3 ms·
Hmm, I actually have an old password protected PDF (pass is prolly around ~10 chars, letters+digits) whose password I forgot. Are there legit services offering
by mvelbaum 3y ago
Hmm, I actually have an old password protected PDF (pass is prolly around ~10 chars, letters+digits) whose password I forgot.
Are there legit services offering brute-force cracking? How long would it take, and how much it would it cost?
- mikequinlan 3y agoYou may not need to crack the password. https://smallpdf.com/unlock-pdf https://smallpdf.com/unlock-pdf for example. Here is a PDF password cracker: https://www.lostmypass.com/file-types/pdf/ https://www.lostmypass.com/file-types/pdf/
- mvelbaum 3y agoI tried the free tools already -- none seemed to work :(
- pcthrowaway 3y agoI'm very wary downloading and running software on my computer in general, but I'd be even moreso with software from some unknown company providing a hacking tool. Definitely better to do this in a VM, but then your performance would take a hit
- Etheryte 3y agoThis question, albeit for a longer password at 20 chars, was discussed at [0]. [0] https://security.stackexchange.com/questions/61346/how-long-would-it-take-to-bruteforce-an-aes-128-protected-pdf-knowing-the-key-is https://security.stackexchange.com/questions/61346/how-long-...
- ycuser2 3y ago10 chars doesn't seem impossible to me (just a feeling). Don't about such services.
- kingforaday 3y agoKeep in mind 10 character spaces should be represented by the selection pool size (A-Z = 26, a-z = 26, 0-9 = 10, so 26+26+10=62). You now can say 62^10 = total possible guesses available. Certainly you can start to make intelligent decisions on guessing properties and priorities to reduce your time. Also I didn't discuss entropy here in order to represent it more basically for the parent comment.
- tyingq 3y agoView the source of the pdf, find the trailer dictionary (ctrl-f "/Encrypt"), and note the object number of the encryption dictionary. An example trailer below, here the encryption dictionary happens to be object ID 94,0 % Trailer dictionary trailer << /Size 95 % number of objects in the file /Root 93 0 R % the page tree is object ID (93,0) /Encrypt 94 0 R % the encryption dict is object ID (94,0) /ID [<1cf5...>] % an arbitrary file identifier >> Use the object id to find the encryption dictionary: % Encryption dictionary 94 0 obj << /Filter /Standard % use the standard security handler /V 1 % algorithm 1 /R 2 % revision 2 /U (xxx...xxx) % hashed user password (32 bytes) /O (xxx...xxx) % hashed owner password (32 bytes) /P 65472 % flags specifying the allowed operations >> endobj Generally, if /V and /R are both 4 or less, you can find tools to crack it yourself on a normal PC. More info on the values of /V and /R here: https://qpdf.readthedocs.io/en/stable/encryption.html https://qpdf.readthedocs.io/en/stable/encryption.html
- mvelbaum 3y agoThis is what I get: 20 0 obj << /R 4 /O (...) /U (...) /P -1548 /Length 128 /V 4 /EncryptMetadata true /Filter /Standard /StmF /StdCF /StrF /StdCF /CF << /StdCF << /AuthEvent /DocOpen /CFM /AESV2 >>>>>> endobj I tried a bunch of tools, including https://www.elcomsoft.com/apdfpr.html?src=prog_apdfprp https://www.elcomsoft.com/apdfpr.html?src=prog_apdfprp to get it to quickly remove the password, but nothing worked :/
- btdmaster 3y agoIs it purely lowercase? Someone gave an example of how to do this with 10 characters a-z 0-9 a few years ago: https://nicholaslyz.com/blog/2021/07/23/cracking-pdf-hashes-with-hashcat/ https://nicholaslyz.com/blog/2021/07/23/cracking-pdf-hashes-... Also, is the password completely random? If it's not, you'd have a much easier time using a large dictionary rather than every possible 10-character word. As in the article, it looks like on a consumer GPU you'd get on the order of 10MH/s, or 10 million hashes per second. I need someone to check my math on this, but 36**10/10_000_000 GPU-seconds (36 characters, optimistically assuming [a-z0-9] lowercase) is about 4000 GPU-days, so out of reach. The A100 attempt from the article only made it about 15x faster, so you'd still need to wait a few months at best. (This is with the assumption you know it's pure lowercase.) Can someone confirm my math on this?