<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Advanced Password Cracking - Insight &#187; Software</title>
	<atom:link href="http://blog.crackpassword.com/category/software/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.crackpassword.com</link>
	<description>&#171;...This blog is about &#60;a href=&#34;/?s=password+recovery&#34;&#62;cracking passwords&#60;/a&#62;, &#60;a href=&#34;/?s=forensic&#34;&#62;forensics solutions&#60;/a&#62;,&#60;br&#62;&#60;a href=&#34;/?s=security&#34;&#62;computer and network security&#60;/a&#62;, &#60;a href=&#34;/?s=system+recovery&#34;&#62;system recovery&#60;/a&#62; and other things...&#187;</description>
	<lastBuildDate>Thu, 15 Jul 2010 09:37:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Something new….</title>
		<link>http://blog.crackpassword.com/2010/07/something-new%e2%80%a6/</link>
		<comments>http://blog.crackpassword.com/2010/07/something-new%e2%80%a6/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 09:37:00 +0000</pubDate>
		<dc:creator>Alexandra Tsybulskaya</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Customer Reference Program Questionnaire]]></category>
		<category><![CDATA[Internet Password Breaker]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1341</guid>
		<description><![CDATA[According to the preliminary results of our latest questionnaire (ElcomSoft Customer Reference program Questionnaire) the majority of people forget their passwords when returned from holidays, thus being blocked out from the precious information they have on the PC. I bet that lots of people found themselves or those around in a similar situation at least [...]]]></description>
			<content:encoded><![CDATA[<p>According to the preliminary results of our latest questionnaire (ElcomSoft Customer Reference program Questionnaire) the majority of people forget their passwords when returned from holidays, thus being blocked out from the precious information they have on the PC. <br />
I bet that lots of people found themselves or those around in a similar situation at least once. Let me share my personal experience with you. One of my friends, having returned from the vacation in a tropical paradise, was pleased to see a new computer at her desk (while she was away the company renewed some of the machines) and at the same time very much discouraged and upset to find out that many of her passwords remained in her old pc and she didn&#39;t bother herself to save them anywhere else. So the access to the mail account from her new modern PC was forbidden, as well as access to several password-protected websites (from social networks to online banking).&nbsp; Nothing to be happy with, isn&rsquo;t it?!! But such a story no longer has a sad ending due to the release of Elcom&rsquo;s new recovery tool, namely ElcomSoft Internet Password Breaker. In the above described situation EINPB revealed necessary passwords stored in the old computer, thus letting a person replace the password-protected data from one machine to another.&nbsp; One more important remark in this respect is that my friend didn&rsquo;t have to seek help of the &ldquo;user-unfriendly sysadmin&rdquo; <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>What&rsquo;s special about EINPB? Let&rsquo;s have a quick jog through some of its features. Our new tool instantly reveals cached passwords to Web sites in Microsoft Internet Explorer, mailbox &amp; identity passwords in lots of Microsoft versions. It as well supports the new security model employed by Microsoft Internet Explorer 7 and 8.</p>
<p>Think it can be of any interest for you, please visit our site <a href="http://www.elcomsoft.com">http://www.elcomsoft.com</a> &amp; learn more about EINPB at <a href="http://einpb.elcomsoft.com">http://einpb.elcomsoft.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/07/something-new%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>0-day</title>
		<link>http://blog.crackpassword.com/2010/06/0-day/</link>
		<comments>http://blog.crackpassword.com/2010/06/0-day/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 10:50:43 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[EPPB]]></category>
		<category><![CDATA[iOS 4]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1330</guid>
		<description><![CDATA[It’s been two weeks since Steve Jobs has announced release of new iPhone 4 and iOS 4 operating system during his keynote on WWDC’2010. New iPhone will begin shipping on Thursday, 24th of June, and new iOS will become available for download today, just few hours are left. iOS 4 comes packed with a lot [...]]]></description>
			<content:encoded><![CDATA[<p>It’s been two weeks since Steve Jobs has announced release of new iPhone 4 and iOS 4 operating system during his keynote on WWDC’2010. New iPhone will begin shipping on Thursday, 24th of June, and new iOS will become available for download today, just few hours are left.</p>
<p>iOS 4 comes packed with a lot of nice features (long-awaited multitasking, background location services, iBooks and much improved Mail app&#160; just to name a few) and we are very pleased to announce today the release of the new version of Elcomsoft iPhone Password Breaker with support for iTunes 9.2 and iOS 4.</p>
