4 ms·
Along similar lines, I wonder if this fuzzer can be used to bruteforce passwords for applications. Would it do any better than standard "try all the combination
by smkdtr 12y ago
Along similar lines, I wonder if this fuzzer can be used to bruteforce passwords for applications. Would it do any better than standard "try all the combinations" method?
- owenmarshall 12y agoIf the password is generated with a sane KDF - bcrypt/scrypt/pbdkf2, no. If it's not, better attacks exist than trying every single password. If you're trying to crack the application - not the password - maybe, but I kinda doubt it.
- tptacek 12y agoNot really, because it depends on collecting traces from the target, and if you can do that you can usually just read the password out of memory.
- bri3d 12y agoOn the flip side, it could probably be used as a really slow universal keygen for naive license-key implementations :)