Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security

Reply
 
LinkBack Thread Tools
Old 06-03-09   #1 (permalink)
PC Gamer
 
Caedis's Avatar
 
intel nvidia

Join Date: May 2009
Location: Texas
Posts: 178

Rep: 65 Caedis is acknowledged by some
Unique Rep: 55
Trader Rating: 0
Cool Brute force password calculator


Have you ever typed in your password while logging into a page and it has that little password strength bar on it that fills up the more you type? How accurate is it? Can you even trust such a novel multi-colored doo-dad?

Why guess? I went to the trouble of getting together a spreadsheet that can definitively tell you exactly how secure you are using that password of yours. It can even give suggestions as to how to improve your password. Be warned, it’s not always pretty to see the honest truth.

Give it a try by clicking here, then click “Download”
(Updated 6/5/09)
  • Added extended data validation to prevent accidental entry of erroneous data.
  • Cleaned up the document to fix some grammatical errors
  • Added a "Galactic Years" option that gives a better frame of reference for larger passwords.
  • Additional tweaks and fixes to improve visibility and visual appeal.

(Updated 6/4/09)

I took all the comments and criticism I received and revamped the calculator to use speeds derived from the Nvidia GTX295 to calculate estimated brute force times.
Additionally I added a box at the bottom of the calculator that can be used to quickly and easily copy your score to any forum or blog you want. A solid password really is something to be proud of, show it off!

Here's my good password-
Quote:
All times relative to Nvidia GTX 295 GPU assuming ~4788000000000 Keys/Sec
Password length of 44
Total Password Entropy of 1.44648363739316E+56
Estimated time to crack:
Days 629,387,547,598,665,000,000,000,000,000,000,000,00 0,000.00
Years 1,723,205,997,972,500,000,000,000,000,000,000,000, 000.00
Centuries 17,232,059,979,725,000,000,000,000,000,000,000,000 .00
Galactic Years 7,658,693,324,322,230,000,000,000,000,000.00
BULLETPROOF password
Get this test at http://bruteforce.caedis.net
Additionally if you want to link to the calculator I have added a entry in my domain name for just such a purpose:
http://bruteforce.caedis.net
Link there if you plan to repost, don't link directly to the file. (as I have been approached by several people already about this)


What is brute force?

Brute force attacks are when your password is guessed by blindly going from one password to the next without little or no reguard for what is being tried. Bascially doing the following:
  1. a
  2. aa
  3. ab
  4. abc
  5. abc1
  6. abc11
  7. abc12
  8. abc121
  9. abc122

As you can see it’s just adding more onto the guess until it gets it right.

This method is the only remaining method to get passwords in situations where the person hasn’t put any real words or significant dates or numbers into the password.

If the person does put words or significant combinations of numbers (like anniversaries or birthdates) then a dictionary attack is usually tried first as it is exponentially faster.

When multiple combinations of common words or combinations of words/numbers are checked. This is often done first as it can sometimes take SECONDS to crack a password this way. If you have a password such as “myDogSkip” the cracker will just have to combine “my” “dog” and “Skip” into the right order to get the password. When this is especially effective is when the person knows even a little about you. Many times this is done by simply asking a friend/co-worker off-hand about some trivial part of your life. Your dogs name? Your wife’s name? or even more easily by going to your Facebook or Myspace page and getting a few key words off it. Think of all the words you use on your profile pages, then think if ANY of them could be used in any way to get a password of yours. If the answer is anything but a strong “NO” then you probably need to re-evaluate what you have secured with that weak password. Which is worse? Identity theft, or an annoying password that’s hard to type in quickly?


Originally posted on my blog at Caedis.net

System: Nova II
CPU
Core i5-750 Lynnfield
Motherboard
ASUS P7P55D Deluxe
Memory
Mushkin Enhanced Blackline 4GB (2 x 2GB)
Graphics Card
XFX 9800 GTX+ / GTS 250
Hard Drive
300GB WD SATA
Power Supply
700W
Case
Liquid Cooled Coolermaster HAF 932
CPU cooling
Liquid Cooled
GPU cooling
Reference
OS
Ubuntu 9.10, Win 7
Monitor
19" Rosewill + 40" Sony HDTV w/ DVI in

Last edited by Caedis : 06-05-09 at 01:50 PM Reason: Version 3 of the calculator
Caedis is offline   Reply With Quote
Old 06-03-09   #2 (permalink)
AMD Overclocker
 
JOKesTER's Avatar
 
Join Date: May 2009
Location: #Root
Posts: 251

Rep: 27 JOKesTER is acknowledged by some
Unique Rep: 25
Trader Rating: 0
Default

Wow - I Really Don't Get The Point Of This...

Maybe People Who Haven't Used "Noob" Programs Like "Cain And Able" Actually Don't Know This.
JOKesTER is offline   Reply With Quote
Old 06-03-09   #3 (permalink)
WaterCooler
 
intel ati

Join Date: Aug 2007
Location: Lichfield, England
Posts: 2,765

Rep: 125 Outcasst is acknowledged by manyOutcasst is acknowledged by many
Unique Rep: 115
Trader Rating: 7
Default

It says my password would take 2.7 Years to crack using an average single machine
__________________
"Aoccdrnig to rscheearch at Cmabrugde Uinervtisy, it deosn't mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist and lsat ltteer be at the rghit pclae. The rset can be a tatol meses and you can sitll raed it wouthit a porbelm. This is bcuseae the huamn mnid deos not raed ervey lteter by istlef, but the wrod as a wlohe."

System: Shattered Shield
CPU
Q6600 G0 3.6GHz 1.45v
Motherboard
Gigabyte P35-DS3R F13
Memory
8GB Crucial Ballistix DDR2
Graphics Card
4850X2 2GB
Hard Drive
Samsung 64GB SSD, WD300AAKS
Sound Card
X-Fi Extreme Music
Power Supply
Corsair 650W TX
Case
Coolermaster CM690 v2
CPU cooling
Apogee GTZ
GPU cooling
Stock
OS
Windows 7 x64
Monitor
Samsung SM226BW 22"
Outcasst is online now   Reply With Quote
Old 06-03-09   #4 (permalink)
Programmer
 
SiNiSt3r's Avatar
 
amd nvidia

Join Date: Jun 2006
Location: Maryland
Posts: 730

Rep: 61 SiNiSt3r is acknowledged by some
Unique Rep: 56
Trader Rating: 0
Default

good guide for people that don't really understand how all this stuff happens, and believe that it will never happen to them.

I can't tell you how stupid people can be with their passwords....

user: root
passsword: control

rofl
__________________
i7 920 D0 @ 4.5GhZ w/HT using the stock cooler
Current Build (in progress): i(7) CUP Underwater
90* Fittings Tested Courtsey of nafljhy


Quote:
Originally Posted by Spitphire View Post
What's coming out next?
Quote:
Originally Posted by losttsol View Post
Probably a card with 4 GPU's and 2 Fans. That will be followed in 6 months by a card with 8 GPU's, a bucket of liquid nitrogen, and a copy of Crysis 2 which won't be playable on high resolution.

System: My System
CPU
AMD Athlon X2 6400+ BE
Motherboard
M2N32-SLI Deluxe WiFi
Memory
Super Talent 4G PC6400
Graphics Card
eVGA 7900GS KO
Hard Drive
150gb WD Raptors RAID 0 750gb WD RAID 1
Power Supply
Ultra X Connect 2 550W
Case
Silverstone TJ09
OS
Vista Premium x64/ BackTrack convert to Slackware
Monitor
2x Asus VH226H 1080p 3840x1080

Last edited by SiNiSt3r : 06-03-09 at 12:52 PM
SiNiSt3r is offline   Reply With Quote
Old 06-03-09   #5 (permalink)
ZOMG Native Linux Client!
 
gonX's Avatar
 
intel nvidia

Join Date: May 2006
Location: Tampere, Finland
Posts: 20,915
Blog Entries: 10

FAQs Submitted: 1
Hardware Reviews: 15
Trader Rating: 13
Default

Mine is around 18 letters long with capitalization and numerics, so good luck cracking that
__________________
THE Mouse FAQ | 32-bit Resolution Fix | Important Information
64-Bit Driver Signing Fix | The Infraction and Warning System
My Anime Progress | The HoN Discussion Thread


Please direct all tech related questions to a thread in the respectable forums, and not to my PM inbox. Thank you

System: Certainly not the OS you'd expect
CPU
Intel Q6600 B3 @ 3 GHz
Motherboard
Gigabyte EP45-UD3P, F9b Bios
Memory
2x2048MB CorsairXMS DDR2-800 @ 500MHz 5-5-4-17
Graphics Card
Gigabyte 8800GT 512MB @ 686/1743/927
Hard Drive
3x250GB+2x200GB 4xMaxtor 1xHitachi
Sound Card
E-MU Tracker|pre USB
Power Supply
Cooler Master RS-550-ACLY 550W
Case
Antec Three Hundred
CPU cooling
Lapped Big Typhoon (stock fan) + AS5
GPU cooling
Stock
OS
Arch Linux i686
Monitor
IBM P275
gonX is offline Overclocked Account gonX's Gallery   Reply With Quote
Old 06-03-09   #6 (permalink)
AMD Overclocker
 
JOKesTER's Avatar
 
Join Date: May 2009
Location: #Root
Posts: 251

Rep: 27 JOKesTER is acknowledged by some
Unique Rep: 25
Trader Rating: 0
Default

Quote:
Originally Posted by Outcasst View Post
It says my password would take 2.7 Years to crack using an average single machine
Thats Why Dictionary Attacks Are Normally Used For Password Cracking - LOL - Not Bruteforce.
JOKesTER is offline   Reply With Quote
Old 06-03-09   #7 (permalink)
PC Gamer
 
Caedis's Avatar
 
intel nvidia

Join Date: May 2009
Location: Texas
Posts: 178

Rep: 65 Caedis is acknowledged by some
Unique Rep: 55
Trader Rating: 0
Default

Quote:
Originally Posted by JOKesTER View Post
Wow - I Really Don't Get The Point Of This...

