How to crack passwords, and why you should

COMMENT

Auditing passwords is a worthwhile venture, particularly in an environment that deals with sensitive information. Because systems encrypt passwords when they store them, you really can't properly judge the strength of a password unless you try to crack it.

We suggest using a password-cracking tool such as John the Ripper. This tool works extremely well because it can crack MD5 passwords, which most systems currently use. In addition, it's much faster and more sophisticated than earlier password-cracking software such as Crack.

Once you've installed the tool, either from RPM or by compiling a copy yourself, you can set it to work. Keep in mind that John the Ripper uses a fair amount of CPU, but it will only use idle CPU time. However, copying the /etc/shadow file to a nonessential machine and running the tool on that, rather than a production machine, wouldn't be a bad idea either.

If you need to stop John the Ripper, press Ctrl+C. You can resume cracking passwords from where you left off by using the following:

$ john -restore

This tool comes with a fair-sized dictionary of common passwords, which it uses by default. However, you can download any dictionary you want to use instead of, or as complement to, the existing dictionary. All you need to do is concatenate the default.lst file to the new dictionary.

In addition, it's a good idea to add words that are specific to your particular environment, including employee names, addresses, company name, etc.

To use a different dictionary than the default, use the following:

# john -wordfile:/tmp/dict.txt /etc/shadow

This runs John the Ripper against the passwords in /etc/shadow using the dictionary /etc/dict.txt.

To download the John the Ripper password cracker, visit the Openwall Project Web site.

Talkback

Having pressed on the link and tried to download the 'John the Ripper' program, my PC Antivirus (NOD32) alarms and reports that the file is a trojan.

Lets hope other unsuspecting people who are not IT literate dont install this program.

Great idea to put a link to a trojan on your website!!!!

Keep up the good word ZDNet. Please ensure you put a warning on the page to alert people and in future CHECK sources are legit.

1 Jun 05 09:01 Reply

Thats essentially an Antivirus for windows

1 Jun 05 09:19 Reply

Or you could just enforce complexity and password length along with password history.

1 Jun 05 14:46 Reply

If I'm willing to give you my password in exchange for a coupon for a cup of coffee, does it really matter how "complex" it is?

You have to wonder how many of the people who sold their passwords so cheaply did it as a way of getting back at IT security departments who'd made their lives a misery for so long.

1 Jun 05 23:12 Reply

I doubt anybody actually gave them real passwords...or gave them to "spite" an IT department. Most people don't live under such a jaded mindset as yourself. But if somone was going to give me some STarbucks for "my" password. I would come up with yet another one of "my" passwords and give it to them.

That was an insanely stupid test. Even so, back to the point of the article -- if you are cracking and revealing passwords and then somebody else knows the passwords (the pasword cracker) then why not give them away because then they are useless. Thus cracking passwords is contradictory to the spirirt of most corporate policies that forbid giving somebody else your password.

2 Jun 05 16:10 Reply

yes, yes, this is all good and well, and having downloaded this program "John the Ripper" about 5 times and trying to instal it about 17 times, i wonder why i even bothered. it's all great and lovely that it works for you, but what about the rest of us? i am at a complete loss as to how to install this thing. yes, i read the readme and install stuffs, but aparrently the files i needed weren't downloaded. i probably sound stupid and ignorent but i'm slightly agitated that it's not working for me.

28 Jun 05 02:02 Reply

I want to crack program with protoctoin
I need to learn how i can do?

17 Jul 05 17:28 Reply

Hello,
I'm Japanese. I'm not good at English.

The originap page(http://www.openwall.com/john/) with [John the Ripper 1.6 (Win32 - binaries, 763 KB)] with Trjyan.

Normal?? Abnormal??

Reading Thank you.

24 Oct 05 19:36 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

2 hours ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

2 hours ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

2 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

3 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

3 hours ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

4 hours ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

6 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

6 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

7 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

7 hours ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

miyabi81

Chatter preview http://www.zdnet.co.uk/news/application-development/2010/03/17/salesforce-opens-up-chatter-developer-preview-40088348/

cybfor

US gov t considers undercover social networking: [zdnet.co.uk] The Obama administration has considered sending... http://dlvr.it/Kh3L

sudipta_vodafone

Please give me chance in the vodafone essar Ltd as back office executive

14 hours ago by sudipta_vodafone on Vodafone culls 375 'mainly back-office' jobs
sudipta_vodafone

I want to get a back office job in vodafone direct payroll

14 hours ago by sudipta_vodafone on Vodafone culls 375 'mainly back-office' jobs
Xwindowsjunkie

I also find it harder to use. It used to scale properly in Firefox. Text would size up and down without dragging all the right edge debris with it....

18 hours ago by Xwindowsjunkie on ZDNet UK: faster, smarter, still IT all the way
dava4444

that comment bot is a nutter, it just referred me to the moderator on my own blog. shocked look. please help thank you Dava I'm afriad to...

21 hours ago by dava4444 on Welcome to the new ZDNet UK community!
dava4444

Hi Rupert! Don't think I could fill the above shoes... but if your ever looking for a consumer rights Tech blogger..tip me the wink lol peace Dava

22 hours ago by dava4444 on Fancy working for ZDNet UK?

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now