<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Truecrypt, a variety of bruteforcing options</title>
	<atom:link href="http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/feed/" rel="self" type="application/rss+xml" />
	<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/</link>
	<description>Attempting to understand security</description>
	<lastBuildDate>Fri, 13 Nov 2009 14:22:14 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: LiquidMK</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-188</link>
		<dc:creator>LiquidMK</dc:creator>
		<pubDate>Tue, 03 Nov 2009 22:57:26 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-188</guid>
		<description>Wow, [b]james[/b] described really magic algorithm of forgotten password recovery! I&#039;d made dictionary with Excel macro and with true.crypt.brute it took just about 5 minutes to recover my data! )
I&#039;m happy!!!</description>
		<content:encoded><![CDATA[<p>Wow, [b]james[/b] described really magic algorithm of forgotten password recovery! I&#8217;d made dictionary with Excel macro and with true.crypt.brute it took just about 5 minutes to recover my data! )<br />
I&#8217;m happy!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: German</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-179</link>
		<dc:creator>German</dc:creator>
		<pubDate>Sat, 17 Oct 2009 23:12:21 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-179</guid>
		<description>Hi guys,

could you tell me how to use that software now exactly concerning the word file. do i just have to copy and paste it? 

more important: how can i edit or modify it in such way that there are just some letters left which habe to be combined to brute force the correct password? i wanna reduce it to the letters i&#039;m sure that they are the right one, i just lost the sequence...

Cheers!!!</description>
		<content:encoded><![CDATA[<p>Hi guys,</p>
<p>could you tell me how to use that software now exactly concerning the word file. do i just have to copy and paste it? </p>
<p>more important: how can i edit or modify it in such way that there are just some letters left which habe to be combined to brute force the correct password? i wanna reduce it to the letters i&#8217;m sure that they are the right one, i just lost the sequence&#8230;</p>
<p>Cheers!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 1664</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-175</link>
		<dc:creator>1664</dc:creator>
		<pubDate>Tue, 06 Oct 2009 15:25:04 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-175</guid>
		<description>Thanks for the info Diablohorn &amp; James, i changed my password while drunk and now dont remember it :(  i usually use a combo of about 3-4 diff words out of 10 or so that are personal to me so am hoping the excel and macro method will help me out, again thanks for sharing your info</description>
		<content:encoded><![CDATA[<p>Thanks for the info Diablohorn &amp; James, i changed my password while drunk and now dont remember it <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />   i usually use a combo of about 3-4 diff words out of 10 or so that are personal to me so am hoping the excel and macro method will help me out, again thanks for sharing your info</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: diablohorn</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-158</link>
		<dc:creator>diablohorn</dc:creator>
		<pubDate>Mon, 07 Sep 2009 22:19:50 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-158</guid>
		<description>here is a new link and the link above has been adjusted:

http://diablohorn.tbhost.eu/distribute/truecrypt_brute_building_blocks.zip</description>
		<content:encoded><![CDATA[<p>here is a new link and the link above has been adjusted:</p>
<p><a href="http://diablohorn.tbhost.eu/distribute/truecrypt_brute_building_blocks.zip" rel="nofollow">http://diablohorn.tbhost.eu/distribute/truecrypt_brute_building_blocks.zip</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dave</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-157</link>
		<dc:creator>dave</dc:creator>
		<pubDate>Sat, 05 Sep 2009 19:30:52 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-157</guid>
		<description>The link above to the zip is dead (rapid share). says been removed?</description>
		<content:encoded><![CDATA[<p>The link above to the zip is dead (rapid share). says been removed?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Saiketsu</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-152</link>
		<dc:creator>Saiketsu</dc:creator>
		<pubDate>Wed, 05 Aug 2009 17:50:52 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-152</guid>
		<description>James, i&#039;m gald to see that someone used the same method than me to create a super-password, then lost it and recovered it with a BF. I&#039;m going to try your method. Thanks ! :)</description>
		<content:encoded><![CDATA[<p>James, i&#8217;m gald to see that someone used the same method than me to create a super-password, then lost it and recovered it with a BF. I&#8217;m going to try your method. Thanks ! <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christoph</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-148</link>
		<dc:creator>Christoph</dc:creator>
		<pubDate>Fri, 17 Jul 2009 14:31:31 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-148</guid>
		<description>@dezrah: You&#039;re chances are actually pretty good to crack the password. Assuming you have an alphabet of 11 characters and a 9 character password. If you did not use duplicates, you have about 20 million combinations. 

