Cheap GPUs can crack password faster than a CPU

utorrent

Intermediate
Oct 28, 2010
236
0
21
پشاور
[from ZD net]
http://www.zdnet.com/blog/hardware/cheap...less/13125

Think that your eight-character password consisting of lowercase characters, uppercase characters and a sprinkling of numbers is strong enough to protect you from a brute force attack?

Think again!

Jon Honeyball writing for PC Pro has a sobering piece on how the modern GPU can be leveraged as a powerful tool against passwords once considered safe from bruteforce attack.

Take a cheap GPU (like the Radeon HD 5770) and the free GPU-powered password busting tool called ’ighashgpu‘ and you have yourself a lean, mean password busting machine. How lean and mean? Very:

The results are startling. Working against NTLM login passwords, a password of “fjR8n” can be broken on the CPU in 24 seconds, at a rate of 9.8 million password guesses per second. On the GPU, it takes less than a second at a rate of 3.3 billion passwords per second.

Increase the password to 6 characters (pYDbL6), and the CPU takes 1 hour 30 minutes versus only four seconds on the GPU. Go further to 7 characters (fh0GH5h), and the CPU would grind along for 4 days, versus a frankly worrying 17 minutes 30 seconds for the GPU.

It gets worse. Throw in a nine-character, mixed-case random password, and while a CPU would take a mind-numbing 43 years to crack this, the GPU would be done in 48 days.

Surely throwing symbols in there keeps you safe, right? Wrong! Take a password consisting of seven characters, mixed-case/symbols random password like ‘F6&B is’ (note the space), that’s gotta be tough for a bruteforce attack. Right? A CPU will take some 75 days to churn through the possibilities, while a GPU is done with it in 7 hours.

What’s the solution? Well, Honeyball doesn’t know, and neither do I to be perfectly honest. What I do know is that this is a warning, and one that we need to take seriously. Unless we’re willing to move onto 15-16 characters, mixed-case/symbols random password (which will end up on Post-It Notes), passwords will soon only offer protection against honest people.
 

kingsface

DL_xICEMANx
Jan 17, 2009
3,567
0
41
Lahore
Interesting. The difference is near a billion of password guesses between CPU and gpu.


Sent from my iPod touch using Tapatalk
 

deltree

Well-known member
Jun 8, 2008
1,209
0
41
KHI
Its not as fast as written iv tried it few days ago in an urgent situation with a 9600gt and brute forcing a password protected rar with 8 characters plus numbers was not a good time frame! Or should I say was not part of this lifetime! And I used multiple softwares....hash cracking is easier, hire a amazon ec2 cloud server for a day and you could break apart the worlds most complex passwords in no time that also includes wpa2 cracking!
 

sl33py

Beginner
Jan 20, 2010
27
0
1
Since a GPU consists of a large number of relatively simpler cores it's no wonder it is faster than most CPU's, since it can work in parallel.
 

my3m

Well-known member
Sep 23, 2010
1,315
0
41
yar is say betr 4x GTX 590 lagalo phr 15 characters ko 10mint mein crack kero
 

Negotiator

Adventurer
May 17, 2010
29
0
1
Between Heaven & Hell
if medusa or hydra brute force can use it(when i have some proper hardware than i will check myself)than this is really bad news for dsl users and more for us to create proper security
[from ZD net]
http://www.zdnet.com/blog/hardware/cheap...less/13125

Think that your eight-character password consisting of lowercase characters, uppercase characters and a sprinkling of numbers is strong enough to protect you from a brute force attack?

Think again!

Jon Honeyball writing for PC Pro has a sobering piece on how the modern GPU can be leveraged as a powerful tool against passwords once considered safe from bruteforce attack.

Take a cheap GPU (like the Radeon HD 5770) and the free GPU-powered password busting tool called ’ighashgpu‘ and you have yourself a lean, mean password busting machine. How lean and mean? Very:

The results are startling. Working against NTLM login passwords, a password of “fjR8n” can be broken on the CPU in 24 seconds, at a rate of 9.8 million password guesses per second. On the GPU, it takes less than a second at a rate of 3.3 billion passwords per second.

Increase the password to 6 characters (pYDbL6), and the CPU takes 1 hour 30 minutes versus only four seconds on the GPU. Go further to 7 characters (fh0GH5h), and the CPU would grind along for 4 days, versus a frankly worrying 17 minutes 30 seconds for the GPU.

It gets worse. Throw in a nine-character, mixed-case random password, and while a CPU would take a mind-numbing 43 years to crack this, the GPU would be done in 48 days.

