Thursday, September 27, 2007

0phrack... one reason why you should have a BIOS Password.

I recalled there's a time you really forgot your password. (Hence you shouldn't forgot something that is so important).Be it either in your Linux box or Windows. Although password is seen to be easily crack or by brute force or smart guessing. It is your first line of defense against malicious attack. For Linux users , it's advisable to disable the single mode booting (a.k.a boot mode single in Debian/Gentoo or init 1 in Fedora/Redhat). the reason. Simply allowing it disable the purpose of security itself :).

Well leaving the security lectures above . Today I'm quite please with myself by obtaining 10-20 passwords from various Windows Box . So parents i recommend Ophrack to have a sneak peak on what;s goin on in your kids PC today.
Ophrack is a cracker tool based on Rainbow Tables and support various LM accent.

Based on my assumption (people tend to put their password in purely 6-8 character of alphanumeric) It shouldn't take more then 5-6 minutes to crack up the hashes (on a 1gighz Intel Machine).

To counter the problem? make yourself an anagram of alphanumeric password 20 character should enough :)

3 comments:

Anonymous said...

hehehe..
i strongly agree with you..

20 chars passwd..

i lost my passwd, can i have yours? :p

Anonymous said...

aku ada gak pakai software camnie. Linux Boot tp xde GUI la. hehehehe. dlm 2 min setel la crack pwd.

<~!@#> said...

Well the time it takes to crack pwd depends on the strength of the password also cpu capability to calculate the infinite state engine. (Try crack an 14 character alphanumeric pwd inside a Vm) aiyoo. 2-3 bulan lum tentu leh siap