
एक तेज़ पासवर्ड वर्डलिस्ट जनरेटर, स्मार्टलिस्ट निर्माण और पासवर्ड हाइब्रिड-मास्क विश्लेषण उपकरण जो शुद्ध सुरक्षित रस्ट में लिखा गया है
क्रैकेन एक तेज़ पासवर्ड वर्डलिस्ट जनरेटर, स्मार्टलिस्ट निर्माण और पासवर्ड हाइब्रिड-मास्क विश्लेषण उपकरण है जो शुद्ध सुरक्षित रस्ट में लिखा गया है (अधिक जानकारी [talk/][talk] पर)। यह [maskprocessor][mp], [hashcat][hashcat], [Crunch][crunch] और 🤗 HuggingFace के [tokenizers][tokenizers] जैसे शानदार उपकरणों से प्रेरित है।
[DeepSec2021][talk-abstract] में हमने पासवर्ड का NLP टोकनाइज़र्स (अधिक जानकारी [talk/][talk] पर) का उपयोग करके सामान्य उपशब्दों का शोषण करके हाइब्रिड-मास्क के रूप में विश्लेषण करने की एक नई विधि प्रस्तुत की।
हमारी विधि एक पासवर्ड को केवल वर्णों के मास्क के बजाय उसके उपशब्दों में विभाजित करती है। HelloWorld123! को ['Hello', 'World', '123!'] में विभाजित किया गया क्योंकि ये तीन उपशब्द अन्य पासवर्डों में बहुत सामान्य हैं।
?w1?w2?l?d)
पूरा तालिका यहाँ
हाइब्रिड-मास्क बहुत बहुत तेज़ी से उत्पन्न करना 🦸⚡💨 (प्रदर्शन प्रदर्शन अनुभाग देखें)स्मार्टलिस्ट बनाना - दिए गए पासवर्ड फ़ाइलों से उपशब्दों की कॉम्पैक्ट और प्रतिनिधि सूची (🤗 HuggingFace के [tokenizers][tokenizers] का उपयोग करके)हाइब्रिड-मास्क के लिए विश्लेषण करना - बेहतर पासवर्ड उम्मीदवारों के लिए आँकड़े बनाना (फिर से बहुत तेज़)cracken -w rockyou.txt -w 100-most-common.txt '?w1?w2?d?d?d?d?s'hashcat, john या अपने पसंदीदा पासवर्ड क्रैकर में पाइप कर सकते हैंcracken createcracken entropyहाइब्रिड-मास्क का उपयोग करके तेज़ी से पासवर्ड उम्मीदवार उत्पन्न करें - cracken generate -i hybrid-masks.txtअधिक विवरण के लिए उपयोग अनुभाग देखें
डाउनलोड करें (वर्तमान में केवल लिनक्स): [नवीनतम रिलीज़ 🔗][releases]
अधिक इंस्टॉलेशन विकल्पों के लिए installation अनुभाग देखें
क्रैकेन चलाएं:
लंबाई 8 के सभी शब्द उत्पन्न करें जो बड़े अक्षर से शुरू होते हैं, फिर 6 छोटे अक्षर और फिर एक अंक:
$ cracken -o pwdz.lst '?u?l?l?l?l?l?l?d'
दो वर्डलिस्ट से वर्ष प्रत्यय (1000-2999) के साथ शब्द उत्पन्न करें <firstname><lastname><year>
$ cracken --wordlist firstnames.txt --wordlist lastnames.lst --charset '12' '?w1?w2?1?d?d?d'
rockyou.txt से निकाले गए उपशब्दों से आकार 50k की स्मार्टलिस्ट बनाएं
$ cracken create -f rockyou.txt -m 50000 --smartlist smart.lst
एक स्मार्टलिस्ट का उपयोग करके पासवर्ड HelloWorld123! के हाइब्रिड मास्क की एन्ट्रॉपी का अनुमान लगाएं
$ cracken entropy -f smart.lst 'HelloWorld123!'
hybrid-min-split: ["hello", "world1", "2", "3", "!"]
