Blackhat Regional Summit São Paulo 2014 (Nov/2014)
We do a lot of password cracking these days. Hashes from owned systems pop out frequently on Pastebin and Twitter, and it is not unusual to find a nice SQL injection that allows you to dump the entire login table from a web application. However, we still use the same old wordlists and rules.
Presented during Blackhat Regional Summit São Paulo 2014, this talked aimed to provide a fresh view on password cracking research through showing positive results, drawbacks, failures, and challenges while cracking passwords from .br domains; testing the performance of some popular wordlists against different scenarios; identifying patterns and behavior of users while choosing their passwords, beyond 'qwerty'; and providing tools, scripts, rules, and wordlists to aid in cracking Brazilian passwords but useful for any language.
Read more: http://codalabs.net/gameofhashes
Code & others: https://github.com/BRDumps
Black Hat Regional Summit São Paulo: https://www.blackhat.com/sp-14/summit.html#a-song-of-hashes-and-dumps-what-ive-learned-from-cracking-br-passwords