
مولّد سريع لقوائم كلمات المرور، أداة إنشاء القوائم الذكية وتحليل أقنعة كلمات المرور الهجينة، مكتوبة بلغة Rust الآمنة النقية.
كراكين هي أداة سريعة لتوليد قوائم كلمات المرور، وإنشاء القوائم الذكية، وتحليل أقنعة كلمات المرور الهجينة، مكتوبة بلغة Rust الآمنة النقية (المزيد في talk/). مستوحاة من أدوات رائعة مثل maskprocessor وhashcat وCrunch و🤗 tokenizers من HuggingFace.
في DeepSec2021 قدمنا طريقة جديدة لتحليل كلمات المرور كأقنعة هجينة تستغل السلاسل الفرعية الشائعة في كلمات المرور باستخدام محللات NLP (مزيد من المعلومات في talk/).
طريقتنا تقسم كلمة المرور إلى كلماتها الفرعية بدلاً من مجرد قناع أحرف. HelloWorld123! مقسمة إلى ['Hello', 'World', '123!'] لأن هذه الكلمات الفرعية الثلاث شائعة جدًا في كلمات مرور أخرى.
?w1?w2?l?d)
الجدول الكامل هنا
الأقنعة الهجينة بسرعة فائقة جدًا جدًا 🦸⚡💨 (انظر قسم الأداء)القوائم الذكية - قائمة مضغوطة وتمثيلية للكلمات الفرعية من ملفات كلمات المرور المعطاة (باستخدام 🤗 tokenizers من HuggingFace)أقنعتها الهجينة - بناء إحصائيات لتحسين مرشحات كلمات المرور (وبسرعة كبيرة أيضًا)cracken -w rockyou.txt -w 100-most-common.txt '?w1?w2?d?d?d?d?s'hashcat أو john أو أي أداة تكسير كلمات مرور تفضلهاcracken createcracken entropyالأقنعة الهجينة الأكثر تكرارًا لتوليد مرشحات كلمات مرور بسرعة - cracken generate -i hybrid-masks.txtلمزيد من التفاصيل انظر قسم الاستخدام
التحميل (لينكس فقط حاليًا): أحدث إصدار 🔗
لخيارات تثبيت إضافية انظر قسم التثبيت
تشغيل كراكين:
توليد كل الكلمات بطول 8 تبدأ بحرف كبير متبوع بـ 6 أحرف صغيرة ثم رقم:
$ cracken -o pwdz.lst '?u?l?l?l?l?l?l?d'
توليد كلمات من قائمتين للكلمات مع لاحقة سنة (1000-2999) <firstname><lastname><year>
$ cracken --wordlist firstnames.txt --wordlist lastnames.lst --charset '12' '?w1?w2?1?d?d?d'
إنشاء قائمة ذكية بحجم 50 ألف كلمة فرعية مستخرجة من rockyou.txt
$ cracken create -f rockyou.txt -m 50000 --smartlist smart.lst
تقدير الإنتروبيا للقناع الهجين لكلمة المرور HelloWorld123! باستخدام قائمة ذكية
$ cracken entropy -f smart.lst 'HelloWorld123!'
hybrid-min-split: ["hello", "world1", "2", "3", "!"]
hybrid-mask: ?w1?w1?d?d?s
hybrid-min-entropy: 42.73
--
charset-mask: ?l?l?l?l?l?l?l?l?l?l?d?d?d?s
charset-mask-entropy: 61.97
حتى كتابة هذه السطور، من المحتمل أن كراكين هو أسرع مولد لقوائم الكلمات في العالم:
يحقق كراكين أداءً أعلى بنسبة 25% تقريبًا مقارنة بـ maskprocessor السريع من hashcat والمكتوب بلغة C.
يمكن لكراكين توليد حوالي 2 جيجابايت/ثانية لكل نواة.
مزيد من التفاصيل في benchmarks/ 🔗
لماذا السرعة مهمة؟ يمكن لوحدة معالجة رسومية نموذجية اختبار مليارات كلمات المرور في الثانية اعتمادًا على دالة تجزئة كلمة المرور. عندما يولد مولد قائمة الكلمات عددًا أقل من الكلمات في الثانية مما يمكن لأداة التكسير التعامل معه - ستنخفض سرعة التكسير.
