DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [dm-crypt] LUKS & search for passphrase using dictionary
@ 2012-07-19 22:48 Milan Broz
  2012-07-19 23:34 ` Arno Wagner
  0 siblings, 1 reply; 2+ messages in thread
From: Milan Broz @ 2012-07-19 22:48 UTC (permalink / raw)
  To: dm-crypt

Hi,

From time to time someone tries to recover (or crack) LUKS passphrase
using dictionary lists.
I saw lately even some crazy patches for cryptsetup doing that.

Please do not patch source or create some slow bash scripts
(initialization and memory locking cost resources).
Just use libcryptsetup. I added some example how to do it, see

http://code.google.com/p/cryptsetup/source/browse/#git%2Fmisc%2Fdict_search

e.g. for JTR known password list you can run (on quadcore cpu here)
  # luks_dict test.img /usr/share/john/password.lst 4

Then read FAQ how LUKS keyslot iterations slow down these attacks...

It is just quickly written example, perhaps with some bugs.

Anyway, enjoy :)
Milan

p.s.
If you really run this, compile cryptsetup with openssl support
(configure --with-crypto_backend=openssl) it is quicker than default gcrypt. 

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2012-07-19 23:34 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-07-19 22:48 [dm-crypt] LUKS & search for passphrase using dictionary Milan Broz
2012-07-19 23:34 ` Arno Wagner

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox