5 ms·
How did you brute force 22 characters? Did you somehow use your fuzzy memory of the password to help?
by CaptainMarvel 7y ago
How did you brute force 22 characters? Did you somehow use your fuzzy memory of the password to help?
- polack 7y agoYes, sorry I was unclear about that. I knew multiple parts of it, but not what position the segments would go into. I had also mixed the passphrase up with another old obsolete one, so I had too many of these segments (back then I broke up the passphrases into blocks of 4 chars in my head) to fit in. There was also a couple of chars that I was uncertain about so those got "fully" brute forced. The worst part about the process was that it was hard to create rules for Hashcat to generate all different possibilities for the passphrase with all the information I knew about it baked in.
- MawKKe 7y agoSo.. nothing to do with LUKS?
- lucb1e 7y agoJust because luks isn't bad doesn't mean you can't use cracking tools to recover data when you forgot half the password, only have surveillance footage of the password being typed, have a bad password, etc. Since the article doesn't document any (new) luks weaknesses, none of the comments will be about luks being insecure.
- MayeulC 7y agoI've been in the same situation multiple times. I don't recall a case where the data was of critical importance, so I could get away with it, but using the parts of the passphrase I knew in a combined bruteforce/dictionary attack definitely crossed my mind. Do you have some links to reference material on how to achieve that?