يستخدم كراكين خوارزمية A* لتحليل كلمات المرور بسرعة كبيرة. يمكنه العثور على القناع الهجين الأدنى لملف كلمات المرور بمعدل ~100 ألف كلمة مرور/ثانية (cracken entropy -f words1.txt -f words2.txt ... -p pwds.txt)
تثبيت كراكين أو تجميعه من المصدر
تحميل أحدث إصدار من releases 🔗
كراكين مكتوب بلغة Rust ويحتاج إلى rustc للتجميع. يجب أن يدعم كراكين جميع المنصات التي تدعمها Rust.
تعليمات التثبيت لـ cargo 🔗
هناك خياران للتجميع من المصدر - التثبيت باستخدام cargo من crates.io (المفضل) أو التجميع يدويًا من المصدر.
التثبيت باستخدام cargo:
$ cargo install cracken
استنساخ كراكين:
$ git clone https://github.com/shmuelamar/cracken
بناء كراكين:
$ cd cracken
$ cargo build --release
تشغيله:
$ ./target/release/cracken --help
$ cracken --help
Cracken v1.0.0 - a fast password wordlist generator
USAGE:
cracken [SUBCOMMAND]
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
SUBCOMMANDS:
generate (default) - Generates newline separated words according to given mask and wordlist files
create Create a new smartlist from input file(s)
entropy
Computes the estimated entropy of password or password file.
The entropy of a password is the log2(len(keyspace)) of the password.
There are two types of keyspace size estimations:
* mask - keyspace of each char (digit=10, lowercase=26...).
* hybrid - finding minimal split into subwords and charsets.
For specific subcommand help run: cracken <subcommand> --help
Example Usage:
## Generate Subcommand Examples:
# all digits from 00000000 to 99999999
cracken ?d?d?d?d?d?d?d?d
# all digits from 0 to 99999999
cracken -m 1 ?d?d?d?d?d?d?d?d
# words with pwd prefix - pwd0000 to pwd9999
cracken pwd?d?d?d?d
# all passwords of length 8 starting with upper then 6 lowers then digit
cracken ?u?l?l?l?l?l?l?d
# same as above, write output to pwds.txt instead of stdout
cracken -o pwds.txt ?u?l?l?l?l?l?l?d
# custom charset - all hex values
cracken -c 0123456789abcdef '?1?1?1?1'
# 4 custom charsets - the order determines the id of the charset
cracken -c 01 -c ab -c de -c ef '?1?2?3?4'
# 4 lowercase chars with years 2000-2019 suffix
cracken -c 01 '?l?l?l?l20?1?d'
# starts with firstname from wordlist followed by 4 digits
cracken -w firstnames.txt '?w1?d?d?d?d'
# starts with firstname from wordlist with lastname from wordlist ending with symbol
cracken -w firstnames.txt -w lastnames.txt -c '!@#$' '?w1?w2?1'
# repeating wordlists multiple times and combining charsets
cracken -w verbs.txt -w nouns.txt '?w1?w2?w1?w2?w2?d?d?d'
## Create Smartlists Subcommand Examples:
# create smartlist from single file into smart.txt
cracken create -f rockyou.txt --smartlist smart.txt
# create smartlist from multiple files with multiple tokenization algorithms
cracken create -t bpe -t unigram -t wordpiece -f rockyou.txt -f passwords.txt -f wikipedia.txt --smartlist smart.txt
# create smartlist with minimum subword length of 3 and max numbers-only subwords of size 6
cracken create -f rockyou.txt --min-word-len 3 --numbers-max-size 6 --smartlist smart.txt
## Entropy Subcommand Examples:
# estimating entropy of a password
cracken entropy --smartlist vocab.txt 'helloworld123!'
