Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Have you heard that Unix co-founder Ken Thompson's 39-year old BSD password has finally been cracked? Learn more in an interesting The Hacker News article: . A 39-year-old login password ofKen Thompson, the co-creator of the UNIX operating system among, has finally been cracked that belongs to a BSD-based system, one of the original versions of UNIX, which was back then used by various computer science pioneers. In 2014, developer Leah Neukirchen spotted an interesting " /etc/passwd " file in a publicly available source tree of historian BSD version 3, which includes hashed passwords belonging to more than two dozens Unix luminaries who worked on UNIX development, including Dennis Ritchie, Stephen R. Bourne, Ken Thompson, Eric Schmidt, Stuart Feldman, and Brian W. Kernighan. Since all passwords in that list are protected using now-depreciated DES-based crypt(3) algorithm and limited to at most 8 characters, Neukirchen decided to brute-force them for fun and successfully cracked passwords (listed below) for almost everyone using password cracking tools like John the Ripper and hashcat. The link for this article located at The Hacker News is no longer available. . A 39-year-old access code belonging to Ken Thompson, one of the architects of the UNIX operating system, has been deciphered.. Ken Thompson, UNIX Prominence, Password Cracking Insights. . LinuxSecurity.com Team
Putting up a good and long password is advised by cybersecurity, however, cybersecurity doesn’t teach us how to identify the hacker hacking into your computer. It doesn’t matter how strong you are creating passwords, there is always be an option for hackers to crack your passwords.. The hackers nowadays have been creating well-developed algorithms, which can speed up the processes to discover your password codes. So if you are one of them who thought that putting up a tough password is a secure way to stay away from hacker then this article is just for you. Today we will discuss some password cracking techniques used by hackers to hack into our account. The link for this article located at TechViral is no longer available. . The hackers nowadays have been creating well-developed algorithms, which can speed up the processes . cybersecurity, putting, password, advised, however, doesn’t. . LinuxSecurity.com Team
A password-cracking expert has unveiled a computer cluster that can cycle through as many as 350 billion guesses per second. It's an almost unprecedented speed that can try every possible Windows passcode in the typical enterprise in less than six hours. . The five-server system uses a relatively new package of virtualization software that harnesses the power of 25 AMD Radeon graphics cards. It achieves the 350 billion-guess-per-second speed when cracking password hashes generated by the NTLM cryptographic algorithm that Microsoft has included in every version of Windows since Server 2003. As a result, it can try an astounding 958 combinations in just 5.5 hours, enough to brute force every possible eight-character password containing upper- and lower-case letters, digits, and symbols. Such password policies are common in many enterprise settings. . Revealing an innovative system that decodes iOS backups at an astonishing rate, posing a serious threat to personal data privacy.. Password Cracking, Computing Cluster, AMD Radeon, Virtualization, Enterprise Security. . LinuxSecurity.com Team
Popular Wi-Fi password cracking tool Backtrack . The Kali distribution includes Metasploit, Wireshark, John the Ripper, Nmap, Aircrack-ng, and others to provide a security testing suite you can easily boot up from a Live CD. The distribution comes in not only 32- and 64-bit flavors, but also works with ARM-based systems as well. That means Kali can run on some Chromebooks and even the Raspberry Pi. Check out the Kali site for the official downloads and more information.. Kali Linux provides resources such as Nmap and Burp Suite for efficient vulnerability assessments and network monitoring.. Kali Linux, Penetration Testing Tools, Password Cracking Techniques. . LinuxSecurity.com Team
I was talking last week to my friend HD Moore who founded and leads the development team for Metasploit at Rapid7. He told me about yet another open source project that Rapid7 has been supporting with financial and engineering support. The venerable John-the-Ripper password cracking project has been the recipient of support from Rapid7 for about a year now, culminating in the latest release which was recently announced. . John-the-Ripper which is the standard in the security/password cracking world, is part of Openwall. There are actually quite a number of open source security projects under the Openwall umbrella. Openwall itself is the granddaddy of security Linux distributions. Many of today's "secure" Linux distributions like SELinux and EnGarde have some of the Openwall DNA. But in addition, Openwall also handles things like crypt blowfish, the popular password hashing algorithm and many other open source security projects. The news of Rapid7's support was also announced on the Rapid7 community boards last week as well. Rapid7 has developed a history of supporting open source security projects. It gave a home to HD Moore and the Metasploit team about 2 years ago. Since then Rapid7 has also begun to sell the Metasploit Pro commercial product based on the open source Metasploit project. To their credit they have also continued to develop and distribute a robust open source version of the product as well. . Rapid7 enhances open source projects like John-the-Ripper, strengthening security tools and community contributions.. John-the-Ripper Support, Open Source Contributions, Rapid7 Support. . LinuxSecurity.com Team
As we reported earlier today, Amazon is now offering a Cluster GPU Instance. Security blogger Thomas Roth decided to find out how quickly the system could be used to crack SHA1 hashes. He was able to crack 14 hashes with passwords ranging in length from one to six characters in 49 minutes. "This just shows one more time that SHA1 is deprecated," he writes. . "You really don't want to use it anymore!" Roth shares his process in this post. In the comments he notes the cost of cracking the passwords was only between four and five dollars. Last summer, mainstream media outlets like the BBC began reporting what security company Elcomsoft had known for years: GPUs are highly efficient password cracking machines. The link for this article located at ReadWriteHack is no longer available. . Discover the methods Thomas Roth implemented leveraging Amazon's GPU resources to effectively decipher passwords, highlighting the vulnerabilities associated with SHA1 encryption.. Password Cracking, Cloud Security, SHA1 Hashing, GPU Instances, Security Techniques. . Anthony Pell
Instead of indicating password quality via coloured bars, the Windows crypto tool Thor's Godly Privacy (TGP) informs users about the estimated time required for a successful brute-force attack on the chosen password. TGP calculates the time from the number of iterations a brute-force tool would need to arrive at the correct character combination.. The calculation is based on a Class F attack with a throughput of 1 billion passwords per second and a key space of 96 that contains all lower and upper case letters as well as all numbers and special characters, brackets etc (961 + 962 + 963 + 964 + ...). However, TGP not only returns the time required for trying out the entire key space, it also gives an estimated time for the specific password in question; 10 The link for this article located at H Security is no longer available. . The calculation is based on a Class F attack with a throughput of 1 billion passwords per second and. instead, indicating, password, quality, coloured, windows, crypto, thor's, godly, priva. . LinuxSecurity.com Team
The security specialist Objectif S. Oechslin has fitted an elderly Athlon 64 X2 4400+ with an SSD and the optimised tables. This system can, with only a 75% CPU utilisation, crack a 14 digit password with special characters, in an average of 5.3 seconds. Oechslin says that, worst case, it should be able to search arithmetically through 300 billion passwords per second, a speed that is a factor of 500 faster than an Elcomsoft cracker supported by a modern Tesla GPU from NVIDIA. The link for this article located at H Security is no longer available. . Oechslin has fitted an elderly Athlon 64 X2 4400+ with an SSD and the optimised tables. This system . security, specialist, objectif, oechslin, fitted, elderly, athlon, 4400+. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.