Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
    • Search
    • Submit
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
    • Search
    • Submit
  • GAME REVIEWS
  • ARTICLES
    • Editorials
    • Guru3D VGA Charts
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Dated content
    • More Categories
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Knowledgebase
    • Search articles
    • More Categories
  • FORUMS
  • SEARCH
    • Search Articles
    • Search News
    • Search Files
  • NEWSLETTER
  • CONTACT

New Reviews
MSI Radeon HD 7790 TurboDuo OC review
Metro Last Light VGA Graphics Benchmark performance test
Noctua NH-U12S and NH-U14S review
ASUS GeForce GTX 670 DirectCU Mini review
OCZ Vertex 3.20 SSD review
Cooler Master Eisberg 240L Prestige review
Guru3D and OCZ Contest - PC Power 1200W PSU Giveaway
MSI GeForce GTX 650 Ti BOOST OC review
ASUS ROG ORION PRO Gaming Headset Review
Guru3D Rig of the Month - April 2013

New Downloads
GPU-Z Download 0.7.1
HWiNFO32 4.18 Download
HWiNFO64 4.18 Download
GeForce 320.14 BETA Driver Download
Nvidia Lifelike Human Face Rendering Tech Demo Download
3DMark Download v1.1.0
XBMC Media Center Download 12.0 2
RTSS Rivatuner Statistics Server Download v5.1.1
AS SSD Benchmark Download v1.7.4739.38088
AMD Catalyst Application Profile Download 13.4 CAP1


New Forum Topics
by: mentalpeace Borderlands 2 + MSI 670 oc + Physx Highby: hallryu Windows 8 #2by: hallryu The Guru3D Screenshot Thread - RTFM! #22 (Rules update!)by: eighty1 help upgrading cpu mobo and some queries.by: PantherX Fold Faster on GPUs With FahCore_17by: freeZ HTC One - Unboxing Videoby: Bukkake Another look at HPET High Precision Event Timerby: Glidefan the "i'm proud of this picture i took" thread #3by: villa_youth Metro: Last Lightby: mbk1969 Windows timer resolution tool in form of system service


Online Users
There are currently 1644 user(s) online:
Google, Live Search, Memorian, MSN, Yahoo


Guru3D.com » News » Password Cracking 25 GPU Monster Devours Passwords Real Fast

Password Cracking 25 GPU Monster Devours Passwords Real Fast

Posted by Hilbert Hagedoorn on: 12/08/2012 09:06 AM | 26 comment(s) ]

A presentation at the Passwords^12 Conference in Oslo, Norway, has moved the goalposts, again. Speaking on Monday, researcher Jeremi Gosney (a.k.a epixoip) demonstrated a rig that leveraged the Open Computing Language (OpenCL) framework and a technology known as Virtual OpenCL (VCL) to run the HashCat password cracking program across a cluster of five, 4U servers equipped with 25 AMD Radeon GPUs and communicating at 10 Gbps over Infiniband switched fabric. 

Gosney's system elevates password cracking to the next level, and effectively renders even the strongest passwords protected with weaker encryption algorithms, like Microsoft's LM and NTLM, obsolete. 

In a test, the researcher's system was able to churn through 348 billion NTLM password hashes per second. That renders even the most secure password vulnerable to compute-intensive brute force and wordlist (or dictionary) attacks. A 14 character Windows XP password hashed using LM, for example, would fall in just six minutes, said Per Thorsheim, organizer of the Passwords^12 Conference

[Note of clarification from Jeremi: "LM Is what is used on Win XP, and  LM converts all lowercase chars to uppercase, is at most 14 chars long, and splits the password into two 7 char strings before hashing -- so we only have to crack 69^7 combinations at most for LM. At 20 G/s we can get through that in about 6 minutes. With 348 billion NTLM per second, this means we could rip through any 8 character password (95^8 combinations) in 5.5 hours." ]

“Passwords on Windows XP? Not good enough anymore,” Thorsheim said.

Tools like Gosney’s GPU cluster aren’t suited for an “online” attack scenario against a live system. Rather, they’re used in “offline” attacks against collections of leaked or stolen passwords that were stored in encrypted form, Thorsheim said. In that situation, attackers aren’t limited to a set number of password attempts – hardware and software limitations are all that matter.

