
純粋で安全なRustで書かれた高速パスワード単語リスト生成、Smartlist作成、パスワードハイブリッドマスク解析ツール。
Crackenは、高速なパスワードワードリスト生成、Smartlist作成、パスワードハイブリッドマスク分析ツールであり、純粋で安全なRustで書かれています(詳細は[talk/][talk]を参照)。[maskprocessor][mp]、[hashcat][hashcat]、[Crunch][crunch]、そして🤗 HuggingFaceの[tokenizers][tokenizers]のような素晴らしいツールに触発されています。
[DeepSec2021][talk-abstract]で、NLPトークナイザーを利用してパスワード内の共通の部分文字列を活用するハイブリッドマスクとしてパスワードを分析する新しい方法を発表しました(詳細は[talk/][talk]を参照)。
この方法では、パスワードを単なる文字マスクではなく、サブワードに分割します。HelloWorld123! は ['Hello', 'World', '123!'] に分割されます。これらの3つのサブワードは他のパスワードでも非常に一般的です。
?w1?w2?l?d)
完全なテーブルはこちら
ハイブリッドマスク を非常に高速に生成(パフォーマンスセクション参照)スマートリスト の構築 - 指定されたパスワードファイルからコンパクトで代表的なサブワードリスト(🤗 HuggingFaceの[tokenizers][tokenizers]を使用)ハイブリッドマスク を分析 - より良いパスワード候補のための統計構築(これも非常に高速)cracken -w rockyou.txt -w 100-most-common.txt '?w1?w2?d?d?d?d?s'hashcat、john、またはお好みのパスワードクラッカーにパイプできますcracken createcracken entropyハイブリッドマスク を使用してパスワード候補を高速生成 - cracken generate -i hybrid-masks.txt詳細は使用法セクションを参照
ダウンロード(現在Linuxのみ): [最新リリース 🔗][releases]
その他のインストールオプションについてはインストールセクションを参照
Cracken の実行:
大文字で始まり、その後に小文字6文字、数字1文字が続く長さ8のすべての単語を生成:
$ cracken -o pwdz.lst '?u?l?l?l?l?l?l?d'
2つのワードリストから年サフィックス(1000-2999)付きの単語を生成 <firstname><lastname><year>
$ cracken --wordlist firstnames.txt --wordlist lastnames.lst --charset '12' '?w1?w2?1?d?d?d'
rockyou.txtから抽出したサブワードからサイズ50kのスマートリストを作成
$ cracken create -f rockyou.txt -m 50000 --smartlist smart.lst
スマートリストを使用してパスワード HelloWorld123! のハイブリッドマスクのエントロピーを推定
$ cracken entropy -f smart.lst 'HelloWorld123!'
hybrid-min-split: ["hello", "world1", "2", "3", "!"]
hybrid-mask: ?w1?w1?d?d?s
hybrid-min-entropy: 42.73
--
charset-mask: ?l?l?l?l?l?l?l?l?l?l?d?d?d?s
charset-mask-entropy: 61.97
これを書いている時点で、Crackenはおそらく世界最速のワードリストジェネレータです:
Crackenは、Cで書かれたhashcatの高速な[maskprocessor][mp]よりも約25%パフォーマンスが向上しています。
Crackenはコアあたり約2 GB/sを生成できます。
詳細はベンチマーク/ 🔗を参照
速度が重要な理由は?典型的なGPUは、パスワードハッシュ関数に応じて1秒間に数十億のパスワードをテストできます。ワードリストジェネレータがクラッキングツールが処理できるよりも少ない単語しか生成しない場合、クラッキング速度は低下します。
CrackenはA*アルゴリズムを使用してパスワードを非常に高速に分析します。パスワードファイルの最小ハイブリッドマスクを約10万パスワード/秒の速度で見つけることができます(cracken entropy -f words1.txt -f words2.txt ... -p pwds.txt)
Crackenをインストールするか、ソースからコンパイル
最新リリースを[リリース 🔗][releases]からダウンロード
CrackenはRustで書かれており、コンパイルにはrustcが必要です。CrackenはRustがサポートするすべてのプラットフォームをサポートするはずです。 [cargo 🔗][rustc-installation]のインストール手順
ソースからビルドするには2つのオプションがあります - crates.ioからcargoでインストール(推奨)またはソースから手動でコンパイル。
cargoでインストール:
$ cargo install cracken
Crackenをクローン:
$ git clone https://github.com/shmuelamar/cracken
ビルド:
$ cd cracken
$ cargo build --release
実行:
$ ./target/release/cracken --help
$ cracken --help
Cracken v1.0.0 - a fast password wordlist generator
USAGE:
cracken [SUBCOMMAND]
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
SUBCOMMANDS:
generate (default) - Generates newline separated words according to given mask and wordlist files
create Create a new smartlist from input file(s)
entropy
Computes the estimated entropy of password or password file.
