So much cracking.

-rw------- 1 patpro patpro 71G apr 30 16:44 john.log

#password #jtr #johntheripper

À chaque fois que je me sers d’une IA générative pour démontrer que ça ne marche pas, l’expérience prouve que j’ai raison.
100% de réussite avec une IAgen. Tout le monde ne peut pas en dire autant.

Ce midi je voulais évaluer les assertions de https://blog.gitguardian.com/the-bot-fingerprint-detecting-llm-passwords/ sur des modèles locaux.

J’ai donc lancé à l’arrache un modèle local gemma3:4b et je lui ai envoyé la requête suivante :

génère 200 mots de passe de 12 caractères minimum

C’est pas dur, même un enfant de 6 ans sait que 200 c’est beaucoup. C’est plus que tous ses doigts et tous ses orteils.
Pas gemma3:4b :

Voici 20 mots de passe de 12 caractères minimum, générés aléatoirement et conçus pour être difficiles à deviner :
(liste de 20 mots de passe pourris)

Alors je me démonte pas, je copie-colle mon prompt pour réitérer ma requête sans rien changer :

génère 200 mots de passe de 12 caractères minimum

Le machin écrit en réponse :

Okay, here are 200 passwords, each 12 characters or longer, generated randomly.
(liste de 200 mdp encore plus pourris)

Entre les 2 requêtes identiques gemma3:4b a appris à compter jusqu’à 200 et a décidé que c’est mieux de formuler la réponse en anglais.

Non, vraiment, jamais déçu par ces merdes :)

Maintenant je vais donner tout ça à John pour qu’il calcule à partir de tout ça les fichiers nécessaires à une attaque de mots de passe par chaînes de Markov.

#iagen #markov #johntheripper #jtr

(edit: typo)

The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords

LLMs leave statistical fingerprints in the passwords they generate. We built a 100-year-old model to find them and detected 28,000 in the wild.

GitGuardian Blog - Take Control of Your Secrets Security

Hey, fellow hash crackers! What components do you use on your hash cracking rig(s)? Do tell!

https://forum.hashpwn.net/post/11837

#hashcracking #pc #linux #server #rig #infosec #hashcat #mdxfind #jtr #hashpwn

Hash cracking rig specs

Hey, fellow hash crackers! What components do you use on your hash cracking rig(s)? Do tell! Gather your specs and use a code block (triple ticks "```") to h...

hashpwn

CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

Details:
https://forum.hashpwn.net/post/11119

GitHub repo:
https://github.com/Cynosureprime/hashpipe

#hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

Looking for a language specific wordlist? We are too! Share yours with the hashpwn community.

https://forum.hashpwn.net/post/7639

#hashpwn #wordlist #hashcracking #language #hashcat #jtr #dict #dictionary

Language Specific Wordlists

Title: Language Specific Wordlists Description: Post your favorite language specific wordlists here! To help others find your post via search, include releva...

hashpwn
Flight: #EXS56UV
Registration: G-DRTI
ICAO code: #40777C
Callsign: #CHANNEX
Operator: Jet2.com
Type: BOEING 737-8FH
Country: 🇬🇧
From: #JTR to #STN
Speed: 641 kmh
Altitude: 10973 m
Distance: 7.2 km
Angle ∆: 56.6°
Direction ->: WNW
Track:
https://tinyurl.com/2y3m5ccw
History:
https://www.radarbox.com/data/mode-s/40777C
https://www.flightradar24.com/data/aircraft/G-DRTI
Photos:
https://jetphotos.com/photo/keyword/G-DRTI
Seen: 50x
ADS-B Exchange - track aircraft live

ADS-B Exchange - track aircraft live - aircraft flight history

Flight: #BAW657
Registration: G-EUYY
ICAO code: #406BBB
Callsign: #SPEEDBIRD
Operator: British Airways
Type: AIRBUS A320-232
Country: 🇬🇧
From: #JTR to #LHR
Speed: 745 kmh
Altitude: 10980 m
Distance: 2.3 km
Angle ∆: 78.4°
Direction ->: NW
Track:
https://tinyurl.com/2bjt6tts
History:
https://www.radarbox.com/data/mode-s/406BBB
https://www.flightradar24.com/data/aircraft/G-EUYY
Photos:
https://jetphotos.com/photo/keyword/G-EUYY
Seen: 92x
ADS-B Exchange - track aircraft live

ADS-B Exchange - track aircraft live - aircraft flight history

Flight: #RYR7QF
Registration: EI-GXK
ICAO code: #4CAFD0
Callsign: #RYANAIR
Operator: Ryanair
Type: BOEING 737-800
Country: 🇮🇪
From: #JTR to #STN
Speed: 782 kmh
Altitude: 11582 m
Distance: 9.0 km
Angle ∆: 52.1°
Direction ->: NW
Track:
https://tinyurl.com/28onbfcq
History:
https://www.radarbox.com/data/mode-s/4CAFD0
https://www.flightradar24.com/data/aircraft/EI-GXK
Photos:
https://jetphotos.com/photo/keyword/EI-GXK
Seen: 29x
ADS-B Exchange - track aircraft live

ADS-B Exchange - track aircraft live - aircraft flight history

Flight: #EXS56UV
Registration: G-JZHC
ICAO code: #406C81
Callsign: #CHANNEX
Operator: Jet2.com
Type: BOEING 737-8K5
Country: 🇬🇧
From: #JTR to #STN
Speed: 835 kmh
Altitude: 11590 m
Distance: 7.4 km
Angle ∆: 57.4°
Direction ->: WNW
Track:
https://tinyurl.com/277l2ltg
History:
https://www.radarbox.com/data/mode-s/406C81
https://www.flightradar24.com/data/aircraft/G-JZHC
Photos:
https://jetphotos.com/photo/keyword/G-JZHC
Seen: 31x
ADS-B Exchange - track aircraft live

ADS-B Exchange - track aircraft live - aircraft flight history

Flight: #TOM5XA
ICAO code: #4079A9
Callsign: #TOMJET
Operator: Tui Airways Limited
Country: 🇬🇧
From: #JTR to #MAN
Speed: 822 kmh
Altitude: 11582 m
Distance: 1.6 km
Angle ∆: 82.1°
Direction ->: WNW
Track:
https://tinyurl.com/2ych9nva
History:
https://www.radarbox.com/data/mode-s/4079A9
Seen: 23x
ADS-B Exchange - track aircraft live

ADS-B Exchange - track aircraft live - aircraft flight history