(slides available here - PDF)

The clustered GPUs clocked impressive speeds against more sturdy hashing algorithms as well, including MD5 (180 billion attempts per second, 63 billion/second for SHA1 and 20 billion/second for passwords hashed using the LM algorithm. So called “slow hash” algorithms fared better. The bcrypt (05) and sha512crypt permitted 71,000 and 364,000 per second, respectively.

Published benchmarks against common hashing algorithms using the 25 GPU HPC cluster

In an IRC chat with Security Ledger, Gosney said he has been working on CPU clustering for about five years and GPU clustering for the last four years.

“Then we just started trying to build the biggest GPU rigs we could, packing as many GPUs into a single server as possible so that we wouldn’t have to deal with clustering or distributing load,” Gosney wrote..



Password Cracking 25 GPU Monster Devours Passwords Real Fast





Rate this story
Rating:

« Intel HD Graphics Driver 15.28.10.2897 Windows 7 and 8 Download · Password Cracking 25 GPU Monster Devours Passwords Real Fast · Scythe Apsalus III-120 »

2 pages 1 2


ASLayerAODsk
Master Guru



Posts: 515
Joined: 2006-05-08

#4475192 Posted on: 12/09/2012 05:14 AM
Wouldnt it be completely useless vs biometrics? or is that the 'picture' you had in mind as mentioned previously?

Year
Ancient Guru



Posts: 11657
Joined: 2007-11-01

#4475240 Posted on: 12/09/2012 09:09 AM
(This is begging for it)But can it run crysis?




lol you just ruined the day of 368 Billion people (me included) who actually wanted to post what you posted.. "Can It Run Crysis?".

LesserHellspawn
Master Guru



Posts: 169
Joined: 2010-03-27

#4475265 Posted on: 12/09/2012 10:02 AM
*shrug*

Next year we'll have yet another system that again supasses this by a mile. One day one of these things will even fully calculate pi...

Mufflore
Ancient Guru



Posts: 9519
Joined: 2010-05-22

#4475270 Posted on: 12/09/2012 10:09 AM
Because there will always be something better next year, you wont upgrade your PC?

How do you propose fully calculating an infinite series?

Darkest
Ancient Guru



Posts: 5237
Joined: 2003-03-25

#4475380 Posted on: 12/09/2012 02:36 PM
Because there will always be something better next year, you wont upgrade your PC?

How do you propose fully calculating an infinite series?

Some mathematicians believe that there's no such thing as infinity, and that that some things are simply beyond our comprehension. Even if that is true, it's probably the same result in the end (Aka never going to happen). Don't get me wrong, that's not my belief. Simply throwing it out there.

Interesting article by the way, they're pushing some very impressive numbers.

Black_ice_Spain
Ancient Guru



Posts: 4154
Joined: 2008-05-08

#4475427 Posted on: 12/09/2012 04:06 PM
I need this!

Years ago I protected an archive of pictures before transporting them.
Then I lost the originals in a hard drive crash and was left only with the protected archive, thinking I knew the password.
But I cant remember the password for the life of me.

I've tried cracking it a few times, but after months, it was still going so decided to stop and wait for a more efficient method.

rent amazon cloud server

S3nt3nc3
Master Guru



Posts: 199
Joined: 2010-12-08

#4475502 Posted on: 12/09/2012 05:34 PM
Nothing can crack my passwords.

32 symbols is enough to feel safe about my stuff :banana:

Mufflore
Ancient Guru



Posts: 9519
Joined: 2010-05-22

#4475528 Posted on: 12/09/2012 06:04 PM
For 10 to 20 years maybe.
GPU performance is coming on like mad!
Remember to destroy old archives.

StewieTech
Chuck Norris



Posts: 653
Joined: 2012-02-06

#4475538 Posted on: 12/09/2012 06:20 PM


lol you just ruined the day of 368 Billion people



boodikon
Maha Guru



Posts: 2082
Joined: 2005-10-30

#4475544 Posted on: 12/09/2012 06:25 PM
well a random picture as password woud be a perfect key???
It woud have millions of codes? =) Picture woud not have to be perfect, only like 100x similar things in there, like landscape and buildings etc ...

Johnny mehnomic springs to mind.

R41DZ3R0
Newbie



Posts: 1
Joined: 2012-12-09

#4475649 Posted on: 12/09/2012 09:47 PM
that is not an everyday SystemBuilder's Rig we've seen aren't we. Such unique skills they have..

2 pages 1 2


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2013