Você está na página 1de 5

Lockdown.co.

uk - The Home Computer Security Centre


LockDown is the source for security information and resources for the home computer user.

Password Recovery Speeds


Support Incident Tracker
How long will your password stand up
Elvis Impersonator
Debt Management This document shows the approximate amount of time required for a computer or a cluster of computers to guess various passwords.
The figures shown are approximate and are the maximum time required to guess each password using a simple brute force
"key-search" attack, it may (and probably will) be possible to guess correctly without trying all the combinations shown using other
methods of attack or by having a "lucky guess".
See the bottom of the page for details about the classes of attack.

10 Characters
Just numbers. As you can see choosing a password from such a small range of characters is a bad idea.

Numerals 0123456789
Password Class of Attack
Length Combinations Class A Class B Class C Class D Class E Class F
2 100 Instant Instant Instant Instant Instant Instant
3 1000 Instant Instant Instant Instant Instant Instant
4 10,000 Instant Instant Instant Instant Instant Instant
5 100,000 10 Secs Instant Instant Instant Instant Instant
6 1 Million 1½ Mins 10 Seconds Instant Instant Instant Instant
7 10 Million 17 Mins 1½ Mins 1½ Mins Instant Instant Instant
8 100 Million 2¾ Hours 17 Mins 1½ Mins 10 Seconds Instant Instant
9 1000 Million 28 Hours 2¾ Hours 17 Mins 1½ Mins 10 Seconds Instant

26 Characters
The full alphabet, either upper or lower case (not both in this case).

Upper Case Alpha ABCDEFGHIJKLMNOPQRSTUVWXYZ


Lower Case Alpha abcdefghijklmnopqrstuvwxyz
Password Class of Attack
Length Combinations Class A Class B Class C Class D Class E Class F
2 676 Instant Instant Instant Instant Instant Instant
3 17,576 < 2 Secs Instant Instant Instant Instant Instant
4 456,976 46 Secs 5 Secs Instant Instant Instant Instant
5 11.8 Million 20 Mins 2 Mins 12 Secs Instant Instant Instant
6 308.9 Million 8½ Hours 51½ Mins 5 Mins 30 Secs 3 Secs Instant
7 8 Billion 9 Days 22 Hours 2¼ Hours 13 Mins 1¼ Mins 8 Secs
8 200 Billion 242 Days 24 Days 2½ Days 348 Mins 35 Mins 3½ Mins
9 5.4 Trillion 17 Years 21 Months 63 Days 6¼ Days 15 Hours 1½ Hours
10 141 Trillion 447 Years 45 Years 4½ Years 163 Days 16 Days 39¼ Hours
12 95 Quadrillion 302,603 Years 30,260 Years 3,026 Years 302 Years 30 Years 3 Years
15 1.6 Sextillion 53 Trillion years 532 Million years 53 Million years 5 Million years 531,855 Years 53,185 Years
20 19.9 Octillion 63 Quadrillion years 6.3 Quadrillion years 631 Trillion years 63.1 Trillion years 6.3 Trillion years 631 Billion yea

36 Characters
The full alphabet, either upper or lower case (not both in this case) plus numbers.

Upper Case Alpha ABCDEFGHIJKLMNOPQRSTUVWXYZ


Lower Case Alpha abcdefghijklmnopqrstuvwxyz
Numerals 0123456789
Password Class of Attack
Length Combinations Class A Class B Class C Class D Class E Class F
2 1,296 Instant Instant Instant Instant Instant Instant
3 46,656 4 Secs Instant Instant Instant Instant Instant
4 1.6 million 2½ Mins 16 Seconds 1½ Seconds Instant Instant Instant
5 60.4 million 1½ Hours 10 Mins 1 Min Instant Instant Instant

52 Characters
This time we're trying the full alphabet but using a mixture of upper and lower case letters, that effectively doubles the number of
combinations when compared with just using a single case.