<p>Elcomsoft iPhone Password Breaker (or EPPB for short) is a utility to recover passwords for encrypted and password-protected iPhone/iPod/iPad backups created with iTunes (please note that it’s not meant to recover or remove passcode lock on the device).</p>
<p>With iOS 4 Apple has completely changed the way backups are encrypted and stored. Backup and restore processes are way much faster now. Apple have also improved protection against password recovery attacks, thus making our job harder (password recovery is about 5x slower for new backups than for older ones).</p>
<p>We at Elcomsoft try our best to keep up with the times, so most of our tools &amp; programs are adjusted to the latest technologically advanced features. The EPPB is not an exception, new version of EPPB fully supports both old and new backup formats. It also supports hardware acceleration using NVIDIA and ATI GPUs and Tableau TACC1441.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/06/0-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Casual and Secure&#8217; Friday Post</title>
		<link>http://blog.crackpassword.com/2010/05/casual-and-secure-friday-post/</link>
		<comments>http://blog.crackpassword.com/2010/05/casual-and-secure-friday-post/#comments</comments>
		<pubDate>Fri, 14 May 2010 07:59:33 +0000</pubDate>
		<dc:creator>Katerina Korolkova, PR Director</dc:creator>
				<category><![CDATA[Human Factor]]></category>
		<category><![CDATA[Industry News]]></category>
		<category><![CDATA[Legal Questions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1307</guid>
		<description><![CDATA[German law has always been strict about any possible security breaches. This week German court ordered that anyone using wireless networks should protect them with a password so the third party could not download data illegally. &#160; However, there is no order that users have to change their Wi-Fi passwords regularly, the only requirement being [...]]]></description>
			<content:encoded><![CDATA[<p>German law has always been strict about any possible security breaches. This week German court ordered that anyone using wireless networks should protect them with a password so the third party could not download data illegally. <span style="mso-spacerun:yes">&nbsp;</span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-ansi-language:EN-US">However, there is no order that users have to change their Wi-Fi passwords regularly, the only requirement being to set up a password on the initial stage of wireless access installation and configuration. <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-ansi-language:EN-US">I&rsquo;ve conducted a mini-research here in Russia. There are 5 wireless networks in range that my computer finds when at home. Although all of the networks have rather bizarre names, they are all WPA- or WPA2-protected. My guess is that people do not install wireless access at home by themselves or browse the Internet for instructions and find some on protection and passwords. At the same time, I often come across unprotected networks in Moscow and I do use them to check my Twitter account. It is obvious that to make any conclusions, one has to dive into this topic much more deeply.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-ansi-language:EN-US">What I learnt working for ElcomSoft &ndash; the company that recovers passwords and does it very well &ndash; is the following: sometimes <i style="mso-bidi-font-style:normal">a</i> password is not enough. You need <i style="mso-bidi-font-style:normal">a good</i> password to make sure your data is protected. WPA requires using passwords that are at least 8 characters long. Such length guarantees quite good protection. The problem as usual is the human factor. We still use admin123 and the like to protect our networks. <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-ansi-language:EN-US">Fortunately, there are tools that can help you check how strong your WPA/WPA2-password is. One of such tools is <a href="http://elcomsoft.com/ewsa.html">Wireless Security Auditor</a>. It makes use of various hardware for password recovery acceleration and a set of customizable dictionary attacks. The idea is simple: if this monster does not find your WPA/WPA2-password, then it is secure&nbsp;<img alt=":)" src="http://blog.crackpassword.com/wp-content/plugins/fckeditor-for-wordpress-plugin/ckeditor/plugins/smiley/images/regular_smile.gif" title=":)" /></span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-ansi-language:EN-US">Nice weekend to all.<o:p></o:p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/05/casual-and-secure-friday-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Elcomsoft iPhone Password Breaker</title>
		<link>http://blog.crackpassword.com/2010/05/elcomsoft-iphone-password-recovery/</link>
		<comments>http://blog.crackpassword.com/2010/05/elcomsoft-iphone-password-recovery/#comments</comments>
		<pubDate>Fri, 07 May 2010 06:00:53 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Elcomsoft]]></category>
