TOTP brute-force search incomplete?
#3
I was able to add -T 1 (and, as required by -T, --force) to set the kernel thread count to 1. This technically slows things down, but still runs in 1 second.
Code:
hashcat64.exe --potfile-path=totp.potfile -a 3 -m 18100 --keep-guessing -T 1 --force totp.hash ?l?l?l?l?l hashcat (v5.1.0) starting... OpenCL Platform #1: NVIDIA Corporation ====================================== * Device #1: Quadro P2200, 1280/5120 MB allocatable, 10MCU OpenCL Platform #2: Intel(R) Corporation ======================================== * Device #2: Intel(R) UHD Graphics 630, 4095/13039 MB allocatable, 24MCU * Device #3: Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, skipped. Hashes: 2 digests; 2 unique digests, 2 unique salts Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates Applicable optimizers: * Zero-Byte * Not-Iterated * Brute-Force Minimum password length supported by kernel: 0 Maximum password length supported by kernel: 256 Watchdog: Temperature abort trigger set to 90c 671202:1000000000:O5RWS6DB 455543:1000001000:PBYWM2LO 671202:1000000000:ORRW22LB 671202:1000000000:MFUGC43I 455543:1000001000:MFUGC43I 455543:1000001000:MJSGY3DZ 671202:1000000000:NBRXM6LP 455543:1000001000:OZWGS5TV 455543:1000001000:O5WWI3DV 455543:1000001000:N5SGC3TU 455543:1000001000:M5RWG23O 455543:1000001000:MR4HIYLI 455543:1000001000:NZTG46LE 671202:1000000000:OBWW4ZDH 455543:1000001000:MF3WSYLJ 455543:1000001000:NJXHAZTK 455543:1000001000:M52HA2TT 671202:1000000000:MFRG24TD 455543:1000001000:PB2WC6TT 455543:1000001000:MZ3HM33F 455543:1000001000:MRYWC23C 455543:1000001000:MNTHEYL2 455543:1000001000:NN5G22DE 671202:1000000000:NJ5GM5LK 671202:1000000000:NJ3WU53R 455543:1000001000:O5SHA4DY 671202:1000000000:NVSHMYTY 671202:1000000000:MN4WOZTY 455543:1000001000:MJ2W45TY Approaching final keyspace - workload adjusted. 671202:1000000000:NZVXC6TW Session..........: hashcat Status...........: Exhausted Hash.Type........: TOTP (HMAC-SHA1) Hash.Target......: .\totp.hash Time.Started.....: Fri Jun 19 15:25:36 2020 (1 sec) Time.Estimated...: Fri Jun 19 15:25:37 2020 (0 secs) Guess.Mask.......: ?l?l?l?l?l [5] Guess.Queue......: 1/1 (100.00%) Speed.#1.........: 15497.5 kH/s (7.05ms) @ Accel:512 Loops:26 Thr:1 Vec:1 Speed.#2.........:  2728.6 kH/s (6.93ms) @ Accel:32 Loops:26 Thr:1 Vec:1 Speed.#*.........: 18226.2 kH/s Recovered........: 0/2 (0.00%) Digests, 0/2 (0.00%) Salts Progress.........: 23762752/23762752 (100.00%) Rejected.........: 0/23762752 (0.00%) Restore.Point....: 453938/456976 (99.34%) Restore.Sub.#1...: Salt:1 Amplifier:0-26 Iteration:0-26 Restore.Sub.#2...: Salt:1 Amplifier:0-26 Iteration:0-26 Candidates.#1....: suxjq -> xqxvq Candidates.#2....: sdmfq -> xipfq Hardware.Mon.#1..: Temp: 44c Fan: 51% Util: 94% Core:1746MHz Mem:5005MHz Bus:16 Hardware.Mon.#2..: N/A

Strangely, it still skipped 3 (it gave me 30, I expected 33): OFRGE2LN, NZZGWZTE, & MN2HO3DC. Any ideas if other switches might help? I understand it will be slower, but obviously much faster than my Python example.
Reply


Messages In This Thread
TOTP brute-force search incomplete? - by geitda - 06-19-2020, 06:10 PM
RE: TOTP brute-force search incomplete? - by geitda - 06-19-2020, 09:38 PM