home.social

#bcrypt — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bcrypt, aggregated by home.social.

  1. Since Wordpress v6.8, the default hash func produces a custom bcrypt hash: $wp$2y$10$...

    More info on this custom algo, how it uses hmac-sha384, and how to crack them with hashcat.

    forum.hashpwn.net/post/4205

    #wordpress #bcrypt #wpbcrypt #hashcracking #hashpwn #hashgen #hashcat

  2. Hoy aprendí sobre el algoritmo de hash #bcrypt, basado en el cifrador de bloques #Blowfish, revisando un artículo de @andrea_navarro sobre extensiones de #Flask... particularmente sobre las extensiones de seguridad.

    Y acabo de descubrir que es uno de los algoritmos soportados para la creación de passwords en GNU/Linux :D

    Habrá que hacer algunos experimentos.

    #gnu #linux #cryptography #criptografía #ciberseguridad #infosec #encrypt #hash #python #flask

  3. So ... due to an early obsession with historical BSD hashes ... I have significantly more bcrypt hashrate-per-watt cracking capacity than most solo shops. For bcrypt cost 12, it's about 34Kh/s straight wordlist -- the equivalent of about 17 4090s -- at only 1100W (these old Bitcoin FPGAs are very efficient for bcrypt specifically). And this capacity is intermittently idle, which is kinda a shame.

    I haven't really put it out there as something I can help with if needed (outside of the Hashcat team). So ... feel free to ping me if you need bcrypts cracked/audited!

    (Reasonable rates, but note that I do have a pretty firmly high bar for provenance / proof of authorization)

    (Rat's nest of USB has been cleaned up a bit 😅)

    #bcrypt #PasswordCracking #hashing

  4. Need a quick way to check a hash against a huge database?

    I've written a small but flexible Go CLI tool to query the HashMob API.

    It's actually pretty damn handy if I do say so myself.

    If you find it useful, stars and boosts are much appreciated ❤️

    github.com/n0kovo/gohashmob

    (just starting to learn Go, don't judge my probably horrible code 🥹)

    #hacking #infosec #tools #osint #passwordcracking #passwords #passwordsecurity #hashcracking #hashlookup #hashmob #md5 #sha1 #bcrypt #pentesting #bugbounty #redteam

  5. Thingiverse Data Leaked — Check Your Passwords - Every week seems to bring another set of high-profile data leaks, and this time it... - hackaday.com/2021/10/14/thingi #securityhacks #thingiverse #databreach #makerbot #bcrypt #sha-1 #news