|
Message-ID: <CANWtx01y5mgbSytXVZc9Zve_-hdGxc_NRaSXbYdqi3MpRMOb3A@mail.gmail.com> Date: Tue, 8 Oct 2013 13:43:30 -0400 From: Rich Rumble <richrumble@...il.com> To: john-users@...ts.openwall.com Subject: Re: How best to compute this via john On Tue, Oct 8, 2013 at 12:11 PM, Stephen John Smoogen <smooge@...il.com>wrote: > > http://arstechnica.com/security/2013/10/how-the-bible-and-youtube-are-fueling-the-next-frontier-of-password-cracking/2/ > > Someone, not me, needs to create a parser for IMDB, http://imdbpy.sourceforge.net/ I've not been able to make use of that yet. You can mirror IMDB's text database's http://www.imdb.com/interfaces by visiting those FTP links. I've long used the Free-CDDB database, full of perfect phrases and pop culture. My perl scripts for extracting the data from it (free-cddb) are not so good, but the list I've made has been useful nonetheless. Movie titles, song names, artist's, famous quotes are all good places to start. What end's up happening however, and this is where more needs to be done, is that you get a ton of phrases to use, but no ranking or knowledge of what is more likely to work. That's what is needed to be more effective at cracking pass phrases, some ranking system or the like. See how many google results come back for a pharse or something? Or a bandname/artist name? Might help weed out some phrases that won't come up. As far as mangling rules, you'd need to insert spaces, remove spaces, add space and cap the next letter after the space, remove the space and cap the letter after the removed space. Remove all but the first letter after each space "ask not what you can do for you're country" = anwycdfyc Stuff like that too :) -rich
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.