Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
    • Search
    • Submit
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
    • Search
    • Submit
  • GAME REVIEWS
  • ARTICLES
    • Editorials
    • Guru3D VGA Charts
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Dated content
    • More Categories
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Knowledgebase
    • Search articles
    • More Categories
  • FORUMS
  • SEARCH
    • Search Articles
    • Search News
    • Search Files
  • NEWSLETTER
  • CONTACT

New Reviews
Gigabyte GeForce GTX 780 WindForce 3x OC review
GeForce GTX 780 SLI and Multi monitor review
GeForce GTX 780 review
OCZ Vertex 450 SSD review
Gigabyte GeForce GTX 650 Ti Boost OC WindForce 2X review
MSI Radeon HD 7790 TurboDuo OC review
Metro Last Light VGA Graphics Benchmark performance test
Noctua NH-U12S and NH-U14S review
ASUS GeForce GTX 670 DirectCU Mini review
OCZ Vertex 3.20 SSD review

New Downloads
GeForce 320.18 WHQL Driver Download
AMD Catalyst Application Profile Download 13.5 CAP1
MSI Afterburner 3.0.0 Beta 10 Download
PhysX System Software 9.13.0325 Download
GPU-Z Download 0.7.1
HWiNFO32 4.18 Download
HWiNFO64 4.18 Download
GeForce 320.14 BETA Driver Download
Nvidia Lifelike Human Face Rendering Tech Demo Download
3DMark Download v1.1.0


New Forum Topics
by: Hilbert Hagedoorn GeForce GTX 780 reviewby: Stone Gargoyle Xbox World reveals Next Gen Xbox?by: bishi Geforce GTX 780 Owners Clubby: hallryu Crysis 3 #2by: alanm Interesting background story of AMDby: Pill Monster Ford Australia to shut down factoriesby: eighty1 help upgrading cpu mobo and some queries.by: Pill Monster 3D Mark 2013 Guru3D Recordsby: RedSeptember Call of Juarez - Gunslingerby: Agent-A01 Geforce GTX TITAN Owner Club


Online Users
There are currently 2216 user(s) online:
Fractalphonic, g4wings, Google, Live Search, MSN, neorage, Prod, Yahoo


Guru3D.com » News » Password Cracking 25 GPU Monster Devours Passwords Real Fast

Password Cracking 25 GPU Monster Devours Passwords Real Fast

Posted by Hilbert Hagedoorn on: 12/08/2012 09:06 AM | 26 comment(s) ]

A presentation at the Passwords^12 Conference in Oslo, Norway, has moved the goalposts, again. Speaking on Monday, researcher Jeremi Gosney (a.k.a epixoip) demonstrated a rig that leveraged the Open Computing Language (OpenCL) framework and a technology known as Virtual OpenCL (VCL) to run the HashCat password cracking program across a cluster of five, 4U servers equipped with 25 AMD Radeon GPUs and communicating at 10 Gbps over Infiniband switched fabric. 

Gosney's system elevates password cracking to the next level, and effectively renders even the strongest passwords protected with weaker encryption algorithms, like Microsoft's LM and NTLM, obsolete. 

In a test, the researcher's system was able to churn through 348 billion NTLM password hashes per second. That renders even the most secure password vulnerable to compute-intensive brute force and wordlist (or dictionary) attacks. A 14 character Windows XP password hashed using LM, for example, would fall in just six minutes, said Per Thorsheim, organizer of the Passwords^12 Conference

[Note of clarification from Jeremi: "LM Is what is used on Win XP, and  LM converts all lowercase chars to uppercase, is at most 14 chars long, and splits the password into two 7 char strings before hashing -- so we only have to crack 69^7 combinations at most for LM. At 20 G/s we can get through that in about 6 minutes. With 348 billion NTLM per second, this means we could rip through any 8 character password (95^8 combinations) in 5.5 hours." ]

“Passwords on Windows XP? Not good enough anymore,” Thorsheim said.

Tools like Gosney’s GPU cluster aren’t suited for an “online” attack scenario against a live system. Rather, they’re used in “offline” attacks against collections of leaked or stolen passwords that were stored in encrypted form, Thorsheim said. In that situation, attackers aren’t limited to a set number of password attempts – hardware and software limitations are all that matter.

(slides available here - PDF)

The clustered GPUs clocked impressive speeds against more sturdy hashing algorithms as well, including MD5 (180 billion attempts per second, 63 billion/second for SHA1 and 20 billion/second for passwords hashed using the LM algorithm. So called “slow hash” algorithms fared better. The bcrypt (05) and sha512crypt permitted 71,000 and 364,000 per second, respectively.

Published benchmarks against common hashing algorithms using the 25 GPU HPC cluster

In an IRC chat with Security Ledger, Gosney said he has been working on CPU clustering for about five years and GPU clustering for the last four years.

“Then we just started trying to build the biggest GPU rigs we could, packing as many GPUs into a single server as possible so that we wouldn’t have to deal with clustering or distributing load,” Gosney wrote..



Password Cracking 25 GPU Monster Devours Passwords Real Fast





Rate this story
Rating:

« Intel HD Graphics Driver 15.28.10.2897 Windows 7 and 8 Download · Password Cracking 25 GPU Monster Devours Passwords Real Fast · Scythe Apsalus III-120 »

2 pages 1 2


Mufflore
Ancient Guru



Posts: 9536
Joined: 2010-05-22

#4474638 Posted on: 12/08/2012 09:08 AM
I need this!

Years ago I protected an archive of pictures before transporting them.
Then I lost the originals in a hard drive crash and was left only with the protected archive, thinking I knew the password.
But I cant remember the password for the life of me.

I've tried cracking it a few times, but after months, it was still going so decided to stop and wait for a more efficient method.

Mannerheim
Ancient Guru



Posts: 4480
Joined: 2004-01-24

#4474645 Posted on: 12/08/2012 09:51 AM
Wonder if theres a crypt "files" that destroys files after 10 wrong answer?
It woud make all these hack systems useless.

Mufflore
Ancient Guru



Posts: 9536
Joined: 2010-05-22

#4474648 Posted on: 12/08/2012 10:02 AM
The file would need an executable element.
There would always be a way to prevent the executable from running.

Mannerheim
Ancient Guru



Posts: 4480
Joined: 2004-01-24

#4474649 Posted on: 12/08/2012 10:05 AM
The file would need an executable element.
There would always be a way to prevent the executable from running.


well a random picture as password woud be a perfect key???
It woud have millions of codes? =) Picture woud not have to be perfect, only like 100x similar things in there, like landscape and buildings etc ...

Mufflore
Ancient Guru



Posts: 9536
Joined: 2010-05-22

#4474654 Posted on: 12/08/2012 10:24 AM
How would you use the picture to unlock the file?

Mannerheim
Ancient Guru



Posts: 4480
Joined: 2004-01-24

#4474661 Posted on: 12/08/2012 10:30 AM
Same as file asks password, it woud ask picture. There are some programs made that identifyes faces and fingerprints... so it shoud not be impossible to make..
Picture just woud have millions of code to crack, compared to any other password.

Im not genious about these but more like thinker.. =)

Seems Win8 has somekind picture password... but it gives u a photo and have to draw to open... Woud be better if u had a photo in memory stick and win woud not give a photo, woud have to select it ur self, from hundreds of photos and then draw...

http://www.youtube.com/watch?v=NQtG6d7rCSk

anticupidon
Maha Guru



Posts: 1667
Joined: 2008-03-06

#4474732 Posted on: 12/08/2012 01:43 PM
whoa, the powah needed to feed this monster!
but what it is new is the scale,the concept is not new,all mobile phone shops have a smaller version to calculate hashes for unlocking codes.
we build some of those rigs,so..

Mufflore
Ancient Guru



Posts: 9536
Joined: 2010-05-22

#4474753 Posted on: 12/08/2012 02:16 PM
Same as file asks password, it woud ask picture. There are some programs made that identifyes faces and fingerprints... so it shoud not be impossible to make..
Picture just woud have millions of code to crack, compared to any other password.

Im not genious about these but more like thinker.. =)
All you are doing is using a longer password.
You can do that without a picture file.

Even if you did use a picture file, it will need a defined process, this process will be cracked.
Nothing will be gained other than a more complicated way of using a longer password, making it more annoying for the end user.

Seems Win8 has somekind picture password... but it gives u a photo and have to draw to open... Woud be better if u had a photo in memory stick and win woud not give a photo, woud have to select it ur self, from hundreds of photos and then draw...

http://www.youtube.com/watch?v=NQtG6d7rCSk

If you have an operating system based protection system, it can be foiled by using a different operating system to crack the file.
Granted it adds a bit of time 'before' it is cracked, but when it has been worked out once, it can be used all the time.

sverek
Maha Guru



Posts: 1036
Joined: 2011-01-02

#4474764 Posted on: 12/08/2012 02:46 PM
good. Now install F@H and turn this monster into something useful.

Speed Weed
Master Guru



Posts: 637
Joined: 2011-12-04

#4474883 Posted on: 12/08/2012 06:00 PM
Wonder if anyone with a password like 'love,' 'sexy,' or '1234' is reading this? ;)

Extraordinary
Ancient Guru



Posts: 2763
Joined: 2010-04-21

#4474886 Posted on: 12/08/2012 06:11 PM
Wonder if anyone with a password like 'love,' 'sexy,' or '1234' is reading this? ;)



Probably not, the people who cracked their account after 3 attempts might be though

PhazeDelta1
Ancient Guru



Posts: 9340
Joined: 2010-09-12

#4474905 Posted on: 12/08/2012 06:55 PM
Wonder if anyone with a password like 'love,' 'sexy,' or '1234' is reading this? ;)


if people are using passwords like that, then they deserve to get hacked.

vbetts
Moderator



Posts: 10225
Joined: 2006-07-04

#4474915 Posted on: 12/08/2012 07:28 PM
(This is begging for it)But can it run crysis?

Mufflore
Ancient Guru



Posts: 9536
Joined: 2010-05-22

#4475143 Posted on: 12/09/2012 02:49 AM
Hey that might be possible.

Speak to Lucid, they may be able to make a chip that works across motherboards.
http://www.ubergizmo.com/2009/09/lucid-offers-a-multi-gpu-alternative-to-sli-and-crossfire/

Then you can setup an array of UltraHD displays...
http://www.tomshardware.com/news/LG-Ultra-HD-84-inch-TV-Price-UK-Release-Date,19465.html
and play Crysis from 1/2 a mile away.

Cool!

Penal Stingray
Banned



Posts: 961
Joined: 2010-12-17

#4475161 Posted on: 12/09/2012 03:29 AM
But can it crack my butcrack? Lols

2 pages 1 2


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2013