Mixed Alpha AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz


Password Class of Attack
Length Combinations Class A Class B Class C Class D Class E Class F
2 2,704 Instant Instant Instant Instant Instant Instant
3 140,608 14 Secs < 2 Secs Instant Instant Instant Instant
4 7.3 Million 12½ Mins 1¼ Mins 8 Secs Instant Instant Instant
5 380 Million 10½ Hours 1 Hour 6 Minutes 38 Secs 4 Secs Instant
6 19 Billion 23 Days 2¼ Days 5½ Hours 33 Mins 3¼ Mins 19 Secs
7 1 Trillion 3¼ Years 119 Days 12 Days 28½ Hours 3 Hours 17 Mins
8 53 Trillion 169½ Years 17 Years 1½ Years 62 Days 6 Days 15 Hours
9 2.7 Quadrillion 8,815 Years 881 Years 88 Years 9 Years 322 Days 32 Days

62 Characters
Mixed upper and lower case alphabetic characters plus numbers.

Mixed Alpha and Numerals 0123456789AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz


Password Class of Attack
Length Combinations Class A Class B Class C Class D Class E Class F
2 3,844 Instant Instant Instant Instant Instant Instant
3 238,328 23 Secs < 3 Secs Instant Instant Instant Instant
4 15 Million 24½ Mins 2½ Mins 15 Secs < 2 Secs Instant Instant
5 916 Million 1 Day 2½ Hours 15¼ Mins 1½ Mins 9 Secs Instant
6 57 Billion 66 Days 6½ Days 16 Hours 1½ Hours 9½ Mins 56 Secs
7 3.5 Trillion 11 Years 1 Year 41 Days 4 Days 10 Hours 58 Mins
8 218 Trillion 692 Years 69¼ Years 7 Years 253 Days 25¼ Days 60½ Hours

86 Characters
Mixed upper and lower case alphabet and common symbols.

Mixed Alpha & Symbols AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz <SP>!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~


Password Class of Attack
Length Combinations Class A Class B Class C Class D Class E Class F
2 7,396 Instant Instant Instant Instant Instant Instant
8 2.9 Quadrillion 9,488 Years 948 Years 94 Years 57 Years 346 Days 34 Days

96 Characters
Mixed upper and lower case alphabet plus numbers and common symbols.

Mixed Alpha, Numerals & Symbols 0123456789AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz <SP>!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~


Password Class of Attack
Length Combinations Class A Class B Class C Class D Class E Class F
2 9,216 Instant Instant Instant Instant Instant Instant
3 884,736 88½ Secs 9 Secs Instant Instant Instant Instant
4 85 Million 2¼ Hours 14 Mins 1½ Mins 8½ Secs Instant Instant
5 8 Billion 9½ Days 22½ Hours 2¼ Hours 13½ Mins 1¼ Mins 8 Secs
6 782 Billion 2½ Years 90 Days 9 Days 22 Hours 2 Hours 13 Mins
7 75 Trillion 238 Years 24 Years 2½ Years 87 Days 8½ Days 20 Hours
8 7.2 Quadrillion 22,875 Years 2,287 Years 229 Years 23 Years 2¼ Years 83½ Days

Examples
These are just a couple of examples to show the resilience of certain types of password, using the information in the tables above you
will be able to make your own examples.

Sample Passwords Class of Attack


Pwd Combinations Class A Class B Class C Class D Class E Class F
darren 308.9 Million 8½ Hours 51½ Mins 5 Mins 30 Secs 3 Secs Instant
Land3rz 3.5 Trillion 11 Years 1 Year 41 Days 4 Days 10 Hours 58 Mins
B33r&Mug 7.2 Quadrillion 22,875 Years 2,287 Years 229 Years 23 Years 2¼ Years 83½ Days

Classes of Attack
These are just some example speeds, I'd be interested to hear from people with more information about the speed taken to crack various
types of passwords with various hardware.

