<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>What&#039;s My Pass? &#187; Unix</title>
	<atom:link href="http://www.whatsmypass.com/tag/unix/feed" rel="self" type="application/rss+xml" />
	<link>http://www.whatsmypass.com</link>
	<description>Password Recovery for Windows, Mac, Linux, browsers, email, instant messengers, BIOS</description>
	<lastBuildDate>Tue, 24 Jan 2012 16:08:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Password Exploitation Class Videos</title>
		<link>http://www.whatsmypass.com/password-exploitation-class-videos</link>
		<comments>http://www.whatsmypass.com/password-exploitation-class-videos#comments</comments>
		<pubDate>Tue, 31 Aug 2010 02:47:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Matthew Shoemaker Memorial Fund]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Wireless profile passwords]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/password-exploitation-class-videos</guid>
		<description><![CDATA[The Password Exploitation Class was put on as a charity event for the Matthew Shoemaker Memorial Fund . The speakers were Dakykilla, Purehate_ and Irongeek. Lots of password finding and crack topics were covered. Hashcat, OCLHashcat, Cain, SAMDump2, Nir&#8217;s Password Recovery Tools, Password Renew, Backtrack 4 R1, UBCD4Win and much more. Part 1: Topics include: [...]]]></description>
			<content:encoded><![CDATA[<p>The Password Exploitation Class was put on as a charity event for the <a href="http://www.shoecon.org">Matthew Shoemaker Memorial Fund </a>. The speakers were Dakykilla, <a href="http://www.question-defense.com">Purehate_</a> and <a href="http://www.irongeek.com/">Irongeek</a>.</p>
<p>Lots of password finding and crack topics were covered. Hashcat, OCLHashcat, Cain, SAMDump2, Nir&#8217;s Password Recovery Tools, Password Renew, Backtrack 4 R1, UBCD4Win and much more.<br />
<span id="more-1018"></span></p>
<p>Part 1: Topics include: Why exploit local passwords?, Scenario:Imaged Systems, Grabbing local passwords, Hash Examples, Great Resources, Platforms Used: Ubuntu, Backtrack, UBCD4Win, Windows Profile, Windows System Trifecta, Anti-Virus Pains, Getting an account/changing an account password, hash insertion, Sala&#8217;s Password Renew, Keyloggers, Boot CD demos, SAMDump2, Browser Passwords, IE, Firefox Etc., PSPV, PasswordFox, IE Passview, ChromePass, RDP and VNC password grabbing, Instant Messaging, Stupid Web Apps rant, AOA: Any Old Asterisks (stuff hidden by Asterisks), Network Shares stored passwords, Outlook PST password cracking and hash collision example, Wireless profile passwords, WirelessKeyView, Sniffing them off the wire with Wireshard and Cain.<br />
<a href="http://www.archive.org/download/PasswordExploitationClass/passwordclass1.avi">Download Class 1</a></p>
<p>Part 2: The best single video out there for showing Hashcat and OCLHashcat. Lots of info about using Hashcat/OCLHashcat, its advantages, and the power of a video card to boost cracking speed.<br />
<a href="http://www.archive.org/download/PasswordExploitationClass/passwordclass2.avi">Download Class 2</a></p>
<p>Part 3: Windows LM and NTLM hash cracking, Time Memory Tradeoffs, SAM Cracking Prevention, Linux/Unix passwd and shadow files, Parts of a *nix hash, Windows Cached Domain Credentials, Problems with Windows 7, Cracking Creds Countered, Finding where Unknown Apps store passwords, System Process Monitoring, RegFromApp, ProcessActivityView, Procmon (Process Monitor), finding the hash type, Other Weird Vectors, Inverse Bruteforce, Look in the logs for passwords, upcoming events.<br />
<a href="http://www.archive.org/download/PasswordExploitationClass/passwordclass3.avi">Download Class 3</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/password-exploitation-class-videos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.archive.org/download/PasswordExploitationClass/passwordclass2.avi" length="245204672" type="video/x-msvideo" />
<enclosure url="http://www.archive.org/download/PasswordExploitationClass/passwordclass1.avi" length="340141508" type="video/x-msvideo" />
<enclosure url="http://www.archive.org/download/PasswordExploitationClass/passwordclass3.avi" length="200843330" type="video/x-msvideo" />
		</item>
		<item>
		<title>Password Cracking Guide</title>
		<link>http://www.whatsmypass.com/password-cracking-guide</link>
		<comments>http://www.whatsmypass.com/password-cracking-guide#comments</comments>
		<pubDate>Wed, 24 Mar 2010 15:06:24 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[Password Info]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Cracking Office]]></category>
		<category><![CDATA[GPU]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Novell NetWare]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[WEP]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/password-cracking-guide</guid>
		<description><![CDATA[This pdf document is for people who want to learn to the how and why of password cracking. There is a lot of information being presented and you should READ IT ALL BEFORE you attempted doing anything documented here. Here is the table of contents 1 LM vs. NTLM 2 Syskey 3 Cracking Windows Passwords [...]]]></description>
			<content:encoded><![CDATA[<p>This pdf document is for people who want to learn to the how and why of password cracking. There is a lot of information being presented and you should READ IT ALL BEFORE you attempted doing anything documented here.<span id="more-912"></span><br />
