Upgrade to Pro — share decks privately, control downloads, hide ads and more …

PANIC Project

Avatar for Jacob Jacob
February 27, 2012

PANIC Project

Slides from a Lightning talk at Brucon 2011 in Sept on project I have been working on for the past 3 months

Avatar for Jacob

Jacob

February 27, 2012
Tweet

More Decks by Jacob

Other Decks in Technology

Transcript

  1. The Project • Find Passwords and Emails • Normalize the

    data • Put it in a database • Compare or correlate emails and passwords (think RockYou but automated)
  2. The Project (contd.) • Pull apart passwords to find useful

    data (numbers of upper case, lower case, numbers, and/or special characters) • Make pretty graphs (oooh pretty graphs)
  3. Origins • Started as a blog post with Gawker(Drink!) and

    Lulzsec(Drink!) leaks. • Decided Pastebin was a good idea for more data and for a constant stream of new data and fresh data.
  4. Current Progress • An idea • No working code. Well...

    no code. • A really good idea • People interested in helping
  5. Future goals • The ability to upload one-off drops/leaks to

    the website • Quarterly “reports” on the top ~100 passwords and their stats • Compare reports to previous reports
  6. Future Goals (contd.) • Possibly pull in time to crack

    based on password policy • Take hashed passwords and give them to a password cracker to get even more data • ??? • Profit?