Wi-fi, Wallets and JSON Tokens Fall To Hashcat 4.x

--

Anyone who has seen Hashcat in action knows that it can break most passwords within a short-time. The requirement to rely on pure brute force is often not required, and where the majority of passwords can be cracked using well-defined rules. So if you use uppercase letters for the first character, and a number at the end, then Hashcat will apply its rules, and you see your password melt:

Now Hashcat 4.1 goes a few steps forward with support for the Ethereum Wallet, (PBKDF2-SHA256 and Ethereum Pre-Sale Wallet), and JWT (JSON Web Token). A worry, too, is the PBKDF2 cracking has been further optimized, and where WPA-2 cracking could be at an even great risk. The cracker can already support Bitcoin wallet cracking.

Hash 4.2 adds more support for WPA cracking (16800 — WPA-PMKID-PBKDF2 and16801 — WPA-PMKID-PMK)

Hashcat can use OpenCL, and which allows it to run on a range of processors, including supporting GPUs (and which can run parallel cracking activities). We can see that the performance differences are significant in places (eg where WPA-2 cracking has been improved by over 20%).

--

--

Prof Bill Buchanan OBE FRSE
ASecuritySite: When Bob Met Alice

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.