Here is the table of contents</p>
<pre>1 LM vs. NTLM
2 Syskey
3 Cracking Windows Passwords
   3.1 Extracting the hashes from the Windows SAM
      3.1.1 Using BackTrack Tools
         3.1.1.1 Using bkhive and samdump v1.1.1 (BT2 and BT3)
         3.1.1.2 Using samdump2 v2.0.1 (BT4)
         3.1.1.3 Cached Credentials
      3.1.2 Using Windows Tools
         3.1.2.1 Using fgdump
         3.1.2.2 Using gsecdump
         3.1.2.3 Using pwdump7
         3.1.2.4 Cached Credentials
   3.2 Extracting the hashes from the Windows SAM remotely
      3.2.1 Using BackTrack Tools
         3.2.1.1 ettercap
      3.2.2 Using Windows Tools
         3.2.2.1 Using fgdump
   3.3 Cracking Windows Passwords
      3.3.1 Using BackTrack Tools
         3.3.1.1 John the Ripper BT3 and BT4
            3.3.1.1.1 Cracking the LM hash
            3.3.1.1.2 Cracking the NTLM hash
            3.3.1.1.3 Cracking the NTLM using the cracked LM hash
            3.3.1.1.4 Cracking cached credentials
         3.3.1.2 John the Ripper - current
            3.3.1.2.1 Get and Compile
            3.3.1.2.2 Cracking the LM hash
            3.3.1.2.3 Cracking the LM hash using known letter(s) in known location(s) (knownforce)
            3.3.1.2.4 Cracking the NTLM hash
            3.3.1.2.5 Cracking the NTLM hash using the cracked LM hash (dumbforce)
            3.3.1.2.6 Cracking cached credentials
         3.3.1.3 Using MDCrack
            3.3.1.3.1 Cracking the LM hash
            3.3.1.3.2 Cracking the NTLM hash
            3.3.1.3.3 Cracking the NTLM hash using the cracked LM hash
         3.3.1.4 Using Ophcrack
            3.3.1.4.1 Cracking the LM hash
            3.3.1.4.2 Cracking the NTLM hash
            3.3.1.4.3 Cracking the NTLM hash using the cracked LM hash
      3.3.2 Using Windows Tools
         3.3.2.1 John the Ripper
            3.3.2.1.1 Cracking the LM hash
            3.3.2.1.2 Cracking the NTLM hash
            3.3.2.1.3 Cracking the NTLM hash using the cracked LM hash
            3.3.2.1.4 Cracking cached credentials
         3.3.2.2 Using MDCrack
            3.3.2.2.1 Cracking the LM hash
            3.3.2.2.2 Cracking the NTLM hash
            3.3.2.2.3 Cracking the NTLM hash using the cracked LM hash
         3.3.2.3 Using Ophcrack
            3.3.2.3.1 Cracking the LM hash
            3.3.2.3.2 Cracking the NTLM hash
            3.3.2.3.3 Cracking the NTLM hash using the cracked LM hash
         3.3.2.4 Using Cain and Abel
      3.3.3 Using a Live CD
         3.3.3.1 Ophcrack
4. Changing Windows Passwords
   4.1 Changing Local User Passwords
      4.1.1 Using BackTrack Tools
         4.1.1.1 chntpw
      4.1.2 Using a Live CD
         4.1.2.1 chntpw
         4.1.2.2 System Rescue CD
   4.2 Changing Active Directory Passwords
5 plain-text.info
6 Cracking Novell NetWare Passwords
7 Cracking Linux/Unix Passwords
8 Cracking networking equipment passwords
   8.1 Using BackTrack tools
      8.1.1 Using Hydra
      8.1.2 Using Xhydra
      8.1.3 Using Medusa
      8.1.4 Using John the Ripper to crack a Cisco hash
   8.2 Using Windows tools
      8.2.1 Using Brutus
9 Cracking Applications
   9.1 Cracking Oracle 11g (sha1)
   9.2 Cracking Oracle passwords over the wire
   9.3 Cracking Office passwords
   9.4 Cracking tar passwords
   9.5 Cracking zip passwords
   9.6 Cracking pdf passwords
10 Wordlists aka Dictionary attack
   10.1 Using John the Ripper to generate a wordlist
   10.2 Configuring John the Ripper to use a wordlist
   10.3 Using crunch to generate a wordlist
   10.4 Generate a wordlist from a textfile or website
   10.5 Using premade wordlists
   10.6 Other wordlist generators
   10.7 Manipulating your wordlist
11 Rainbow Tables
   11.1 What are they?
   11.2 Generating your own
      11.2.1 rcrack - obsolete but works
      11.2.2 rcracki
      11.2.3 rcracki - boinc client
      11.2.4 Generating a rainbow table
   11.3 WEP cracking
   11.4 WPA-PSK
      11.4.1 airolib
      11.4.2 pyrit
12 Distributed Password cracking
   12.1 john
   12.2 medussa (not a typo this is not medusa)
13 using a GPU
   13.1 cuda - nvidia
   13.2 stream - ati</pre>
<p><a href="http://tools.question-defense.com/Cracking_Passwords_Guide.pdf">Cracking_Passwords_Guide.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/password-cracking-guide/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hashcat v0.30</title>
