Showing posts with label Bcrypt. Show all posts
Showing posts with label Bcrypt. Show all posts

Monday, 14 September 2015

Users Ashley Madison Had Often Name As Password


Users of the Ashley Madison website often used their username and password, so researchers have discovered. The group of researchers called Cynosure Prime showed last week that by some programming errors crack the password hashes of Ashley Madison are simple. At the hack of the cheaters website approximately 36 million password hashes were stolen.

Hashes to ensure that the user passwords are not immediately visible to an attacker in case the website is hacked. Ashley Madison used before a strong hashing algorithm, but by various programming errors hashes prove yet easy to crack. The researchers have cracked 11.7 million password hashes.

It shows that mainly weak and insecure passwords were used. So there were three million passwords of six characters and there were slightly less than 3 million, which consisted of eight males kara. The shortest password was cracked one character long. Nearly 10 million passwords only consisted of small letters or lowercase letters and numbers.

User Name

The researchers were also curious how many users are using their username and password. A total of 630 000 passwords were found that matched the user name. The investigators noted that the actual number is higher as possible, since there are obvious only obvious mutations were used. If there was more combinations of uppercase and lowercase letters sought was the true number is likely higher. The researchers argue that these passwords could be cracked too easily without programming errors found.

Striking Passwords

Instead of publishing a list of the Top 10 most common passwords, the researchers decided to create a collection of distinctive passwords. It is about passwords as allthegoodpasswordshavegone ',' youwillneverfindout ',' everynameitriedwastaken ',' goodguydoingthewrongthing ',' thisisagoodpassword 'and' correct horse battery staple ", known from the xkcd strip.

Thursday, 10 September 2015

Researchers Crack 11 Million Passwords Ashley Madison


Researchers have managed to crack more than 11 million passwords of Ashley Madison users, as they have announced today. The group of researchers called himself the cynosure Prime and examined the data that was stolen by the cheaters website. Attackers managed to steal gigabytes of data at Ashley Madison, including hashed passwords of users.

It involves a total of 36 million password hashes. Ashley Madison had the passwords are not stored in plain text, but in hashed form. This makes them not directly readable, but they can be cracked. For hashing the password had Ashley Madison the bcrypt algorithm used, and there was also a "salt-made 'use. This makes it much more difficult to crack password hashes. In a weaker algorithm, such as MD5, it is possible to try millions of password combinations per second. In the case of the gesalte bcrypt hashes came another researcher with his computer not go beyond 156 hashes per second. This investigator knew in five days 4000 passwords to crack.

It was therefore argued that the cracking of all Ashley Madison password hashes would last for centuries. That now seems not to be so. The researchers from Cynosure Prime investigated namely the second amount of data that was recently put online. In it they found information that helps them with the bcrypt hashed passwords could crack much faster. "Instead of cracking the slow bcrypt hashes, which is currently a hot topic, we decided to choose a more efficient approach and attack the MD5 tokens," the researchers said in their explanation.

The cheaters website appears to have used for reasons still unknown MD5 tokens. These tokens can be cracked much simpler than the bcrypt hashes. The information from the cracked tokens could then be used to crack the hashes bcrypt, she discovered. Since the researchers two weeks ago with their research, they began now more than 11.2 million bcrypt hashes cracked. In total there were in the stolen data over 15 million tokens.

Tuesday, 7 July 2015

Hacking Team Gets Control Back Hacked Twitter Account


The Italian company Hacking Team spyware for governments to develop and victim of a very large hack became possible where all data was captured, has regained control over its own Twitter account after about 10 hours.

A group of attackers who "HackedTeam" named used the hijacked Twitter account to spread links to a torrent file containing the data that was captured at the break. It would go together to such a 400GB 500GB of data. How the attackers were able to gain access to the network is still unknown. The leaked documents would prove, however, that surveillance company weak passwords like "Passw0rd" used. In addition, should the software company SQL Injection vulnerabilities contain.

The burglary was also the source of all kinds of programs, as well as the software itself stolen. A number of the programs has now been on GitHub placed. Furthermore, it seems that the attackers hacked not only the company but also at least one employee of the company. The Gmail account of this employee would be hacked and his Twitter account. Meanwhile, the Gmail password changed and raised the Twitter account, so says a security engineer with the alias "bcrypt" via Twitter.Hacking Team's website is now also no longer accessible.