hybrid-mask: ?w1?w1?d?d?s
hybrid-min-entropy: 42.73
--
charset-mask: ?l?l?l?l?l?l?l?l?l?l?d?d?d?s
charset-mask-entropy: 61.97
इस लेखन के समय, क्रैकेन संभवतः दुनिया का सबसे तेज़ वर्डलिस्ट जनरेटर है:
क्रैकेन का प्रदर्शन हैशकैट के तेज़ [maskprocessor][mp] से लगभग 25% अधिक है जो C में लिखा गया है।
क्रैकेन प्रति कोर लगभग 2 GB/s उत्पन्न कर सकता है।
benchmarks/ 🔗 पर अधिक विवरण
गति क्यों महत्वपूर्ण है? एक सामान्य GPU पासवर्ड हैश फ़ंक्शन के आधार पर प्रति सेकंड अरबों पासवर्ड का परीक्षण कर सकता है। जब वर्डलिस्ट जनरेटर क्रैकिंग टूल की तुलना में प्रति सेकंड कम शब्द उत्पन्न करता है, तो क्रैकिंग गति घट जाएगी।
क्रैकेन पासवर्ड का बहुत तेज़ी से विश्लेषण करने के लिए A* एल्गोरिथ्म का उपयोग करता है। यह ~100k पासवर्ड/सेकंड की दर से पासवर्ड फ़ाइल का न्यूनतम हाइब्रिड-मास्क ढूंढ सकता है (cracken entropy -f words1.txt -f words2.txt ... -p pwds.txt)
क्रैकेन स्थापित करें या स्रोत से संकलित करें
[रिलीज़ 🔗][releases] से नवीनतम रिलीज़ डाउनलोड करें
क्रैकेन रस्ट में लिखा गया है और इसे संकलित करने के लिए rustc की आवश्यकता है। क्रैकेन को उन सभी प्लेटफ़ॉर्मों का समर्थन करना चाहिए जिन्हें रस्ट समर्थन करता है।
[cargo 🔗][rustc-installation] के लिए स्थापना निर्देश
स्रोत से बनाने के दो विकल्प हैं - crates.io से कार्गो के साथ स्थापित करना (पसंदीदा) या स्रोत से मैन्युअल रूप से संकलित करना।
cargo के साथ स्थापित करें:
$ cargo install cracken
क्रैकेन को क्लोन करें:
$ git clone https://github.com/shmuelamar/cracken
क्रैकेन बनाएं:
$ cd cracken
$ cargo build --release
इसे चलाएं:
$ ./target/release/cracken --help
$ cracken --help
Cracken v1.0.0 - a fast password wordlist generator
USAGE:
cracken [SUBCOMMAND]
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
SUBCOMMANDS:
generate (default) - Generates newline separated words according to given mask and wordlist files
create Create a new smartlist from input file(s)
entropy
Computes the estimated entropy of password or password file.
The entropy of a password is the log2(len(keyspace)) of the password.
There are two types of keyspace size estimations:
* mask - keyspace of each char (digit=10, lowercase=26...).
* hybrid - finding minimal split into subwords and charsets.
For specific subcommand help run: cracken <subcommand> --help
Example Usage:
## Generate Subcommand Examples:
# all digits from 00000000 to 99999999
cracken ?d?d?d?d?d?d?d?d
# all digits from 0 to 99999999
cracken -m 1 ?d?d?d?d?d?d?d?d
# words with pwd prefix - pwd0000 to pwd9999
cracken pwd?d?d?d?d
# all passwords of length 8 starting with upper then 6 lowers then digit
cracken ?u?l?l?l?l?l?l?d
# same as above, write output to pwds.txt instead of stdout
cracken -o pwds.txt ?u?l?l?l?l?l?l?d
# custom charset - all hex values
cracken -c 0123456789abcdef '?1?1?1?1'
# 4 custom charsets - the order determines the id of the charset
cracken -c 01 -c ab -c de -c ef '?1?2?3?4'
# 4 lowercase chars with years 2000-2019 suffix
cracken -c 01 '?l?l?l?l20?1?d'
# starts with firstname from wordlist followed by 4 digits
cracken -w firstnames.txt '?w1?d?d?d?d'
# starts with firstname from wordlist with lastname from wordlist ending with symbol
cracken -w firstnames.txt -w lastnames.txt -c '!@#$' '?w1?w2?1'
# repeating wordlists multiple times and combining charsets
cracken -w verbs.txt -w nouns.txt '?w1?w2?w1?w2?w2?d?d?d'
## Create Smartlists Subcommand Examples:
# create smartlist from single file into smart.txt
cracken create -f rockyou.txt --smartlist smart.txt