System update
On Tuesday, August 18th, between 12-1pm, a planned system update of DiVA will take place. During this time, DiVA will not be available.
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Prestandajämförelse mellan populära lösenordsknäckare och metoder
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2024 (Swedish)Independent thesis Basic level (degree of Bachelor), 5 credits / 7,5 HE creditsStudent thesisAlternative title
Performance comparison between popular password crackers and methods (English)
Abstract [sv]

I detta arbete har en jämförelse gjorts mellan olika lösenordsknäckare och metoder samt hur de presterar i förhållande till varandra. Jämförelsen har utförts genom att testa 3 lösenordsknäckare i 3 lägen. Närmare bestämt; bruteforce, dictionary och hybrid. Detta har gjorts för 9 lösenord och 5 försök till varje lösenord. Det som kan observeras är att Hashcat är den snabbaste när det gäller bruteforce-attacker medan John the Ripper är den snabbaste när det kommer till dictionary attacks. Dictionary-attacker presterar lika bra som bruteforce på korta lösenord medan de överträffar bruteforce avsevärt på längre "välkända" lösenord.

Hybrid-attacker utfördes av Hashcat och visade sig prestera sämre än dictionary-attacker men bättre än bruteforce-attacker på mer komplexa lösenord, dock sämre på kortare lösenord. Hydra presterade sämst och lyckades inte knäcka ett enda lösenord under tidsgränsen.

Resultaten visade också att ett mer komplext lösenord inte nödvändigtvis är säkrare än ett mindre komplext. Dictionary-attacker som innehåller miljontals välkända lösenord kommer att knäcka lösenordet oavsett om det är långt eller kort. Allt beror på om lösenordet finns i ordlistan eller inte. Läggs hybrid-attacker till på det så visade det sig att det mest säkra lösenordet innehöll ett specialtecken i början, bokstäver i mitten och en siffra efter. Ingen av metoderna lyckades knäcka det inom den angivna tidsgränsen. Bruteforce däremot handlar helt om lösenordslängd eftersom algoritmen manuellt testar varje kombination inom adressrymden. Därför, ju fler tecken som finns, desto fler möjliga kombinationer finns det och desto svårare är det för datorn att beräkna det hela.

Därmed är det mest säkraste lösenordet ett lösenord som använder en unik teckenföljd. Helst inga faktiska ord där även specialtecken samt siffror inkorporeras. Längden bör vara minst 10 tecken för att det ska vara för långt för att en bruteforce-attack ska kunna utföras samt minska chansen att lösenordet finns i tidigare databasläckor.

Abstract [en]

In this work a comparison between different password crackers and methods has been made as well as how they fare against each other. The comparison has been done by testing 3 password crackers in 3 different modes, those being bruteforce, dictionary and hybrid mode. 9 passwords in total have been used where each individual instance have been run 5 times. What can be seen is that Hashcat is the fastest when it comes to bruteforcing pass-words and John the Ripper is the fastest when it comes to dictionary attacks. Dictionary at-tacks performs equal to bruteforce on short passwords while dictionary attacks outper-form bruteforce by far on longer "well known" passwords.

Hybrid attacks were carried out by Hashcat and turned out to be inferior to dictionary attacks but superior to bruteforce attacks on more complex passwords although worse on shorter passwords. Hydra per-formed the worst and did not manage to crack a single password within the time limit.

The results also showed that a more complex password does not necessarily mean it is safer than a less complex one. Dictionary attacks containing millions of already used passwords will crack it regardless of it being long or short. It all depends on if the password exists in the wordlist or not. Adding hybrid attacks on top of that, the most secure type of password ultimately turned out to be one with special characters at the start, letters in the middle and a number after. Neither method was able to crack that within the given time limit. Bruteforce on the other hand is all about password length because the algorithm manually tries every combination within the address space. Thus, the more characters you have, the more combinations exists and the harder it is for the computer to compute it all.

Ultimately, the most secure password is a password which uses a unique character sequence. Preferably no actual words where special characters as well as numbers are incor-porated. The length should be a minimum of 10 characters therefore it will be too long to be bruteforced as well as lowering the chance of it being included in any previous database leaks.

Place, publisher, year, edition, pages
2024. , p. 10
Keywords [en]
Kryptografi, Pentesting, Hash, Hashcat, Hydra, John the Ripper, Password security Ethical hacking
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-21872Local ID: EXN300OAI: oai:DiVA.org:hv-21872DiVA, id: diva2:1873369
Subject / course
Computer engineering
Educational program
Nätverksteknik med IT-säkerhet
Supervisors
Examiners
Available from: 2024-06-28 Created: 2024-06-19 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 786 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf