How to Improve the Success Rate of Password Cracking Technology

Think like a hacker and ask yourself how quickly a password can be cracked based on its structure.

When a hacker or penetration tester breaches a system and wants to access a plaintext password from a database dump, they must first crack the stored password hash. Many attackers jumped headlong into this concept: they tried any password attack they wanted, with little reason. This discussion will show some effective password cracking methods and how to combine statistical analysis of passwords with tools to create a time-limited method to achieve efficient and successful cracking.

Why is this important?

Password cracking is a dying undertaking. Users need to create more complex passwords, and some back-end developers are starting to use   mechanisms such as Bcrypt to replace standard hash functions. The Bcrypt hash takes longer to generate, so the password becomes more difficult to crack. Crackers need to generate hashes very quickly to effectively crack passwords, so Bcrypt is a very powerful tool to combat such attacks. To illustrate this example, a password cracking program made by 25 GPU clusters launched in 2012 was able to achieve an NTLM hash generation speed of 350 billion hashes per second, compared with a Bcrypt hash generation speed of 71,000. Using this as a comparison model, 5 million NTLM hashes can be generated for each Bcrypt hash generated. When faced with the Bcrpyted algorithm, hackers must make more computational guesses about passwords and cannot rely on using brute force for every possibility.

执行流程的顺序

Note: If an attacker knows that the password is so short that brute force cracking the key space won't take long, there is no need to take incremental attack steps.

Timeline

time efficiency has become a key factor in successfully cracking passwords. While it would be nice to overwrite the entire critical space of a user's password, the time required to do so is often not feasible. Therefore, when cracking, it is important to try the most time-saving attack first, and if not successful, proceed with the slower cryptographic attack that covers more key space. The fastest method is a simple dictionary attack based on commonly used user passwords and previous password dumps. From there, you should try manipulating the dictionary to add numbers or symbols or change letters at the end. This is called a hybrid attack or a rules-based attack. Next, you can try using machine learning to generate possible passwords. Markov chains are a good example. By combining common elements that exist in English to form words (for example,"ing","er","qu"), you can generate good guesses about passwords, such as the password below.Although this specific password can be easily cracked using any method, we will use this password to simplify all attack vectors. Password1234Password1234

Pa +  ss  +  Word  + 1234

Finally, a targeted brute force attack (called a masking attack) overrides all key spaces for a given password based on the password structure. By the "structure" of a password, I mean the type and order of characters used to create the password. For example, a "structure" with upper case letters followed by 7 lower case letters followed by 4 digits (denoted as). Password1234 ullldddd

Lower case letters, upper case letters, symbols, numbers (l)(u)(s)(d)

So if an attacker decides to use this structure to create all possibilities for character combinations, he or she will eventually find the password. The attacker's question then becomes: What structures should be targeted first when attacking a set of hashes? Password1234

Statistical Analysis

To help answer this question, I conducted some statistical analysis of popular password dumps to see if there are password structures that are more common than other password structures and to what extent this structure is correct. The sample size of more than 34 million publicly exposed passwords includes well-known password dumps such as RockYou, LinkedIn, and phpBB.


The figure below shows the frequency of the mask structure for each unique mask. The red line represents the 50% line, which appears after the 13th most frequently occurring mask.


从示例图派生的密码掩码

This means that the top 13 unique mask structures account for 50% of the sample password. More than 20 million passwords in the sample have structures in the top 13 masks. In terms of the universality of structured ciphers, these results are quite shocking. The other 50% exists in the long right tail and has been reduced in this figure. In fact, of the 260,500 unique masks, only 400 are shown in this figure. The concept of this universally structured password is incredible; however, it's not surprising when you consider how users create and remember their passwords. Based on analytical data, there are some logical factors that help explain how this is possible. When users are asked to provide a password that contains capital letters, it will be the first character more than 90% of the time. When asking for numbers, most users add two digits to the end of their password, possibly the year of graduation. The next most popular option is to end the password with a four-digit number (probably last year or this year).In this case, the next most popular number has one number at the end and three numbers at the end. Structural commonalities such as these allow attackers to predict what the structure of a user's password is most likely to be.

Statistical Mixing-Accelerating the use of this structural knowledge makes it safe to assume that users are likely to set their passwords to than (random letters), even if they all start with 9 letters and have 9 letters.

So, we assume that given a password structure, if we see consecutive letters, it is likely to be a Word. This is a very useful assumption for crackers because it eliminates a lot of key space. This then turned into a hybrid attack that took advantage of the statistical significance of common cryptographic structures. Potatoestwivwdhpp Efficiency and Time Limitations Generally, as penetration testers, even if we break a set of hashes, we may not have time to crack all the hashes.

However, disrupting them may help upgrade access to the system and lead to more useful discoveries for customers. Therefore, when cracking a password, it may be useful to determine how much time will be allocated to cracking a set of hashes. Using the structures discovered in previous analysis, an attacker can determine that he or she wants to override the top 10 popular structures based on password complexity requirements sorted by fastest completion time. Finally, an attacker can time limit his or her method by spending no more than an hour performing the hack. This was discovered during a recent penetration test to obtain a hash. Here is a snapshot of the results of the CPU-based cracker.

