
Markov model-based password guesser in C that enumerates candidates by probability, generating most likely passwords first for hash cracking via Hashcat or John.
OMEN is a Markov model-based password guesser written in C. It generates password candidates according to their occurrence probabilities, i.e., it outputs most likely passwords first. OMEN significantly improves guessing speed over existing proposals. If you are interested in the details on how OMEN improves on existing Markov model-based password guessing approaches, please refer to OMEN: Faster Password Guessing Using an Ordered Markov Enumerator.
OMEN consists of two separate program modules: createNG and enumNG. createNG
calculates n-gram probabilities based on a given list of passwords and stores them
on the hard disk. Based on these probabilities enumNG enumerates new
passwords in the correct order (descending).
Use a recent Linux version make sure you have installed git (Git version control system), gcc (GNU Compiler Collection), and make (GNU Make). You can install it under Ubuntu Linux via:
$ sudo apt-get install build-essential git
Check out the source code via:
$ git clone https://github.com/RUB-SysSec/OMEN.git OMEN
Change into the newly created directory OMEN and run:
$ make
If compilation is successful, you can find createNG and enumNG within the current directory.
.
├── alphabetCreator
├── createNG
├── docs
│ ├── CHANGELOG.md
│ ├── LICENSE
│ └── screenshots
├── enumNG
├── evalPW
├── makefile
├── README.md
└── src
├── alphabetCreator.c
...
If you like, you can now remove the src folder and the makefile file, they are no longer used.
A short installation guide using Cygwin on Windows 10 can be found here.
Before one can generate any passwords, the n-gram probabilities have to be estimated using
createNG. To calculate the probabilities using the default settings, createNG must be
called giving a path to a password list that should be trained:
$ ./createNG --iPwdList password-training-list.txt
Each password of the given list must be in a new line. The module then
reads and evaluates the list generating a couple of files. Besides a config file (createConfig) storing the used settings (in this case the default setting), several files are created containing information about the grams and the password length. These files have the extension '.level':
The probabilities of each n-gram and the lengths are mapped to levels between 0
(most likely) and 10 (least likely). Once those files are created, enumNG can
be used to generate a list of passwords ordered by probabilities. Currently, enumNG supports three modes of operation: file, stdout, simulated plaintext attack. In the default mode of enumNG, a list of password guesses based on these levels is created. Using the command
$ ./enumNG
generates 1 billion passwords and stores them in a text file, which can be found
in the 'results' folder. The passwords in this file are ordered by level (i.e., by
probability). Since common text editors are not able to handle such huge files,
it is recommended for testing to reduce the number of passwords created. This
can be done using the argument -m.
$ ./enumNG -m 10000
It will create an ordered list with 10,000 passwords only. If you are interested in printing the passwords to the standard output (stdout) stream use the argument -p.
$ ./enumNG -p -m 10000
If you are interested in evaluating the guessing performance against a plaintext password test set use the argument -s. Please note: In this mode OMEN benefits from the adaptive length scheduling algorithm incorporating live feedback, which is not available (due to the missing feedback channel) in file and stdout mode.
$ ./enumNG -s=password-testing-list.txt -m 10000
The result of this evaluation can be found in the 'results' folder.
Both modules provide a help dialog which can be shown using the -h or --help argument.
How to get from $2a$10$HNYF4KajSTqxIP/KoiB5tOCVeKUgvscTh32hhAmppFk4T/USmI2B. to "GoodOMEN!123"?
OMEN was developed for academic use cases like improving probabilistic password modeling, estimating guess numbers or password strength, in general, to improve password security. Do not abuse this software to harm other people's privacy or to break the law.
Popular hash evaluators like Hashcat and John the Ripper support hundreds of hash and cipher formats and could be easily integrated due to their support to read password candidates via their standard input (stdin) stream.
$ ./enumNG -p -m 10000 | ./hashcat64.bin ...
or
$ ./enumNG -p -m 10000 | ./john --stdin ...
For optimal guessing performance, consider to train createNG with a password distribution that is similar to the one you like to crack.
Please note: Using probabilistic password modeling to crack passwords, in general, should only be considered against slow hashes (e.g., bcrypt, PBKDF2, scrypt, or Argon2) were the number of feasible guesses is limited or in very targeted attacks. In contrast, for very fast hashes (MD5, SHA-1, or NTLM), using good dictionaries and mangling rules (e.g., best64.rule) are the way to go.
If you are interested in this topic, consider to read the following papers and their related work (this list is incomplete, you can help by expanding it):
Probabilistic Context-Free Grammars
Markov Models
Neural Networks