Saturday, February 20, 2010

Using THC Hydra to bruteforce passwords

I've started experimenting with THC Hydra to brute-force passwords on my home Ubuntu box.

1. First, install OpenSSL and GTK toolkit dependencies, which are required by Hydra.
sudo apt-get install libssl-dev libgtk2.0-dev

2. Next, get the Hydra source code.
wget -c

3. Unpack the archive.
tar -xzvf hydra-5.4-src.tar.gz
cd hydra-5.4-src/

4. Compile the Hydra
vi Makefile <- and remove the "-lpq" and "-DLIBPOSTGRES" statements

5. hydra -L users.txt -P password.txt -e ns -vV -t 1 http-post-form "/bb/login:email=^USER^&password=^PASS^:Not allowed"

768-bit RSA modulus has been factored

A rather exciting paper appeared on ePrint a few days ago:
A team of researchers succeeded in factoring a 768-bit RSA modulus.
In many practical applications nowadays, we use a larger 1024-bit RSA modulus for signatures and encryption. This result raises a question of "For how long are 1024-bit encryption/signatures secure?". The authors claim that they are for the next three-four years, and suggest switching onto larger modulus such as 2048.

Friday, February 19, 2010

The security blog is born.

Today, I decided to create a blog with my ruminations on the theory and practical applications of information security. I hope that my readers will find it useful!