As you have heard,
Brian Krebs recently audited passwords obtained after hacking antichat.ru (the base itself was received about a year ago and is no longer relevant!). Honestly, I don’t really understand what his video cards did for 18 days, winning only 44% of passwords. I managed to pick up
77% of passwords on a fairly modest iron in
8 hours . Based on these somewhat frightening numbers, especially for a thematically related information security site, I have several recommendations on which passwords should never be used so that they are not picked up in a couple of minutes.
I used
The UDC utility, which I created myself (by the way, at the moment it
is available free-of-charge ), it does not support calculations on video cards and on my E8400 goes through an average of 5 million passwords per second (just to avoid the illusion that brute force only determines the speed). As a result, I found 31790 passwords from 41037 MD5 hashes. How did I do it?
Numbers
. 11 . , - ( ). - , - , - .
, , .
15759 ! . - .
- , « », 20, . . , - .
; , « ». , 15759 , . ,
123
,
1111
( ). , N ( 50000), .
( « »),
1111111111123123
. :
358 .
: - — . . «qwerty» «password»., 7 .
5767 .
, , .
— - - «». .
:
- -
- CAPS LOCK
- + (2010, 2011, etc.)
- + (123, 1111, etc.)
- /
- «» («one» -> «1», «s» -> "$", «a» -> "@", etc.)
- ( )
- , 40 , .
5213 .
: «» , . , , , ., , , 20 , , — .
, 27097 ( - ), . , , . , «» , .
, , , 10000 . .
. 7
4693 . «»
1234
951753
.
: , , . no one is safe.( )
123321123321123
— , .
1qaz2wsx3edc
— .
123456610q
— , , , , .
ilovepussy777
— ; + , .
[fuckitall]
— , [...] , .
Hellsp@wn
— , @ , .
Jhnjgtl12
— ? .
dalex3pro
— d + + + . pro - .
PANASONIC13
— ? .
iphone3g
— . -, .
qCkiYSJ625
— , , .
UPD:, , , !
, - . .