Maybe People Who Haven't Used "Noob" Programs Like "Cain And Able" Actually Don't Know This.
If you don't get the point then you fall into one of two categories:
  1. You already know about this and it's common sense for you, in which case this isn't directed towards you.
  2. You don't care to know about this and couldn't care less about your security, in which case this isn't the right forum on OCN for you.

In either case, it's eye opening to find out how much of a beating a previously perceived as "strong" password can take before it is cracked.

System: Nova II
CPU
Core i5-750 Lynnfield
Motherboard
ASUS P7P55D Deluxe
Memory
Mushkin Enhanced Blackline 4GB (2 x 2GB)
Graphics Card
XFX 9800 GTX+ / GTS 250
Hard Drive
300GB WD SATA
Power Supply
700W
Case
Liquid Cooled Coolermaster HAF 932
CPU cooling
Liquid Cooled
GPU cooling
Reference
OS
Ubuntu 9.10, Win 7
Monitor
19" Rosewill + 40" Sony HDTV w/ DVI in
Caedis is offline   Reply With Quote
Old 06-03-09   #8 (permalink)
AMD Overclocker
 
JOKesTER's Avatar
 
Join Date: May 2009
Location: #Root
Posts: 251

Rep: 27 JOKesTER is acknowledged by some
Unique Rep: 25
Trader Rating: 0
Default

Quote:
Originally Posted by Outcasst View Post
It says my password would take 2.7 Years to crack using an average single machine
Quote:
Originally Posted by Caedis View Post
If you don't get the point then you fall into one of two categories:
  1. You already know about this and it's common sense for you, in which case this isn't directed towards you.
  2. You don't care to know about this and couldn't care less about your security, in which case this isn't the right forum on OCN for you.

In either case, it's eye opening to find out how much of a beating a previously perceived as "strong" password can take before it is cracked.
That Would Be #1
JOKesTER is offline   Reply With Quote
Old 06-03-09   #9 (permalink)
PC Gamer
 
Caedis's Avatar
 
intel nvidia

Join Date: May 2009
Location: Texas
Posts: 178

Rep: 65 Caedis is acknowledged by some
Unique Rep: 55
Trader Rating: 0
Default

Quote:
Originally Posted by Outcasst View Post
It says my password would take 2.7 Years to crack using an average single machine

Feel my wrath!


Estimated Gross Number of hours to Crack 1.09E+46 hours
On Distributed Level:
456,063,990,862,240,000,000,000,000,000,000,000,00 0,000,000.00 days

1,248,661,826,106,260,000,000,000,000,000,000,000, 000,000.00 years

12,486,618,261,062,600,000,000,000,000,000,000,000 ,000.00 centuries


44 chars of garbled alphanumeric/symbolic trash.

No joke, it's committed to muscle memory. I stumped one of my computer science professors in college by typing it out in plain text for him. His jaw dropped XD

System: Nova II
CPU
Core i5-750 Lynnfield
Motherboard
ASUS P7P55D Deluxe
Memory
Mushkin Enhanced Blackline 4GB (2 x 2GB)
Graphics Card
XFX 9800 GTX+ / GTS 250
Hard Drive
300GB WD SATA
Power Supply
700W
Case
Liquid Cooled Coolermaster HAF 932
CPU cooling
Liquid Cooled
GPU cooling
Reference
OS
Ubuntu 9.10, Win 7
Monitor
19" Rosewill + 40" Sony HDTV w/ DVI in

Last edited by Caedis : 06-03-09 at 01:19 PM Reason: quoted wrong post, man I need my cup of coffee this morning.
Caedis is offline   Reply With Quote
Old 06-03-09   #10 (permalink)
Intel Overclocker
 
intel ati

Join Date: Mar 2006
Location: Great Britain
Posts: 601

Rep: 10 antd Unknown
Unique Rep: 10
Trader Rating: 0
Default

I use KeePass for my passwords. Creates 64 character 'random' passwords using all symbols, letters and numbers for website's which allow that many

One thing that is unlikely to change fast: People using dumb dictionary passwords.

Do you know how many people put their password as 'sexy' ? XD
__________________
System: Sys
CPU
Intel Core 2 Duo E6400 @ 3.2GHz (1.4v)
Motherboard
Gigabyte DS3
Memory
2GB XMS2 Corsair 800MHz
Graphics Card
Sapphire HD4850
Hard Drive
640GB WD-AAKS + 500GB WD + 500GB Hitachi +200GB
Sound Card
Sound Blaster Audigy SE
Power Supply
450W Corsair
Case
CM690
OS
Tiny XP Christmas Edition
Monitor
Samsung 206BW
antd is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 05:14 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.16728 seconds with 8 queries