受损结果表

In this case, the fastest structure to complete is for us to define it as a capital letter followed by three lower case letters ("W "stands for" Word "), and then four digits. There are 69 passwords in the hash set that match the structure, and my standard CPU is able to traverse all possibilities for the structure in a minute. We stopped cracking at 62 minutes, and the cracking produced 221 unique cracking hashes that matched 491 accounts, resulting in a total of 11% of leaks. The reason for the large difference in the number of cracked passwords and account leaks is that Office settings often cause people to use common passwords. If an attacker determines that a common password is being used in the environment, all users with the same password will also be compromised. U (W3) dddd Although a hybrid attack or a rule-based attack (for example) can crack several of these passwords faster, the structure of the attacking password allows us to cover more of the key space.

If a faster attack proves to be unable to successfully destroy the target hash, this method is an effective next step.Also, it is important to remember that this example was done on a fairly mediocre CPU, and executing the same attack on a powerful GPU can shorten this time to a few seconds. Therefore, the exact timing is not as important as the effective implementation of the theory. Best64

targeted

statistical analysis helps us attack common password structures in general; however, there are tools that can help locate specific applications. Tools  such as CeWL can grab words from web pages and use them to generate company-specific Word lists or dictionaries. It works because companies tend to use passwords that are relevant to their industry, company or job. In addition, since we determined that commonly used passwords are popular in the work environment, we can also use already-cracked passwords as the basis for other passwords, which may be similar. For example, if we discover that "" is a user's password, we might put "" in the new Word list, put it in the rule set, and then discover that someone else has the password "". This concept of using cracked basic words (such as'') and modifying them with surrounding characters is very effective when cracking hashes dumped from corporate environments, which can be traced back to the concept of password reuse. Based on penetration tests we conducted, this is best suited for cracking the last 20% of uncracked hashes. AcmeCorp1234AcmeCorpAcmeCorp@2015AcmeCorp

It is also important to prune the dictionary so that all guessed passwords meet the requirements specified by the application, so that time is not wasted guessing passwords that cannot be guessed due to length or character composition.

Putting it all together

, starting with the fastest attack and covering the least key space (standard dictionary attack) to the slowest and largest key space (pure brute force) is the ideal progression considering the time allocated to the attack. Therefore, attackers should implement a standard approach that takes this into account. If the account the attacker wants to breach is completed in the first phase, there may be no reason to continue using other attacks; however, in many cases, if the target account is present, a simple dictionary attack may not be enough, or the attacker just wants to destroy as many accounts as possible, so a mixture of statistically structured attacks and targeted brute force attacks may be needed. Therefore, establishing methods is crucial to successful cracking, which can include the methods mentioned earlier as well as some automated processes. Recent tools such as  PRINCE can help facilitate password cracking. Developing a tool strip, such as PRINCE trying in methods, is important, but understanding the functions behind the tools rather than relying entirely on them will make cracking more effective.

Defense-How to combat statistics

By using these passwords for analysis, you can determine the most popular structures given the required level of complexity. Therefore, developers might want to implement controls to prevent users from using some of these very popular constructs to flatten the curve of the previous graph. The problem with this idea, however, is that without a simple structure, users may find it difficult to remember their passwords. I recommend using a password manager that requires two-factor authentication. These apps will generate and store all your passwords for you, so memory is not an issue. The passwords they generate are structurally random and can be used as long as the application allows them. As I mentioned before, encrypting passwords is another very effective way to slow down the prospects of attackers.Finally, implementing policies within the Office that help users understand the dangers of sharing or reusing passwords is a successful step in the right direction, even if users don't always comply. Although they will likely not always comply, it is an effective control measure.

Conclusions and gains

Password cracking can be a vague concept. As the difficulty of cracking increases, targeted attacks based on efficiency are needed, and personal cracking methods should be established. It's not worth investing money to ultimately increase hash generation speed. Therefore, implementing a method and simplified process using statistics and tools as a means of attack can facilitate password cracking. Developers can put in place controls to deal with this situation, and users can use secure password managers to minimize the effectiveness of these attacks; however, such implementations are not yet very popular. Currently, statistical attacks on passwords are effective in terms of both the number of cracks and the efficiency of connection times. Think about your own passwords and ask yourself how quickly they can be cracked based on their structure and what controls in your Office may cause attackers to break into users 'accounts.

Previous: Hashcat claims to be the world's fastest password cracking tool.
Next: Crack Exlce by yourself word, pdf, Compressed Password Tutorial
  • Focus on Word, Excel, PPT, PDF, RAR, ZIP, 7Z, Compressed File, Office Encrypted File Unlock Decryption
  • We provide users with high-quality file compression password recovery, PDF unlocking, and Word password recovery services.
  • Copyright © Document Password Recovery Master Online Decryption Platform