Dennis has released a paper describing his FPGA cracker
There has been 2 Comments posted on this article
December 14th, 2009 at 10:48 am
Pete Finnigan says:
Hi Alex,
Thanks for the comment, i was aware of this already when i tested it. At the time as Dennis had limited the character set and also the length it was relevant but sort of a side issue if you were not allowed to use the complete chartacter set to create a password starting with a digit (i.e. encase the password in quotes) then it was true but didnt help a lot.
The upside is most sites dont have passwords using digits as the first character or extended characters above a-z0-9_#$, thanks for the comment though, sorry for the delayed response I have been working away.
cheers
Pete
December 7th, 2009 at 05:34 pm
Pete Finnigan says:
Hi Pete
I blogged already yesterday about this FPGA paper. There is a small but important flaw in the implementation. Passwords starting with a number (alter user alex identified by "1" are not found. Dennis confirmed this issue.
Details can be found in my blog (http://blog.red-database-security.com/2009/12/06/dennis-yurichev-wrote-an-article-about-his-fpga-oracle-password-cracker/).
Regards
Alexander
--
Red-Database-Security GmbH