A. 10,000 Passwords/sec
Typical for recovery of Microsoft Office passwords on a Pentium 100

B. 100,000 Passwords/sec
Typical for recovery of Windows Password Cache (.PWL Files) passwords on a Pentium 100

C. 1,000,000 Passwords/sec
Typical for recovery of ZIP or ARJ passwords on a Pentium 100

D. 10,000,000 Passwords/sec

Fast PC, Dual Processor PC.

E. 100,000,000 Passwords/sec

Workstation, or multiple PC's working together.

F. 1,000,000,000 Passwords/sec
Typical for medium to large scale distributed computing, Supercomputers.

Distributed.net's Project Bovine RC5-64 possibly the fastest computer on earth has recently reached a speed of 76.1 Billion passwords
per second!

Friday 10th July 2009 03:01

Copyright © 1996-2009 Ivan Lucas. Licensed under a Creative Commons Attribution-ShareAlike 2.0 License. All trademarks are hereby acknowledged. Privacy Policy.
Lockdown.co.uk - The Home Computer Security Centre
LockDown is the source for security information and resources for the home computer user.

Password Recovery Speeds


Password How long will your password stand up
Recovery -
This document shows the approx imate amount of time required for a computer or a cluster of computers to guess v arious passwords. The figures shown are approx imate and are the maximum time required to
$9.95
guess each password using a simple brute force "key -search" attack, it may (and probably will) be possible to guess correctly without try ing all the combinations shown using other methods of attack or by
Find any password
in seconds with hav ing a "lucky guess".
Password See the bottom of the page for details about the classes of attack.
Recovery.
Download.
10 Characters
Just numbers. As y ou can see choosing a password from such a small range of characters is a bad idea.

Num erals 0123456789


Password Class of Attack
Length Com binations Class A Class B Class C Class D Class E Class F
2 1 00 Instant Instant Instant Instant Instant Instant
3 1 000 Instant Instant Instant Instant Instant Instant
4 1 0,000 Instant Instant Instant Instant Instant Instant
5 1 00,000 1 0 Secs Instant Instant Instant Instant Instant
6 1 Million 1 ½ Mins 1 0 Seconds Instant Instant Instant Instant
7 1 0 Million 1 7 Mins 1 ½ Mins 1 ½ Mins Instant Instant Instant
8 1 00 Million 2 ¾ Hours 1 7 Mins 1 ½ Mins 1 0 Seconds Instant Instant
9 1 000 Million 2 8 Hours 2 ¾ Hours 1 7 Mins 1 ½ Mins 1 0 Seconds Instant

26 Characters
The full alphabet, either upper or lower case (not both in this case).

Upper Case Alpha ABCDEFGHIJKLMNOPQRSTUVWXYZ


Lower Case Alpha abcdefghijklm nopqrstuv wxy z
Online File Sharing Password Class of Attack
Business- Length Com binations Class A Class B Class C Class D Class E Class F
class Secure
2 67 6 Instant Instant Instant Instant Instant Instant
File Sharing 4
Stars by PC 3 1 7 ,57 6 < 2 Secs Instant Instant Instant Instant Instant
Magazine. 4 4 56 ,9 7 6 4 6 Secs 5 Secs Instant Instant Instant Instant
Free Trial 5 1 1 .8 Million 2 0 Mins 2 Mins 1 2 Secs Instant Instant Instant
6 3 08.9 Million 8½ Hours 51 ½ Mins 5 Mins 3 0 Secs 3 Secs Instant
7 8 Billion 9 Day s 2 2 Hours 2 ¼ Hours 1 3 Mins 1 ¼ Mins 8 Secs
Suppor t Incident Tr acker
8 2 00 Billion 2 4 2 Day s 2 4 Day s 2 ½ Day s 3 4 8 Mins 3 5 Mins 3 ½ Mins
Elvis Imper sonator
Debt Management 9 5.4 Trillion 1 7 Years 2 1 Months 6 3 Day s 6 ¼ Day s 1 5 Hours 1 ½ Hours
10 1 4 1 Trillion 4 4 7 Years 4 5 Years 4 ½ Years 1 6 3 Day s 1 6 Day s 3 9 ¼ Hours
12 9 5 Quadrillion 3 02 ,6 03 Years 3 0,2 6 0 Years 3 ,02 6 Years 3 02 Years 3 0 Years 3 Years
15 1 .6 Sextillion 53 Trillion y ears 53 2 Million y ears 53 Million y ears 5 Million y ears 53 1 ,855 Years 53 ,1 85 Years
20 1 9 .9 Octillion 6 3 Quadrillion y ears 6 .3 Quadrillion y ears 6 3 1 Trillion y ears 6 3 .1 Trillion y ears 6 .3 Trillion y ears 6 3 1 Billion y ears

