Members: AMD, blazer, gearjunkie, golem445, hops, meowmeowbean, s3inlc, waffle, winxp5421 usasoft (infra) Introduction A huge thanks to KoreLogic for once again hosting the annual premier password cracking contest. This year we finally saw the appearance of Argon2 hashes, along with other weird and wonderful algorithms such as saph512, RC2, gocrypt & broken SHA1s. Congratulations to HashMob for…
Members that participated (10 crackers/ 1 support) s3in!c golem445 hops blazer gearjunkie winxp5421 AMD cvsi pdo Waffle Usasoft (support) Peak computing power (25-30 standardized to 4090) Before the contest The test hashes gave us a gleam of what the potential hash data would look like. After successfully cracking all the test hashes, we noticed very heavy use of UTF-8 encoded characters. We…
What a breath of fresh air to have DEF CON 30 not be canceled this year. We are thankful that Korelogic’s CMIYC is running strong 13 years in. Going into this contest we assumed the competition would be quite fierce, however we are always up for a fair challenge. As most members on our team are hobbyist password crackers not working in the cybersec industry, this gave us a wonderful opportunity to…
Crack me if you can write-up 2021 Normal 0 false false false EN-AU X-NONE X-NONE We once again assembled the team to take on KoreLogic’s annual Crack me if you can contest for Def Con 29. This year we had 12 members participating they were s3in!c, blazer, golem445, user, pdo, winxp5421, Waffle, gearjunkie, hops, cvsi, 0xln & usasoft. Since we were from all over the world, we were able to…
Rough hardware estimate Hardware Count Hardware Count 2080 TI 2 1070 25 1080 TI 22 1060 6 1080 15 970 2 1070 TI: 7 CPU Physical Core: 892 Software used John the ripper + MPI Passcovery Suite Hashcat Bcval Hashtopolis This year we had 15 members compete, we welcome 0xln, golem445, and John_Smith to the team. Tremendous thank you to Korelogic for hosting the 8th Defcon Crack Me If You Can, it was a…
Over the years the members of the group have participated in quite a few password contests. Positive hack days’s Hashrunner, Defcon | Derbycon’s Crack Me If You Can, and SaintCon’s Pcrack. In fact, Hashrunner was the first contest Cynosure Prime competed in as a team. We love password cracking, especially come contest time. There is something special about the team atmosphere during contests, the…
Crack me if you can write-up 2018 Active participating members 15 GPUs equivalent to GTX1080 peak 60 GPUs equivalent to GTX1080 constant 40 CPU threads peak 1300 CPU threads constant 600 Contest related Instant Messages sent ~7000 Hash:plain submissions to internal platform >5300 Hash:plain submissions to Korelogic 2293 Members blazer cvsi espira gearjunkie hops m33x mastercracker milzo jimbas…
Earlier this month (August 2017) Troy Hunt founder of the website Have I been pwned? [0] released over 319 million plaintext passwords [1] compiled from various non-hashed data breaches, in the form of SHA-1 hashes. Making this data public might allow future passwords to be cross-checked in a secure manner in the hopes of preventing password re-use, especially of those from compromised breaches…
32hex is not MD5? What are Youku talking about? During April 2017, various online sources alleged that Youku, a Chinese video hosting service was hacked and that roughly 100 million user accounts were compromised. These sources stated that Youku usernames along with passwords hashed with MD5 and SHA1 algorithms were leaked. We decided to take a closer look in early June and will be presenting our…
Recovered Percent Total 360,213,049 Usable data 359,005,905 355,886,686 99.13% Unique 116,822,086 113,830,176 97% Salted hashes 68,494,253 Salted pairs 66,099,059 47,120,453 71.29% non-user pass 14,412,299 5,831 0.04% meaningful passes 51,686,760 47,114,622 91.15% When we obtained the Myspace data, we didn’t think too much of it for several reasons. In addition to being a fairly old data-set, the…
We would like to present some statistics based on our current finds of roughly 11.7 million passwords. Firstly, we would like to state that we are predominantly targeting a 15 million subset of the 36 million potential passwords. Secondly, bear in mind that we still haven't cracked about 4 million tokens, all of which could affect the findings presented here. Total password entries = 11,716,208…
Not long after the release of the Ashley Madison leaks, many groups and individuals attempted to crack the bcrypt hashes. Since the developers used a cost factor of 12 for the bcrypt hash, this made the process an extremely compute intensive task. We decided to take a different approach and made some rather interesting discoveries. Without much information about the $loginkey variable and how it…
We have attached some binaries and src of most of the resources used by our team for Hashrunner 2015 Package includes -src and binaries for challenges 7, 8 & 9 -Binaries for the crackers/generators for the PHC finalist algorithms Argon, Battcrypt Lyra2, Parallel & POMELO (which we did not end up using, but had ready in anticipation). Download here Note: Most of the code was pulled together quickly…
We have posted up our team write-up for hashrunner2015 Our resources used in the contest will be released shortly Congrats Team Hashcat, you guys really owned it!!