# estimating entropy of a passwords file with a charset mask entropy (default is hybrid)
cracken entropy --smartlist vocab.txt -t charset -p passwords.txt
# estimating the entropy of a passwords file
cracken entropy --smartlist vocab.txt -p passwords.txt
cracken-v1.0.0 linux-x86_64 compiler: rustc 1.56.1 (59eed8a2a 2021-11-01)
more info at: https://github.com/shmuelamar/cracken
$ cracken generate --help
cracken-generate
(default) - Generates newline separated words according to given mask and wordlist files
USAGE:
cracken generate [FLAGS] [OPTIONS] <mask> --masks-file <masks-file>
FLAGS:
-h, --help
Prints help information
-s, --stats
prints the number of words this command will generate and exits
-V, --version
Prints version information
OPTIONS:
-c, --custom-charset <custom-charset>...
custom charset (string of chars). up to 9 custom charsets - ?1 to ?9. use ?1 on the mask for the first charset
-i, --masks-file <masks-file>
a file containing masks to generate
-x, --maxlen <max-length>
maximum length of the mask to start from
-m, --minlen <min-length>
minimum length of the mask to start from
-o, --output-file <output-file>
output file to write the wordlist to, defaults to stdout
-w, --wordlist <wordlist>...
filename containing newline (0xA) separated words. note: currently all wordlists loaded to memory
ARGS:
<mask>
the wordlist mask to generate.
available masks are:
builtin charsets:
?d - digits: "0123456789"
?l - lowercase: "abcdefghijklmnopqrstuvwxyz"
?u - uppercase: "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
?s - symbols: " !\"\#$%&'()*+,-./:;<=>?@[\\]^_`{|}~"
?a - all characters: ?d + ?l + ?u + ?s
?b - all binary values: (0-255)
custom charsets ?1 to ?9:
?1 - first custom charset specified by --charset 'mychars'
wordlists ?w1 to ?w9:
?w1 - first wordlist specified by --wordlist 'my-wordlist.txt'
$ cracken create --help
cracken-create
Create a new smartlist from input file(s)
USAGE:
cracken create [FLAGS] [OPTIONS] --file <file>... --smartlist <smartlist>
FLAGS:
-h, --help Prints help information
-q, --quiet disables printing progress bar
-V, --version Prints version information
OPTIONS:
-f, --file <file>... input filename, can be specified multiple times for multiple files
--min-frequency <min_frequency> minimum frequency of a word, relevant only for BPE tokenizer
-l, --min-word-len <min_word_len> filters words shorter than the specified length
--numbers-max-size <numbers_max_size> filters numbers (all digits) longer than the specified size
-o, --smartlist <smartlist> output smartlist filename
-t, --tokenizer <tokenizer>... tokenizer to use, can be specified multiple times.
one of: bpe,unigram,wordpiece [default: bpe] [possible values: bpe, unigram, wordpiece]
-m, --vocab-max-size <vocab_max_size> max vocabulary size
$ cracken entropy --help
cracken-entropy
Computes the estimated entropy of password or password file.
The entropy of a password is the log2(len(keyspace)) of the password.
There are two types of keyspace size estimations:
* mask - keyspace of each char (digit=10, lowercase=26...).
* hybrid - finding minimal split into subwords and charsets.
USAGE:
cracken entropy [FLAGS] [OPTIONS] <password> --smartlist <smartlist>...
FLAGS:
-h, --help Prints help information
-s, --summary output summary of entropy for password
-V, --version Prints version information
OPTIONS:
-t, --mask-type <mask_type> type of mask to output, one of: charsets(charsets only), hybrid(charsets+wordlists) [possible values: hybrid, charset]
-p, --passwords-file <passwords-file> newline separated password file to estimate entropy for
-f, --smartlist <smartlist>... smartlist input file to estimate entropy with, a newline separated text file
ARGS:
<password> password to
كراكين مرخص بموجب MIT. يجب استخدام هذا المشروع للأغراض القانونية فقط ⚖️
كراكين قيد التطوير النشط، إذا كنت ترغب في المساعدة، فيما يلي خريطة الطريق الجزئية لهذا المشروع. لا تتردد في تقديم طلبات السحب وفتح القضايا.