If you did use multiples, your search space is 285 billion. However, again assuming that you would not use a word like fffffffff (e.g. limit to max. character reuse of 2) you might end up with something like more manageable like in the lower hundred millions or so ;-)</description>
		<content:encoded><![CDATA[<p>@dezrah: You&#8217;re chances are actually pretty good to crack the password. Assuming you have an alphabet of 11 characters and a 9 character password. If you did not use duplicates, you have about 20 million combinations. </p>
<p>If you did use multiples, your search space is 285 billion. However, again assuming that you would not use a word like fffffffff (e.g. limit to max. character reuse of 2) you might end up with something like more manageable like in the lower hundred millions or so <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DiabloHorn</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-147</link>
		<dc:creator>DiabloHorn</dc:creator>
		<pubDate>Fri, 17 Jul 2009 08:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-147</guid>
		<description>This is interesting information. I&#039;m glad you found your password. It will always be worth a shot if some information is known about the password.</description>
		<content:encoded><![CDATA[<p>This is interesting information. I&#8217;m glad you found your password. It will always be worth a shot if some information is known about the password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: james</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-146</link>
		<dc:creator>james</dc:creator>
		<pubDate>Fri, 17 Jul 2009 02:53:32 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-146</guid>
		<description>So after running overnight the password was waiting for me on my desktop.  Definitely a solution that works, at least in my example; turned out my password was a combination I would never have thought of.  I ran a word list that had 14k possibilities, using Excels to combine 7? passwords 4 deep into every possible combination (always 4 deep).  If you are reading this then good luck and keep your passwords strong and write them down somewhere...my &quot;super password&quot; was 40 characters long...without knowing what made it up I think I would have needed a Cray or something to get it done, and then I probably would have had to wait a few years.</description>
		<content:encoded><![CDATA[<p>So after running overnight the password was waiting for me on my desktop.  Definitely a solution that works, at least in my example; turned out my password was a combination I would never have thought of.  I ran a word list that had 14k possibilities, using Excels to combine 7? passwords 4 deep into every possible combination (always 4 deep).  If you are reading this then good luck and keep your passwords strong and write them down somewhere&#8230;my &#8220;super password&#8221; was 40 characters long&#8230;without knowing what made it up I think I would have needed a Cray or something to get it done, and then I probably would have had to wait a few years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: james</title>
		<link>http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/#comment-145</link>
		<dc:creator>james</dc:creator>
		<pubDate>Thu, 16 Jul 2009 02:35:12 +0000</pubDate>
		<guid isPermaLink="false">http://diablohorn.wordpress.com/?p=147#comment-145</guid>
		<description>I found your information informative, but not very useful.  I tried the script mentioned with the autoit program and could not get it to work.  Searching through the autoit forums found that the guy that wrote it (the real author) was asking about how to get it to run and ditched it because it was flawed.  I  could not get my BT4 running on my VMWare Fusion and did not have a thumbdrive handy, so I went with a VMWare Windows solution.  I found a program called true.crypt.brute that runs dictionary attacks against truecrypt containers.  It can be found at securityvision.ch/download.php.  I had to create a custom dictionary because my problem was as follows:  I got paranoid and put a bunch of personal files into one giant container (20gb), and used 4 or 5 strong passwords (that I routinely use) to generate a super-password.  Unfortunately I forgot to write the awesome password down, so I didn&#039;t know the order the smaller passwords were in.  In my own defense I was on some powerful painkillers at the time, but that is another story.  I needed an automated way to find the password.  So...after much searching came to the brute forcer mentioned.  I did some more searching for the dictionary fix, and came up with using Excels and a macro, which can be found by &quot;googling&quot; google answers phrase permutation.  With these two tools I have generated over 12k possibilities.  Unfortunately the brute forcer takes approximately .5 seconds per try.  When it is completed it will pop up with the correct password...I&#039;ll let you know when it finishes.   I would guess that all of this research took 12 hours or so.  I did find some other useful, easy to use tools in my search, including a great password generator (unfortunately it will only mix 2 deep vice the 4-5 I needed).  It  is called s-wordlist tool, though I don&#039;t remember where I found it.  It was written by &quot;beda&quot; and has a link in it, &quot;beda.securiboxDOTnet&quot;.  I could not find it in 5 min and am done researching, but it is a great dictionary creation tool with more options than I found anywhere else.</description>
		<content:encoded><![CDATA[<p>I found your information informative, but not very useful.  I tried the script mentioned with the autoit program and could not get it to work.  Searching through the autoit forums found that the guy that wrote it (the real author) was asking about how to get it to run and ditched it because it was flawed.  I  could not get my BT4 running on my VMWare Fusion and did not have a thumbdrive handy, so I went with a VMWare Windows solution.  I found a program called true.crypt.brute that runs dictionary attacks against truecrypt containers.  It can be found at securityvision.ch/download.php.  I had to create a custom dictionary because my problem was as follows:  I got paranoid and put a bunch of personal files into one giant container (20gb), and used 4 or 5 strong passwords (that I routinely use) to generate a super-password.  Unfortunately I forgot to write the awesome password down, so I didn&#8217;t know the order the smaller passwords were in.  In my own defense I was on some powerful painkillers at the time, but that is another story.  I needed an automated way to find the password.  So&#8230;after much searching came to the brute forcer mentioned.  I did some more searching for the dictionary fix, and came up with using Excels and a macro, which can be found by &#8220;googling&#8221; google answers phrase permutation.  With these two tools I have generated over 12k possibilities.  Unfortunately the brute forcer takes approximately .5 seconds per try.  When it is completed it will pop up with the correct password&#8230;I&#8217;ll let you know when it finishes.   I would guess that all of this research took 12 hours or so.  I did find some other useful, easy to use tools in my search, including a great password generator (unfortunately it will only mix 2 deep vice the 4-5 I needed).  It  is called s-wordlist tool, though I don&#8217;t remember where I found it.  It was written by &#8220;beda&#8221; and has a link in it, &#8220;beda.securiboxDOTnet&#8221;.  I could not find it in 5 min and am done researching, but it is a great dictionary creation tool with more options than I found anywhere else.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