		<link>http://www.whatsmypass.com/hashcat-v0-30</link>
		<comments>http://www.whatsmypass.com/hashcat-v0-30#comments</comments>
		<pubDate>Mon, 28 Dec 2009 04:19:47 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[Files]]></category>
		<category><![CDATA[Force Attack]]></category>
		<category><![CDATA[Gentoo]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=837</guid>
		<description><![CDATA[A new multi-platform password cracking tool hashcat was just released publicly. Tested on XP, Win7, Gentoo, Debian The main features of hashcat are: * It is free. * Native binaries for Linux and Windows. * Multi-threaded. * Supports the following hashes: * MD5 * md5($pass.$salt) * md5($salt.$pass) * md5(md5($pass)) * md5(md5(md5($pass))) * md5(md5($pass).$salt) * md5(md5($salt).$pass) [...]]]></description>
			<content:encoded><![CDATA[<p>A new multi-platform password cracking tool hashcat was just released publicly.<br />
Tested on XP, Win7, Gentoo, Debian</p>
<p>The main features of hashcat are:</p>
<p>* It is free.<br />
* Native binaries for Linux and Windows.<br />
* Multi-threaded.<br />
<span id="more-837"></span><br />
* Supports the following hashes:</p>
<p>    * MD5<br />
    * md5($pass.$salt)<br />
    * md5($salt.$pass)<br />
    * md5(md5($pass))<br />
    * md5(md5(md5($pass)))<br />
    * md5(md5($pass).$salt)<br />
    * md5(md5($salt).$pass)<br />
    * md5($salt.md5($pass))<br />
    * md5($salt.$pass.$salt)<br />
    * md5(md5($salt).md5($pass))<br />
    * md5(md5($pass).md5($salt))<br />
    * md5($salt.md5($salt.$pass))<br />
    * md5($salt.md5($pass.$salt))<br />
    * md5($username.0.$pass)<br />
    * md5(strtoupper(md5($pass)))<br />
    * SHA1<br />
    * sha1($pass.$salt)<br />
    * sha1($salt.$pass)<br />
    * sha1(sha1($pass))<br />
    * sha1(sha1(sha1($pass)))<br />
    * MySQL<br />
    * MySQL4.1/MySQL5<br />
    * MD5(WordPress)<br />
    * MD5(phpBB3)<br />
    * MD5(Unix)<br />
    * SHA-1(Base64)<br />
    * SSHA-1(Base64)</p>
<p>* Supports the following attacks:</p>
<p>    * Straight-Words Attack<br />
    * Combination-Words Attack<br />
    * Toggle-Case Attack<br />
    * Brute-Force Attack</p>
<p>* All Attack-Modes except Brute-Force can be extended by Hybrid-Attack rules.<br />
* Hybrid-Attack engine is mostly compatible with JTR / PasswordsPro.<br />
* Possible to resume or limit session.</p>
<p>It also has some special features:</p>
<p>* Automatically recognizes already recovered hashes from outfile at startup.<br />
* Automatically generate random rules for Hybrid-Attack.<br />
* Load hashlist that include more than 3 million hashes of any supported type at once.<br />
* Load saltlist from external file and then use them in a Brute-Force Attack variant.<br />
* Able to work in an distributed environment.</p>
<p>There are some more things you should know:</p>
<p>* You can specify multiple wordlists and also multiple directories of wordlists.<br />
* Number of threads can be configured.<br />
* Threads run on lowest priority.</p>
<p>Get It Here: <a href="http://hashcat.net/hashcat/#downloadlatest">hashcat</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/hashcat-v0-30/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>30 years of failure: the username/password combination</title>
		<link>http://www.whatsmypass.com/30-years-of-failure-the-usernamepassword-combination</link>
		<comments>http://www.whatsmypass.com/30-years-of-failure-the-usernamepassword-combination#comments</comments>
		<pubDate>Wed, 14 Oct 2009 16:41:46 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Human Factors and Ergonomics Society]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Unix]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/30-years-of-failure-the-usernamepassword-combination</guid>
		<description><![CDATA[A new study, which is being published in the Proceedings of the Human Factors and Ergonomics Society, details just how long we&#8217;ve been aware of the password problem. It cites a study of Unix passwords from 1979, which showed that about 30 percent of the passwords were four characters or less, and about 15 percent [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.hfes.org/web/Newsroom/HFES09-Hoonaker-CIS.pdf">new study</a>, which is being published in the Proceedings of the Human Factors and Ergonomics Society, details just how long we&#8217;ve been aware of the password problem. It cites a study of Unix passwords from 1979, which showed that about 30 percent of the passwords were four characters or less, and about 15 percent being words that appear in the dictionary. Fast forward to 2006, when a separate survey of 34,000 MySpace passwords revealed that the most common were &#8220;password1&#8243;, &#8220;abc123&#8243;, &#8220;myspace1&#8243;, and &#8220;password&#8221;. </p>
<p>src: <a href="http://arstechnica.com/business/news/2009/10/30-years-of-failure-the-user-namepassword-combination.ars">arstechnica.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/30-years-of-failure-the-usernamepassword-combination/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Mac Security: Set a Firmware Password</title>
		<link>http://www.whatsmypass.com/mac-security-set-a-firmware-password</link>
		<comments>http://www.whatsmypass.com/mac-security-set-a-firmware-password#comments</comments>
		<pubDate>Wed, 03 Jun 2009 04:34:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[firmware]]></category>
		<category><![CDATA[firmware chips]]></category>
		<category><![CDATA[Leopard]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Mac OS X 10.5]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Unix]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=653</guid>
		<description><![CDATA[The biggest risk to your Mac is if it is lost, stolen or physically compromised. If you setup a secure password as discussed previously and the thief can’t login, they can still gain access to all your data using one of the special start-up modes built into all Macs. These start-up modes include booting from [...]]]></description>
			<content:encoded><![CDATA[<p>The biggest risk to your Mac is if it is lost, stolen or physically compromised. If you setup a secure password as discussed previously and the thief can’t login, they can still gain access to all your data using one of the special start-up modes built into all Macs.</p>
<p>These start-up modes include booting from an install DVD and resetting the password, using Target Disk Mode to use your Mac as an external hard disk, or booting into Unix-style Single User Mode.</p>
<p>There is a way to protect your computer by setting a firmware password. The password is written into the computer’s firmware chips on the motherboard and if anyone tries to use a special start-up mode, they will be prompted for that password.</p>
<p>Apple provides a utility for setting a firmware password called <strong>Firmware Password Utility</strong>.</p>
<p>For Mac OS X 10.5.x, start from the Leopard Install DVD and choose <strong>Firmware Password Utility</strong> from the <strong>Utilities</strong> menu.</p>
<p>1. Click to select the checkbox for “Require password to change Open Firmware settings”, as shown below.</p>
<p><img class="aligncenter size-full wp-image-687" title="20090601_firmwarepassword" src="http://mac101.net/files/2009/06/20090601_firmwarepassword.png" alt="Tips &amp; Tricks: Mac Security Fixes: Set a Firmware Password" width="420" height="292" /></p>
<p>2. Type your password in the Password and Verify fields.</p>
<p>3. Click <strong>OK</strong></p>
<p>4. Click <em><strong>lock icon</strong></em> to prevent further changes</p>
<p>5. Choose <strong>Quit</strong> from the application menu</p>
<p>Now, if anyone attempts to use any of the special start-up modes, they will be prompted for the firmware password you set.</p>
<p>via: <a href="http://mac101.net/content/how-to/tips-tricks-mac-security-fixes-set-a-firmware-password/">mac101.net</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/mac-security-set-a-firmware-password/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>GPU Cracking wars have begun&#8230;</title>
		<link>http://www.whatsmypass.com/gpu-cracking-wars-have-begun</link>
		<comments>http://www.whatsmypass.com/gpu-cracking-wars-have-begun#comments</comments>
		<pubDate>Sat, 04 Oct 2008 02:01:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Password Info]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[acceleration technology]]></category>
		<category><![CDATA[Acrobat]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[computational-heavy processing]]></category>
		<category><![CDATA[Distributed Password Recovery]]></category>
		<category><![CDATA[ElcomSoft]]></category>
		<category><![CDATA[GeForce GTX280]]></category>
		<category><![CDATA[GPU]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[nVidia]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[regular Core2Duo processors]]></category>
		<category><![CDATA[U.S. Securities and Exchange Commission]]></category>
		<category><![CDATA[Unix]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=243</guid>
		<description><![CDATA[ElcomSoft Claims 1 Billion Passwords/Sec Recovery; Uses GPUs in Parallel Distributes tasks to multiple NVIDIA video accelerators ElcomSoft has released a new version its Distributed Password Recovery program for recovering system and document passwords at speeds of up to 1 billion passwords per second. Among the passwords the software can recover are system passwords such [...]]]></description>
			<content:encoded><![CDATA[<p>ElcomSoft Claims 1 Billion Passwords/Sec Recovery; Uses GPUs in Parallel<br />
Distributes tasks to multiple NVIDIA video accelerators</p>
<p><a href="http://www.elcomsoft.com/">ElcomSoft</a> has released a new version its <a href="http://gpu.elcomsoft.com/">Distributed Password Recovery</a> program for recovering system and document passwords at speeds of up to 1 billion passwords per second. <span id="more-243"></span>Among the passwords the software can recover are system passwords such as NTLM (Windows logon passwords) and startup passwords, MD5 hashes, password-protected documents created by Microsoft Office 97-2007, PDF files created by Adobe Acrobat, as well as PGP, UNIX, and Oracle.</p>
<p>What&#8217;s interesting about the ElcomSoft approach is that the company is using multiple GPU-based video cards such as NVIDIA&#8217;s <a href="http://www.nvidia.com/object/geforce_gtx_280.html">GeForce GTX280</a> in parallel to process hundreds of billions fixed-point calculations per second. This means, says ElcomSoft, that this release of the Distributed Password Recovery program can try around 5,000 passwords per second for Office 2007 documents with a single GeForce GTX260, while regular Core2Duo processors can only try up to 200 passwords per second.</p>
<p>ElcomSoft claims that all users have to do is insert into a PC video cards (like the GeForce GTX280) to take advantage of the capabilities. Unlike NVIDIA <a href="http://www.nvidia.com/object/quadro_sli_mosaic_mode.html">SLI mode</a> (Scan Line Interleaving) that enables transparent use of multiple GPUs, ElcomSoft uses the computational power of several NVIDIA cards no matter if they are of the same kind. Currently supporting all GeForce 8 and GeForce 9 boards, the acceleration technology offloads parts of computational-heavy processing onto the fast and highly scalable processors featured in the NVIDIA&#8217;s graphic accelerators.</p>
<p>The acceleration technology developed by ElcomSoft allows the execution of mathematically intensive password recovery code on the massively parallel computational elements found in NVIDIA graphic accelerators. The GPU acceleration is unique to Elcomsoft Distributed Password Recovery, making password recovery up to 50 times faster compared to password recovery methods that only use the computer&#8217;s main CPU.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/gpu-cracking-wars-have-begun/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DriveCrypt Security Model bypass</title>
		<link>http://www.whatsmypass.com/drivecrypt-security-model-bypass</link>
		<comments>http://www.whatsmypass.com/drivecrypt-security-model-bypass#comments</comments>
		<pubDate>Thu, 25 Sep 2008 16:40:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Password Info]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[attacker]]></category>
		<category><![CDATA[disk encryption]]></category>
		<category><![CDATA[DriveCrypt Security Model bypass]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[privileged attacker]]></category>
		<category><![CDATA[RAM]]></category>
		<category><![CDATA[Unix]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=206</guid>
		<description><![CDATA[Synopsis The password checking routine of DriveCrypt fails to sanitize the BIOS keyboard buffer before AND after reading passwords. Affected Software Secu Star&#8217;s DriveCrypt Plus Pack v3.9 (possibly other versions also) Technical Description DriveCrypt&#8217;s pre-boot authentication routines use the BIOS API to read user input via the keyboard. The BIOS internally copies the keystrokes in [...]]]></description>
			<content:encoded><![CDATA[<h6>Synopsis</h6>
<p align="justify">The password checking routine of DriveCrypt fails to sanitize the      BIOS keyboard buffer before AND after reading passwords.</p>
<p><span id="more-206"></span></p>
<h6>Affected Software</h6>
<p align="justify">Secu Star&#8217;s DriveCrypt Plus Pack v3.9 (possibly other versions also)</p>
<h6>Technical Description</h6>
<p align="justify">DriveCrypt&#8217;s pre-boot authentication routines use the BIOS API to     read user input via the keyboard. The BIOS internally copies the     keystrokes in a RAM structure called the BIOS Keyboard buffer      inside the BIOS Data Area. This buffer is not flushed after use,     resulting in potential plain text password leakage once the OS     is fully booted, assuming the attacker can read the password at     physical memory location 0&#215;40:0x1e. It is also possible for a root     user to reboot the computer by instrumenting the BIOS keyboard     buffer in spite of the full disk encryption.</p>
<h6>Impact</h6>
<p align="justify">1) Plain text password disclosure.      Required privileges to perform this operation are OS dependant,      from unprivileged users under Windows (any), to root under most      Unix.    2) A privileged attacker able to write to the MBR and knowing the       password (for instance thanks to 1), is able to reboot the computer      in spite of the password prompted at boot time (and in spite of       disk encryption) by initializing the BIOS keybaord buffer with the      correct password (using an intermediary bootloader that will in turn      run DriveCrypt).</p>
<h6>Full Technical Whitepaper</h6>
<p><a href="http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html">http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/drivecrypt-security-model-bypass/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OphCrack Live CD &#8211; Crack Windows Passwords</title>
		<link>http://www.whatsmypass.com/ophcrack-live-cd-crack-windows-passwords</link>
		<comments>http://www.whatsmypass.com/ophcrack-live-cd-crack-windows-passwords#comments</comments>
		<pubDate>Sun, 21 Sep 2008 00:17:35 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Password Info]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Microsoft Vista]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=184</guid>
		<description><![CDATA[Ophcrack LiveCD is a free bootable Windows password cracking CD based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms. Features: » Runs on Windows, Linux/Unix, Mac OS X, &#8230; » Cracks LM [...]]]></description>
			<content:encoded><![CDATA[<div>Ophcrack LiveCD is a free bootable Windows password cracking CD based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms.</div>
<div></div>
<p><strong>Features:</strong><br />
» Runs on Windows, Linux/Unix, Mac OS X, &#8230;<br />
» Cracks LM and NTLM hashes.<br />
» Free tables available for Windows XP and Vista.<br />
» Brute-force module for simple passwords.<br />
» LiveCD available to simplify the cracking.<br />
» Loads hashes from encrypted SAM recovered from a Windows partition, Vista included.<br />
<span id="more-184"></span></p>
<p>Starting with version 2.3, Ophcrack also cracks NT hashes. This is necessary if generation of the LM hash is disabled (this is default for Windows Vista), or if the password is longer than 14 characters (in which case the LM hash is not stored).</p>
<p><a href="http://ophcrack.sourceforge.net/download.php?type=livecd">Download</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/ophcrack-live-cd-crack-windows-passwords/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

