Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 16 Apr 2012 16:11:23 -0600
From: Stephen John Smoogen <smooge@...il.com>
To: john-users@...ts.openwall.com
Subject: Re: .chr files

On 16 April 2012 02:43, Simon Marechal <simon@...quise.net> wrote:
> On 16/04/2012 00:01, Frank Dittrich wrote:
>> So may be we might need some tests on real-life passwords.
>> Either a large set of saltless hashes, or even a large list of cracked
>> passwords from various hashes, converted for --format=dummy.
>
> This :
>
> https://www.korelogic.com/InfoSecSouthwest2012_Ripe_Hashes.html
>

In going through this data.. I think there is a lot of chaff in the
md5 passwords. It looked actually like someone had taken the KoreLogic
dictionary set from the 2010 contests and md5sum'd it 1:1. While some
of those are probably passwords.. other items (like the md5summing of
all the facebook accounts) might introduce more noise than is useful.

-- 
Stephen J Smoogen.
"The core skill of innovators is error recovery, not failure avoidance."
Randy Nelson, President of Pixar University.
"Years ago my mother used to say to me,... Elwood, you must be oh
so smart or oh so pleasant. Well, for years I was smart. I
recommend pleasant. You may quote me."  —James Stewart as Elwood P. Dowd

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.