36 Characters
The full alphabet, either upper or lower case (not both in this case) plus numbers.

open in browser PRO version Are you a developer? Try out the HTML to PDF API pdfcrowd.com
Upper Case Alpha ABCDEFGHIJKLMNOPQRSTUVWXYZ
Lower Case Alpha abcdefghijklm nopqrstuv wxy z
Num erals 0123456789
Password Class of Attack
Length Com binations Class A Class B Class C Class D Class E Class F
2 1 ,2 9 6 Instant Instant Instant Instant Instant Instant
3 4 6 ,6 56 4 Secs Instant Instant Instant Instant Instant
4 1 .6 m illion 2 ½ Mins 1 6 Seconds 1 ½ Seconds Instant Instant Instant
5 6 0.4 m illion 1 ½ Hours 1 0 Mins 1 Min Instant Instant Instant

52 Characters
This time we're try ing the full alphabet but using a mix ture of upper and lower case letters, that effectiv ely doubles the number of combinations when compared with just using a single case.

Mix ed Alpha AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz


Password Class of Attack
Length Com binations Class A Class B Class C Class D Class E Class F
2 2 ,7 04 Instant Instant Instant Instant Instant Instant
3 1 4 0,6 08 1 4 Secs < 2 Secs Instant Instant Instant Instant
4 7 .3 Million 1 2 ½ Mins 1 ¼ Mins 8 Secs Instant Instant Instant
5 3 80 Million 1 0½ Hours 1 Hour 6 Minutes 3 8 Secs 4 Secs Instant
6 1 9 Billion 2 3 Day s 2 ¼ Day s 5½ Hours 3 3 Mins 3 ¼ Mins 1 9 Secs
7 1 Trillion 3 ¼ Years 1 1 9 Day s 1 2 Day s 2 8½ Hours 3 Hours 1 7 Mins
8 53 Trillion 1 6 9 ½ Years 1 7 Years 1 ½ Years 6 2 Day s 6 Day s 1 5 Hours
9 2 .7 Quadrillion 8,81 5 Years 881 Years 88 Years 9 Years 3 2 2 Day s 3 2 Day s

62 Characters
Mix ed upper and lower case alphabetic characters plus numbers.

Mix ed Alpha and Num erals 0123456789AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz


Password Class of Attack
Length Com binations Class A Class B Class C Class D Class E Class F
2 3 ,84 4 Instant Instant Instant Instant Instant Instant
3 2 3 8,3 2 8 2 3 Secs < 3 Secs Instant Instant Instant Instant
4 1 5 Million 2 4 ½ Mins 2 ½ Mins 1 5 Secs < 2 Secs Instant Instant
5 9 1 6 Million 1 Day 2 ½ Hours 1 5¼ Mins 1 ½ Mins 9 Secs Instant
6 57 Billion 6 6 Day s 6 ½ Day s 1 6 Hours 1 ½ Hours 9 ½ Mins 56 Secs
7 3 .5 Trillion 1 1 Years 1 Year 4 1 Day s 4 Day s 1 0 Hours 58 Mins
8 2 1 8 Trillion 6 9 2 Years 6 9 ¼ Years 7 Years 2 53 Day s 2 5¼ Day s 6 0½ Hours

