Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Length of time for bruteforce
EH-Net
May 25, 2013, 03:03:59 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Length of time for bruteforce  (Read 5029 times)
0 Members and 1 Guest are viewing this topic.
cochese86
Newbie
*
Offline Offline

Posts: 9


View Profile
« on: June 20, 2011, 01:21:38 PM »

Hello,

I was wondering what the most amount of time you would allocate during a pen test to bruteforcing?  As an example, if you discover a vpn router and are able to catch the handshake, what's a reasonable amount of time to spend bruteforcing the PSK?  What about if you get ahold of the hashes on a box?

Thanks in advance.
Logged
abgenius
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #1 on: June 23, 2011, 03:35:17 PM »

Use this site
http://lastbit.com/pswcalc.asp
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #2 on: June 24, 2011, 02:20:13 AM »

just turn on the brute forcer and continue with other things. it it comes up with a password focus on it again, if not report that you tried and did not come up with results within the allocated time. Remember to state that it is not a guarantee that the VPN is safe from bruteforcing, and recommend to always use a strong password.
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
cochese86
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #3 on: June 26, 2011, 12:56:04 PM »

Cool, thanks for the replies.  I'm also looking into gpu cracking as the calculator posted said it would take 58 years to crack and 8 character password with caps, lower case, and special characters.
Logged
El33tsamurai
Full Member
***
Offline Offline

Posts: 192


View Profile
« Reply #4 on: June 26, 2011, 03:13:09 PM »

but you take the gamble what they didn't use a strong password.
Logged

CCENT, A+, Network+, Security+
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #5 on: June 27, 2011, 02:37:38 AM »

Cool, thanks for the replies.  I'm also looking into gpu cracking as the calculator posted said it would take 58 years to crack and 8 character password with caps, lower case, and special characters.

lol, thats pretty oudated, even if you do it with your CPU, assuming you use a multi-code. for more information about GPU cracking, read up on this:
http://www.backtrack-linux.org/documents/BACKTRACK_CUDA_v2.0.pdf
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
cochese86
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #6 on: June 27, 2011, 02:33:17 PM »

but you take the gamble what they didn't use a strong password.

I ran a dictionary attack first and then let a bruteforcer go for 5 days.  I'm thinking it's not a simple password.  I was just originally curious what would be an acceptable length of time.


lol, thats pretty oudated, even if you do it with your CPU, assuming you use a multi-code. for more information about GPU cracking, read up on this:


Yeah, I'm new I guess, just looking at better ways to work.  Thanks for the link!
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.085 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.