16 ms·
AV companies like to share samples with each other, so guessing they had at least a bit of a head start. Still, brute forcing a 10 character password that uses
by forgotusername 14y ago
AV companies like to share samples with each other, so guessing they had at least a bit of a head start. Still, brute forcing a 10 character password that uses the full ASCII printable character set looks like it'd require.. 9,500 years on a single high end GPU.
No idea what the current state of cracking is, but probably they used some rules based approach (like John the Ripper used to have) to massively reduce the search space.
- emmelaich 14y agoNote that !@# is just shift-1, shift-2, shift-3. So not unlikely that it would appear in a rules based approach. The password is numbers, english word, keyboard-sequence.
- scottmcf 14y agoThanks for that explanation. Being accustomer to a UK keyboard layout this didn't occur to me (as shift 1-3 is !"£ here).
- dredmorbius 14y agoAre you saying JtR no longer has a rules-based approach, or that it's no longer used? It's still actively maintained. http://www.openwall.com/john/ http://www.openwall.com/john/
- forgotusername 14y agoI'm saying I haven't tried to crack a password in about 12 years :)
- dredmorbius 14y agoFair enough.
- est 14y agoYou have no idea how brute force md5 was like. You just look up a 80TB db table full of hash strings. http://www.cmd5.org/password.aspx http://www.cmd5.org/password.aspx