86 Characters
Mix ed upper and lower case alphabet and common sy mbols.

Mix ed Alpha & Sy m bols AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz <SP>!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~


Password Class of Attack
Length Com binations Class A Class B Class C Class D Class E Class F
2 7 ,3 9 6 Instant Instant Instant Instant Instant Instant
8 2 .9 Quadrillion 9 ,4 88 Years 9 4 8 Years 9 4 Years 57 Years 3 4 6 Day s 3 4 Day s

open in browser PRO version Are you a developer? Try out the HTML to PDF API pdfcrowd.com
96 Characters
Mix ed upper and lower case alphabet plus numbers and common sy mbols.

Mix ed Alpha, Num erals & Sy m bols 0123456789AaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPpQqRrSsTtUuVvWwXxYyZz <SP>!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~


Password Class of Attack
Length Com binations Class A Class B Class C Class D Class E Class F
2 9 ,2 1 6 Instant Instant Instant Instant Instant Instant
3 884 ,7 3 6 88½ Secs 9 Secs Instant Instant Instant Instant
4 85 Million 2 ¼ Hours 1 4 Mins 1 ½ Mins 8½ Secs Instant Instant
5 8 Billion 9 ½ Day s 2 2 ½ Hours 2 ¼ Hours 1 3 ½ Mins 1 ¼ Mins 8 Secs
6 7 82 Billion 2 ½ Years 9 0 Day s 9 Day s 2 2 Hours 2 Hours 1 3 Mins
7 7 5 Trillion 2 3 8 Years 2 4 Years 2 ½ Years 87 Day s 8½ Day s 2 0 Hours
8 7 .2 Quadrillion 2 2 ,87 5 Years 2 ,2 87 Years 2 2 9 Years 2 3 Years 2 ¼ Years 83 ½ Day s

Examples
These are just a couple of ex amples to show the resilience of certain ty pes of password, using the information in the tables abov e y ou will be able to make y our own ex amples.

Sam ple Passwords Class of Attack


Pwd Com binations Class A Class B Class C Class D Class E Class F
darren 3 08.9 Million 8½ Hours 51 ½ Mins 5 Mins 3 0 Secs 3 Secs Instant
Land3 rz 3 .5 Trillion 1 1 Years 1 Year 4 1 Day s 4 Day s 1 0 Hours 58 Mins
B3 3 r&Mug 7 .2 Quadrillion 2 2 ,87 5 Years 2 ,2 87 Years 2 2 9 Years 2 3 Years 2 ¼ Years 83 ½ Day s

Classes of Attack
These are just some ex ample speeds, I'd be interested to hear from people with more information about the speed taken to crack v arious ty pes of passwords with v arious hardware.

A. 1 0,000 Passwords/sec
Ty pical for recov ery of Microsoft Office passwords on a Pentium 1 00

B. 1 00,000 Passwords/sec
Ty pical for recov ery of Windows Password Cache (.PWL Files) passwords on a Pentium 1 00

C. 1 ,000,000 Passwords/sec
Ty pical for recov ery of ZIP or ARJ passwords on a Pentium 1 00

D. 1 0,000,000 Passwords/sec

Fast PC, Dual Processor PC.

E. 1 00,000,000 Passwords/sec

Workstation, or multiple PC's working together.

F. 1 ,000,000,000 Passwords/sec
Ty pical for medium to large scale distributed computing, Supercomputers.

Distributed.net's Project Bov ine RC5-64 possibly the fastest computer on earth has recently reached a speed of 7 6.1 Billion passwords per second!

Friday 1 0th July 2009 03:01

Copyr ight © 1996-2009 Ivan Lucas. Licensed under a Cr eative Commons Attr ibution-Shar eAlike 2.0 License. All tr ademar ks ar e her eby acknowledged. Pr ivacy Policy.

open in browser PRO version Are you a developer? Try out the HTML to PDF API pdfcrowd.com

Você também pode gostar