		<category><![CDATA[iPad]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1293</guid>
		<description><![CDATA[Last week we have released our new product, EPPB, out of beta. We have fixed some bugs, polished GPU acceleration support, added support for Tableau TACC1441 hardware accelerator, making this program the world&#39;s first program capable of utilizing computing power of GPUs both from ATI and NVIDIA as well as dedicated hardware accelerators aimed primarily [...]]]></description>
			<content:encoded><![CDATA[<p>Last week we have released our new product, <a href="http://elcomsoft.com/eppb.html">EPPB</a>, out of beta. We have fixed some bugs, polished GPU acceleration support, added support for Tableau <a href="http://www.tableau.com/index.php?pageid=products&#038;category=hardware_accelerators#galBottom0">TACC1441</a> hardware accelerator, making this program the world&#39;s first program capable of utilizing computing power of GPUs both from <a href="http://www.ati.com">ATI </a>and <a href="http://www.nvidia.com">NVIDIA </a>as well as dedicated hardware accelerators aimed primarily on computer forensics specialists. We have also included ability to run brute-force attacks and not only wordlist-based attacks. Latter were improved with ability to enable/disable individual types of password mutations and set customized level to any of them. </p>
<p>The last, but not the least, we have found that EPPB can handle encrypted backups from Apple&#39;s newest tablet, <a href="http://www.apple.com/ipad/">iPad </a>(thanks to Apple for using the same underlying technologies for iPhone, iPod Touch and iPad).</p>
<p style="text-align: center; "><a href="http://blog.crackpassword.com/wp-content/uploads/2010/05/ipad_eppb.jpg"><img alt="Apple iPad" class="aligncenter size-medium wp-image-1294" height="369" src="http://blog.crackpassword.com/wp-content/uploads/2010/05/ipad_eppb-550x369.jpg" title="Apple iPad" width="550" /></a></p>
<p><strong>P.S.</strong> If anyone&#39;s interested, we think that iPad is really cool gadget. It&#39;s not a substitute for a laptop, but it&#39;s great for catching on emails, surfing web, watching photos or videos or movies and for reading books. And multitouch on 10&#39;&#39; screen is awesome <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p><strong>P.P.S.</strong> Yes, this blog post was originally created on iPad.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/05/elcomsoft-iphone-password-recovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ATI and NVIDIA: Making Friends out of Enemies</title>
		<link>http://blog.crackpassword.com/2010/03/ati-and-nvidia-making-friends-out-of-enemies/</link>
		<comments>http://blog.crackpassword.com/2010/03/ati-and-nvidia-making-friends-out-of-enemies/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 12:18:00 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[ATI]]></category>
		<category><![CDATA[GPGPU]]></category>
		<category><![CDATA[GPU]]></category>
		<category><![CDATA[Nvidia]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1239</guid>
		<description><![CDATA[There had been a long standing competition between NVIDIA and ATI which has lasted for years now. And there is no winner so far &#8212; just like with Windows vs. Linux or PC vs. Mac debate there are ones who prefer the former and others who prefer the latter. Kind of &#171;religious&#187; issue. From developer&#39;s [...]]]></description>
			<content:encoded><![CDATA[<p>There had been a long standing competition between NVIDIA and ATI which has lasted for years now. And there is no winner so far &mdash; just like with Windows vs. Linux or PC vs. Mac debate there are ones who prefer the former and others who prefer the latter. Kind of &laquo;religious&raquo; issue.</p>
<p><span id="more-1239"></span></p>
<p><img alt="gtx295_hd5970" border="0" height="508" src="http://blog.crackpassword.com/wp-content/uploads/2010/03/gtx295_hd5970_thumb.jpg" style="display: block; float: none; margin-left: auto; margin-right: auto; border-width: 0px;" title="gtx295_hd5970" width="600" /></p>
<p>From developer&#39;s point of view NVIDIA has always been superior. Ease of use, quality of SDK and drivers, thorough documentation. Apparently, they have invested a lot in developing, promoting and supporting CUDA.</p>
<p>Developing software for ATI cards is (okay &mdash; was) a nightmare. In 2009 ATI quietly introduced two changes in their drivers which made previously perfectly functional and compatible applications to crash (if you are curious: with Catalyst 9.2 or 9.3 they&#39;ve changed names of supporting DLLs bundled with drivers; with Catalyst 9.9 or 9.10 they&#39;ve probably changed format of underlying binary so that anything compiled and linked in with earlier versions caused a driver to crash). And there was almost no documentation with 1.x ATI SDKs.</p>
<p>But when it comes to pure mathematical performance (that is, not counting memory transactions) ATI cards are faster than NVIDIA counterparts, usually by far. Sometimes by very far. That&#39;s why we&#39;ve been supporting them for more than a year already.</p>
