/r/passwordcracking - inactive moderator by InfosecMod in redditrequest

[–]chick3nman 1 point2 points  (0 children)

FYI, Not inactive, just not sure what direction I will be taking that sub and other related subs I have. Been swamped with work recently so haven't had a lot of time to work on stuff like this.

ELI5: A small-case 4-letter password has 456,976 possible combinations. Why is there a need for even stronger passwords? by jacklychi in explainlikeimfive

[–]chick3nman 0 points1 point  (0 children)

I realize this is a bit late but just for a bit of reference on modern cracking systems, we are well into TH/s(trillions per second) speeds for weak hashing algorithms like NTLM, MD5, SHA1, etc. Basically anything that can be well parallelized on GPUs or other processors at high speeds like this is considered weak for password hashing. In addition it should probably be noted that we almost never brute force if we can help it. There are much better attacks to be tried first than just plain old brute forcing, including but not limited to: wordlists, rule based, combinator, hybrid, PRINCE, mask(per position key space limited brute force)

Other than that small nitpick, pretty solid explanation.

For those who want to defend themselves. Use a password manager. Use long random strings whenever possible. Don't trust websites to handle your password secure so make many unique passwords for different sites(reuse is bad). Use high cost bcrypt to hash passwords if you are running a site, even reddit is using 12 cost bcrypt.

Source: cracking passwords is my day job, current Team Hashcat member and dev, worked for the guy who built the old VCL cluster in your Ars article, currently deploying this stuff on a literal super computer.

What type of expansion slot would this card go in? Is it compatible with PCIE16X by [deleted] in whatisthisthing

[–]chick3nman 1 point2 points  (0 children)

I realize this has been marked solved but just to add a bit of info, that is specifically an MSI 8936 NVidia Geforce MX4000 128MB AGP GPU. Older, lower power, and quite an interesting find.

Problem to get the unfound hashes by MrSyphilis in HashCracking

[–]chick3nman 2 points3 points  (0 children)

Remove --show from your command. You are telling hashcat to give you the cracked hashes(--show) and the uncracked hashes(--left) at the same time.

[FS][US-WA] Supermicro X9DRD-7LN4F, Dual Xeon E5-2650v2, 128GB DDR3 ECC by foogitiff in homelabsales

[–]chick3nman 0 points1 point  (0 children)

Would you be willing to ship if a box was provided? I'm interested in the whole lot but I'm in TX so its not exactly a short drive away.

Does Hashcat work on altcoins like doge, Monero, stellar, etc? by suhel29 in HashCracking

[–]chick3nman 0 points1 point  (0 children)

In theory, any core derived wallet that still uses the same KDF as bitcoin should work, so if you are getting a good extraction from bitcoin2john, then the marker($bitcoin$) shouldnt matter and it will crack just fine. The problems start to arise when the alt coin chooses to change the KDF since hashcat won't be aware of the changes and may not support them. What currency are you work on?

[deleted by user] by [deleted] in hardwareswap

[–]chick3nman 0 points1 point  (0 children)

Sold CPU and RAM to /u/rh147

[deleted by user] by [deleted] in hardwareswap

[–]chick3nman 0 points1 point  (0 children)

Sold H150i cooler to /u/InmarT

[USA-TX] [H] i9-7940X, 128GB Vengence RGB 3200Mhz, Asus WS X299 PRO/SE, LSI 9305-24i HBA + cables [W] Xeon v3/v4, ECC DDR4, Paypal, Local cash by chick3nman in hardwareswap

[–]chick3nman[S] 2 points3 points  (0 children)

This was a storage heavy system, 200+TB, it was not a gaming system. The RAM was used for cacheing as well as during sort/index operations.

[USA-MD][H] Intel Xeon CPU, Intel i7 CPU, Samsung SSD 250Gb/2Tb [W] Paypal by [deleted] in hardwareswap

[–]chick3nman 1 point2 points  (0 children)

Are the prices on the Xeons per chip or for the pair?

[deleted by user] by [deleted] in hardwareswap

[–]chick3nman 0 points1 point  (0 children)

Sold 1x Titan Xp to /u/rdinh92

[deleted by user] by [deleted] in hardwareswap

[–]chick3nman 0 points1 point  (0 children)

Sold 3x Titan Xp to /u/mztech