Password cracking is the process of recovering secret passwords from data that has been stored in or transmitted by a computer system, typically, by repeatedly verifying guesses for the password. The purpose of password cracking might be to help a user recover a forgotten password (though installing an entirely new password is less of a security risk), to gain unauthorized access to a system, or as a preventative measure by the system administrator to check for easily crackable passwords.
Background
Passwords to access computer systems are usually stored, in some form, in a database in order for the system to perform password verification. To enhance the privacy of passwords, the stored password verification data is generally produced by applying a one-way function to the password, possibly in combination with other available data. For simplicity of this discussion, when the one-way function (which may be either an encryption function or cryptographic hash) does not incorporate a secret key, other than the password, we will refer to the one way function employed as a hash and its output as a hashed password.
Even though functions that create hashed passwords may be cryptographically secure, possession of a hashed password provides a quick way to verify guesses for the password by applying the function to each guess, and comparing the result to the verification data. The most commonly used hash functions can be computed rapidly and the attacker can do this repeatedly with different guesses until a valid match is found, meaning the plaintext password has been recovered.
Intel backs Microsoft's concurrent-computing play
Wed, 20 Aug 2008 10:10:50 -0700
On August 20, Intel rolled out new parallel-processing tools that support Microsoft's concurrent runtime environment that is expected to become a central component of Redmond's next-generation computing model. by Mary Jo Foley
10 reasons to love Silverlight and 10 reasons to hate it
Mon, 18 Aug 2008 13:59:24 -0700
I won't add much commentary to Tim's excellent post up on the Register because I work for Adobe and I don't want to get into a bunch of nonsensical arguments about Flash versus Silverlight. But I will say that Tim Anderson is one of the very few tech journalists who...
Microsoft investigating NSlookup.exe flaw, reported attacks
Fri, 15 Aug 2008 11:54:29 -0700
Microsoft is investigating new public reports of a zero-day Windows vulnerability that's being exploited in the wild. According to a this SecurityFocus alert, the attacks are exploiting a remote code-execution vulnerability due to an unspecified error in NSlookup.exe, the command-line administrative tool used for testing and troubleshooting...
LWUIT vs. JavaFX Mobile
Fri, 15 Aug 2008 06:26:21 -0700
The light-weight user interface toolkit for Java ME LWUIT has been released as open source under the GPLv2+classpath exception license. LWUIT is a library that helps content developers in creating rich and consistent Java ME applications. LWUIT supports visual components, theming, transitions, animation, and more. Sounds similar to JavaFX doesn't...
Countering an Apple-favoring .NET critic
Thu, 14 Aug 2008 08:17:50 -0700
I've been investigating Apple Cocoa API as I plan to complement my Windows and UNIX development skills with skills in Mac development. That doesn't mean I am willing to accept weak attacks what I consider to be a superior development platform: .NET. by John Carroll
Google releases open-source crypto toolkit
Mon, 11 Aug 2008 22:15:34 -0700
Google's security team has released an open-source cryptographic toolkit aimed at making it easier and safer for developers to use cryptography in their applications. The toolkit, called KeyCzar, was originally developed by Steve Weis Google and Arkajit Dey MIT and is available under an Apache 2.0...
ABF Password Recovery - Program to retrieve lost or forgotten passwords for many popular programs. Passwords can be recovered for current installation of Windows only.
Meta Description: [ ABF Password Recovery is a program to retrieve lost or forgotten passwords for many popular programs. ]
AccentSoft Utilities - Password recovery tools for Microsoft Access, Microsoft Excel, Microsoft Word, and Microsoft Money.
Meta Description: [ Accent OFFICE Password Recovery: You don't need to be a hacker in order to recover a lost password from an Office document. ]
500DA Password Recovery Free - See the actual password behind the asterisks. Software comes in two versions free and shareware.
Meta Description: [ Your Brand Here - Software Download Site ]
Elcomsoft - Offering programs for recovering lost or forgotten passwords for ZIP, PKZip, WinZip, ACE, WinACE, archives, and in IBM, Lotus, and Microsoft Office applications and several other programs. (Windows 95/98/Me/NT/2000)
Meta Description: [ Password recovery software: for archives (ZIP,RAR,ARJ,ACE), Adobe Acrobat PDF, MS Office (Word,Excel,Access,Outlook,Visio,PowerPoint,VBA), MS Project, MS Backup, MS Mail, MS Schedule+; Symantec ACT!, Intuit Quicken & QuickBooks, WordPerfect, Paradox, QuattroPro; Lotus WordPro, 1-2-3, Approach, Or... ]
Outlook Express Password Recovery - Program to recover passwords for Outlook Express Identities. Multilingual passwords are supported, full install/uninstall support.
Password Recovery - A collection of various password recovery utilities (mostly shareware).
Meta Description: [ password recovery tools, information and utilities ]
Password Spectator - Software to see the actual password behind the asterisks.
Meta Description: [ This great software lets you ]
Password Spyer 2k - Recover passwords hidden by asterisks (***) in Windows applications, including IE6.0. [9X/NT/2000/XP]
Meta Description: [ Instant Password Recovery Software. Recover your lost password. Reveal passwords hidden by asterisks (***) in all windows versions (including 2000 and XP) and most windows applications. Reveal the password behind those asterisks. ]
Refog - Use Password Spectator Pro to display passwords stored behind the asterisks.
Meta Description: [ KGB Keylogger is a multifunctional keyboard tracking software (a.k.a. key logger) that is widely used by both regular users and IT security specialists. ]
Rixler Software - Password revealer software for Internet Explorer, Outlook Express, and Network and Dial-up to display logins and passwords for access to Internet, LAN, or to other computers.
Meta Description: [ Password recovery tools by Rixler Software for most popular Microsoft Applications: Microsoft Excel, MS Word, VBA, Internet Explorer, Outlook Express, Outlook, Access and Dial-up and network connections. ]
ShowPassword - Decrypt and display passwords stored behind the asterisks on all Microsoft Windows platforms, with full IE support.
404Sloth's Password Recovery - View and decrypt passwords hidden behind asterisks in Windows 2000 and Windows XP.
Ultimate Paradox CryptoExplorer - Tool for recovery of Borland Paradox/Delphi/BDE passwords.
Meta Description: [ Ultimate tool to recover Borland Paradox/Delphi/BDE passwords ]
Zip Password Recovery - Recover lost passwords for zip archives.
Meta Description: [ With Zip Password Recovery it's possible to find your lost passwords. Download a free unlimited version valid until end of 2002. ]
Learn how to recover lost or forgotten passwords, for all windows operating systems using a very simple method ...