<p>Next week we&#39;re going to update two of our applications &mdash; Elcomsoft Wireless Security Auditor and Elcomsoft iPhone Password Breaker. Among other things, they will support the use of both NVIDIA and ATI cards at the same time. Although I don&#39;t think this is a very common scenario, we&#39;ve had some questions regarding possibility of such configurations.</p>
<p>Well, the answer is &mdash; it works! To verify this we&#39;ve put GeForce GTX 295 and Radeon HD5970 into the same PC and tried to make this configuration work. This is how it looks before connecting power cables:</p>
<p><a href="http://blog.crackpassword.com/wp-content/uploads/2010/03/gtx295_hd5970_nopower_600px.jpg" style="border: medium none;"><img alt="gtx295_hd5970_nopower_600px" border="0" height="740" src="http://blog.crackpassword.com/wp-content/uploads/2010/03/gtx295_hd5970_nopower_600px_thumb.jpg" style="border: medium none;" title="gtx295_hd5970_nopower_600px" width="658" /></a></p>
<p>And this is how it looks after:</p>
<p><a href="http://blog.crackpassword.com/wp-content/uploads/2010/03/Radeon_600px.jpg" style="border: medium none;"><img alt="Radeon_600px" border="0" height="496" src="http://blog.crackpassword.com/wp-content/uploads/2010/03/Radeon_600px_thumb.jpg" style="display: block; float: none; margin-left: auto; margin-right: auto; border-width: 0px;" title="Radeon_600px" width="658" /></a></p>
<p>With Windows 7, there were no problems installing drivers for both cards, everything went smooth. We have used Catalyst 10.2 and Forceware 196.75 (it has been removed from website due to problems with fan control; I believe 196.21 will also work just fine).</p>
<p>If you will try to do this yourself, beware of one catch. After you have installed drivers you will see both ATI and NVIDIA cards in Windows Device Manager, but EWSA or EPPB will show only cards from one vendor. To overcome this you&#39;ll need to connect monitors to both cards and extend your Windows Desktop onto both of them. If you&#39;ll do this, our programs will be able to recognize all cards and you end up with something like this:</p>
<p><img alt="eppb_hardware" border="0" height="277" src="http://blog.crackpassword.com/wp-content/uploads/2010/03/eppb_hardware.png" style="display: block; float: none; margin-left: auto; margin-right: auto; border-width: 0px;" title="eppb_hardware" width="440" /></p>
<p>In fact, you can use both cards even with Windows XP! This is, however, not so smooth as with Windows 7. Performance for ATI cards is worse in XP, too. The funny thing is that XP seems to be unable to boot with two display drivers installed, so you have to uninstall one driver first, reboot, and then install it again (do not reboot!). Connect second monitor, and our programs will recognize cards from both vendors. If you will try to reboot, you will end up with BSoD and will need to boot in Safe Mode, uninstall one of drivers, and start over. Here&#39;s screenshot of EWSA running under XP x64:</p>
<p><img alt="ewsa_gpu_xp" border="0" height="238" src="http://blog.crackpassword.com/wp-content/uploads/2010/03/ewsa_gpu_xp.png" style="display: block; float: none; margin-left: auto; margin-right: auto; border-width: 0px;" title="ewsa_gpu_xp" width="383" /></p>
<p><strong>EDIT:</strong> Some discussion on performance and architecture of next-generation GPUs have been removed in accordance with NVIDIA request.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/03/ati-and-nvidia-making-friends-out-of-enemies/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>iPhone/iPod Backup Password Recovery</title>
		<link>http://blog.crackpassword.com/2010/02/iphone-ipod-backup-password-recovery/</link>
		<comments>http://blog.crackpassword.com/2010/02/iphone-ipod-backup-password-recovery/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 05:00:04 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[eipb]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[ipod]]></category>
		<category><![CDATA[iTunes]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1108</guid>
		<description><![CDATA[Today we are pleased to unveil the first public beta of our new product, Elcomsoft iPhone Password Breaker, a tool designed to address password recovery of password-protected iPhone and iPod Touch backups made with iTunes. In case you do not know, iTunes routinely makes backups of iPhones and iPods being synced to it. Such backups [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.elcomsoft.com/eppb.html" target="_blank"><img align="left" alt="ElcomSoft iPhone Password Breaker" border="0" height="300" hspace="0" src="http://blog.crackpassword.com/wp-content/uploads/2010/02/eppb_boxshot300.png" style="border-bottom: medium none; border-left: medium none; padding-right: 10px; border-top: medium none; border-right: medium none" title="ElcomSoft iPhone Password Breaker" width="184" /></a>Today we are pleased to unveil the first public beta of our new product, Elcomsoft iPhone Password Breaker, a tool designed to address password recovery of password-protected iPhone and iPod Touch backups made with iTunes.</p>
