Blackhat Regional Summit São Paulo 2014 (Nov/2014)
We do a lot of password cracking these days. Hashes from owned systems pop out frequently on Pastebin and Twitter, and it is not unusual to find a nice SQL injection that allows you to dump the entire login table from a web application. However, we still use the same old wordlists and rules.
Presented during Blackhat Regional Summit São Paulo 2014, this talked aimed to provide a fresh view on password cracking research through showing positive results, drawbacks, failures, and challenges while cracking passwords from .br domains; testing the performance of some popular wordlists against different scenarios; identifying patterns and behavior of users while choosing their passwords, beyond 'qwerty'; and providing tools, scripts, rules, and wordlists to aid in cracking Brazilian passwords but useful for any language.
Read more:
Code & others:
Black Hat Regional Summit São Paulo: