wrote:

> On Tue, May 27, 2008 at 09:54:28AM -0400, bofh wrote:
> > Simple question.  I have a password file, and I want to run JtR on it.
>  My
> > needs are simple.  I want to search through:
> >
> > A-Z
> > a-z
> > 0-9
> > !@...^&*()-=_+[]\;',./{}|:"<>?
> >
> > basically all the printed characters.
> >
> > The password lengths are up to 15 chars.
>
> This is unreasonable.  The search space for the character set above and
> lengths up to 15 is too large.
>

Heh.  OK, 1.5 million billion years is a bit excessive.  Any ideas what

A-Z
a-z
0-9
!@...^*()

would take at 10 and 12 characters?  How difficult would that be to
implement?  I'm not really looking at cracking an entire password file, I'm
more of looking at a proving a point to some business folks.

Thanks again!

-- 
http://www.glumbert.com/media/shift
http://www.youtube.com/watch?v=tGvHNNOLnCk
"This officer's men seem to follow him merely out of idle curiosity." --
Sandhurst officer cadet evaluation.
"Securing an environment of Windows platforms from abuse - external or
internal - is akin to trying to install sprinklers in a fireworks factory
where smoking on the job is permitted." -- Gene Spafford
learn french: http://www.youtube.com/watch?v=j1G-3laJJP0&feature=related

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux