posted in Tools & sources on Feb 21st, 2010
Tool name :
MSNRecover version 0.1
Description :
MSNRecover searches inside the Microsoft Credential management system for MSN authentication data. If such an entry was found targetname, comments, username and password are printed on the display.
Tested on :
Windows XP
Feedback :
In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it [...]
read full post »
posted in News & media on Dec 17th, 2009
In a chat lasting over an hour, we got to talk to a person claiming to be the infamous hacker behind RockYou’s latest data security woes.
While he claimed to have no animosity toward users, he had one clear message for websites: Take better care of your customers’ data. RockYou isn’t the only hacked site storing [...]
read full post »
posted in News & media on Dec 9th, 2009
The WPA Cracker is a cloud-based service that accesses a 400-CPU cluster. For $34, it can run a password against all 135 million entries in about 20 minutes. Those willing to wait 40 minutes can pay $17 to access the system at half mode.
In addition to operating in the cloud, the service is also notable [...]
read full post »
posted in News & media on Dec 1st, 2009
Hackers have developed a distributed Wordpress admin account cracking scheme that poses a severe risk for the security of blogs whose owners select insecure passwords.
PHP scripts located on a virtual server run bruteforce (password guessing) attacks on targeted sites. Many sites can be attacked at the same time by the system, with results written into [...]
read full post »
posted in News & media, Stuff on Nov 29th, 2009
According the latest Microsoft’s researches guessing FTP passwords is still a valuable way to harvest account information. People still forget or ignore to change their default password or change it that way attackers can easily guess.
Microsoft releases password attack data
Microsoft released data collected from an FTP-server honeypot, showing that attempts to guess passwords continue to [...]
read full post »
posted in Tools & sources on Jul 28th, 2009
Tool name :
FFPasswordRecovery 0.2
Description :
FFPasswordRecovery is a tool to extract and decrypt the Firefox authentication and auto complete information.
Tested on :
Windows XP, Firefox 3.5.7
Feedback :
In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a Windows version i’ve not yet tested please drop me an [...]
read full post »
posted in External tools on May 31st, 2009
Tool name :
THC Hydra
Description :
THC Hydra is a fast network authentication cracker which supports many different services.
When you need to brute force crack a remote authentication service, Hydra is often the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, and much [...]
read full post »
posted in External tools on May 24th, 2009
Tool name :
Cain & Abel
Description :
UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain & Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords by [...]
read full post »
posted in Tools & sources on May 19th, 2009
Tool name :
IEPasswordRecovery 0.1
Description :
IEPasswordRecovery searches inside Microsofts protected storage area for Internet Explorer auto completion (authentication input fields in a page) and HTTP authentication entries. If such an entry was found the hostname, username and password are printed on the display.
Only Internet Explorer up to version 6 use the protected storage to keep sensitive [...]
read full post »
posted in External tools on May 17th, 2009
Tool name :
John the ripper
Description :
John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), Windows, DOS, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix flavors, [...]
read full post »