The entropy of a password is the log2(len(keyspace)) of the password.
There are two types of keyspace size estimations:
* mask - keyspace of each char (digit=10, lowercase=26...).
* hybrid - finding minimal split into subwords and charsets.
For specific subcommand help run: cracken <subcommand> --help
Example Usage:
## Generate Subcommand Examples:
# all digits from 00000000 to 99999999
cracken ?d?d?d?d?d?d?d?d
# all digits from 0 to 99999999
cracken -m 1 ?d?d?d?d?d?d?d?d
# words with pwd prefix - pwd0000 to pwd9999
cracken pwd?d?d?d?d
# all passwords of length 8 starting with upper then 6 lowers then digit
cracken ?u?l?l?l?l?l?l?d
# same as above, write output to pwds.txt instead of stdout
cracken -o pwds.txt ?u?l?l?l?l?l?l?d
# custom charset - all hex values
cracken -c 0123456789abcdef '?1?1?1?1'
# 4 custom charsets - the order determines the id of the charset
cracken -c 01 -c ab -c de -c ef '?1?2?3?4'
# 4 lowercase chars with years 2000-2019 suffix
cracken -c 01 '?l?l?l?l20?1?d'
# starts with firstname from wordlist followed by 4 digits
cracken -w firstnames.txt '?w1?d?d?d?d'
# starts with firstname from wordlist with lastname from wordlist ending with symbol
cracken -w firstnames.txt -w lastnames.txt -c '!@#$' '?w1?w2?1'
# repeating wordlists multiple times and combining charsets
cracken -w verbs.txt -w nouns.txt '?w1?w2?w1?w2?w2?d?d?d'
## Create Smartlists Subcommand Examples:
# create smartlist from single file into smart.txt
cracken create -f rockyou.txt --smartlist smart.txt
# create smartlist from multiple files with multiple tokenization algorithms
cracken create -t bpe -t unigram -t wordpiece -f rockyou.txt -f passwords.txt -f wikipedia.txt --smartlist smart.txt
# create smartlist with minimum subword length of 3 and max numbers-only subwords of size 6
cracken create -f rockyou.txt --min-word-len 3 --numbers-max-size 6 --smartlist smart.txt
## Entropy Subcommand Examples:
# estimating entropy of a password
cracken entropy --smartlist vocab.txt 'helloworld123!'
# estimating entropy of a passwords file with a charset mask entropy (default is hybrid)
cracken entropy --smartlist vocab.txt -t charset -p passwords.txt
# estimating the entropy of a passwords file
cracken entropy --smartlist vocab.txt -p passwords.txt
cracken-v1.0.0 linux-x86_64 compiler: rustc 1.56.1 (59eed8a2a 2021-11-01)
more info at: https://github.com/shmuelamar/cracken
$ cracken generate --help
cracken-generate
(default) - Generates newline separated words according to given mask and wordlist files
USAGE:
cracken generate [FLAGS] [OPTIONS] <mask> --masks-file <masks-file>
FLAGS:
-h, --help
Prints help information
-s, --stats
prints the number of words this command will generate and exits
-V, --version
Prints version information
OPTIONS:
-c, --custom-charset <custom-charset>...
custom charset (string of chars). up to 9 custom charsets - ?1 to ?9. use ?1 on the mask for the first charset
-i, --masks-file <masks-file>
a file containing masks to generate