Surely throwing symbols in there keeps you safe, right? Wrong! Take a password consisting of seven characters, mixed-case/symbols random password like ‘F6&B is’ (note the space), that’s gotta be tough for a bruteforce attack. Right? A CPU will take some 75 days to churn through the possibilities, while a GPU is done with it in 7 hours.

What’s the solution? Well, Honeyball doesn’t know, and neither do I to be perfectly honest. What I do know is that this is a warning, and one that we need to take seriously. Unless we’re willing to move onto 15-16 characters, mixed-case/symbols random password (which will end up on Post-It Notes), passwords will soon only offer protection against honest people.
 

Konvict

Intermediate
Dec 13, 2010
221
0
21
Islamabad/Rawalpindi
There is a very simple way to protect us against this threat when talking about passwords for emails and social networking sites!
They can put a limit of entering a password and then block your ability to try again!
That way the software might not be able to enter all the possibilities in one go!

By the way these password cracking softwares are all based on the C and P system of mathematics i guess!
right?
 
General chit-chat
Help Users
We have disabled traderscore and are working on a fix. There was a bug with the plugin | Click for Discord
  • No one is chatting at the moment.
  • Necrokiller Necrokiller:
    Jeez, throwing all those sales away for the sake of PsN accounts. What a mess.
    Link
  • Link
  • Chandoo Chandoo:
    faraany3k said:
    I have heard that it is now unplayable in countries which do not support handful of third world countries not recognized by Sony like Pakistan. Steam is a true global platform.Then they cry that console gaming is dying.
    170 + countries where Steam sells but PSN doesn't will lose access unless they use VPN
    Link
  • Chandoo Chandoo:
    It has a worst rating on Steam than last years MW3 now. Jeese Sony, how can you fuck it up THIS BAD
    Link
  • faraany3k faraany3k:
    I have heard that it is now unplayable in countries which do not support handful of third world countries not recognized by Sony like Pakistan. Steam is a true global platform.Then they cry that console gaming is dying.
    Link
  • Chandoo Chandoo:
    How to ruin a perfectly good thing for dummies - by Sony
    Link
  • Link
  • Chandoo Chandoo:
    Helldivers 2 is now trending worse stream user reviews than SUICIDE SQUAD
    Link
  • Necrokiller Necrokiller:
    Good guy Gaben refunding the game way past what the policy allows 👍
    Link
  • Necrokiller Necrokiller:
    Poor Arrowhead getting screwed by Sony 😞
    Link
  • Necrokiller Necrokiller:
    Gaben ki reach hai, PSN ki nahi hai. Gaben ain't stressing over publishers who rush to his store in the first place 😂
    Link
  • Chandoo Chandoo:
    Gaben ki reach nah hai :(
    Link
  • Chandoo Chandoo:
    saeen I don't think the PSN teams are stressing over needing to offer hundreds of thousands of refunds lol
    Link
  • Necrokiller Necrokiller:
    fuckin' lol
    Link
  • Necrokiller Necrokiller:
    Saeen literally glossed over the fact that PSN isn't available in those 177 countries
    Link
  • Chandoo Chandoo:
    fuckin' lol
    Link
  • Chandoo Chandoo:
    Helldivers 2 delisted on Steam from 177 countries
    Link
  • Necrokiller Necrokiller:
    iampasha said:
    Alan wake 2 is yet to recover it's development costs. Due to no physical release and no steam launch.
    You reap what you sow. This is what happens when you take away choice from consumers. Even with 88% split going to developers, they can't recoup costs. Meanwhile, Helldivers 2 is a massive hit for Sony thanks in big part to Steam.
    Link
  • iampasha iampasha:
    Alan wake 2 is yet to recover it's development costs. Due to no physical release and no steam launch.
    • Haha
    Reactions: Necrokiller
    Link
  • NaNoW NaNoW:
    ....
    Link
  • faraany3k faraany3k:
    Tears of Kingdom saal pehle shuru ki thee, ab tk pehle area se nai nikla. Life sucks donkey balls.
    Link
  • Necrokiller Necrokiller:
    Buh buh buh didn't you know that "sT3aM iS a moN0-pololly" 🤣
    • Haha
    Reactions: iampasha and EternalBlizzard
    Link
  • EternalBlizzard EternalBlizzard:
    You can't defeat Lord Gaben :ROFLMAO:
    • Haha
    Reactions: Necrokiller
    Link
  • Necrokiller Necrokiller:
    Hmmmmm
    Link
  • Necrokiller Necrokiller:
    Link
    Necrokiller Necrokiller: Jeez, throwing all those sales away for the sake of PsN accounts. What a mess.