<p>In case you do not know, iTunes routinely makes backups of iPhones and iPods being synced to it. Such backups contain a plethora of information, essentially all user-generated data from the device in question. Contacts, calendar entries, call history, SMS, photos, emails, application data, notes and probably much more. Not surprisingly, such information manifests significant value for investigators. To make their job easier there are tools to read information out of iTunes backups, one example of such tool being Oxygen Forensic Suite (<a href="http://www.oxygen-forensic.com/" target="_blank">http://www.oxygen-forensic.com/</a>). Such tools can not deal with encrypted backups, though.</p>
<p><span id="more-1108"></span></p>
<p>Starting with iTunes 8.2 and iPhoneOS 3.0 (that is, June 2009) it became possible to protect iTunes backups with a password. After you specify protection password, no backup data leaves or enters device unencrypted. That is, contacts, emails, photos, etc. are encrypted on the device, transmitted <strong>encrypted</strong> over USB cable, and saved <strong>encrypted</strong> on hard disk. Apparently, such backups exhibit much less value for investigators.</p>
<p>This is where our tool comes into play. Given a password-protected backup, it can run various password recovery attacks, trying thousands passwords per second. Unquestionably, it supports multi-core CPUs, extended CPU instructions, and acceleration using GPU cards (only NVIDIA for the moment, ATI and friends coming in a month or two). Technologically, the product is pretty cool (and it&rsquo;s going to become better).</p>
<p>However, this is an early beta and it obviously lacks some functionality. You cannot pause/resume recovery. You are limited to wordlist-based attacks only. It is no way bug-free and it will expire on March, 15 after all. Still, you are invited to give it a try. You can download it at <a href="http://www.elcomsoft.com/eppb-beta.html" target="_blank">http://www.elcomsoft.com/eppb-beta.html</a>.</p>
<p>Please submit your feedback to <i>iphone at elcomsoft.com</i> or use <i>&quot;Help ➯ Send feedback&#8230;&quot;</i> menu command from within program itself. Bug reports are welcome, so are suggestions and feature requests. Top contributors will receive iTunes gift certificates, free software licenses and discounts.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/02/iphone-ipod-backup-password-recovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Need to protect your VBA macro ? Simply damage the file !</title>
		<link>http://blog.crackpassword.com/2009/10/need-to-protect-your-vba-macro-simply-damage-the-file/</link>
		<comments>http://blog.crackpassword.com/2009/10/need-to-protect-your-vba-macro-simply-damage-the-file/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 15:57:26 +0000</pubDate>
		<dc:creator>Andrey Malyshev</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[add-in]]></category>
		<category><![CDATA[damage]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[macro]]></category>
		<category><![CDATA[project]]></category>
		<category><![CDATA[protection]]></category>
		<category><![CDATA[vba]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1014</guid>
		<description><![CDATA[One of our customers sent me two Excel XLA add-ins. When I tried to open that file in the VBA Editor &#8212; the &#34;Project is locked&#34; message appeared. Add-in has been already unlocked by our VBA password recovery tool. According to Microsoft article this message may appear in two cases: when the macro is protected [...]]]></description>
			<content:encoded><![CDATA[<p>One of our customers sent me two Excel XLA add-ins. When I tried to open that file in the VBA Editor &#8212; the &quot;Project is locked&quot; message appeared. Add-in has been already unlocked by our <a href="http://www.elcomsoft.com/avpr.html">VBA password recovery tool</a>. According to <a href="http://support.microsoft.com/kb/229499">Microsoft article</a> this message may appear in two cases: when the macro is protected by password or when it is digitally signed. I analysed the macro password record and found that the password is empty. MS Excel also showed me that macro have no any digital signatures. Then I looked into protection record with more attention and for example found that:</p>
<p><strong>&quot;[Host Extender Info]&quot;</strong> string is replaced to <strong>&quot;[Host Extender 1nfo]&quot;</strong>.</p>
<p>There were some additional similar changes and finally I found that the macro has damaged digital signature record. It&#8217;s ignored when macro is running but when we try to open the macro to view &#8212; Excel shows the error.</p>
<p>Microsoft has <a href="http://www.elcomsoft.com/help/aopr/vba.htm">very weak VBA macro protection</a>. That&#8217;s why developers are searching for non-standard protection methods. It&#8217;s not simple to reconstruct a damaged macro and it may require a lot of time.</p>
<p>If your macro cannot be opened by our <a href="http://www.elcomsoft.com/prs.html">password recovery programs</a> &#8212; the most probable reason is custom protection that damages some technical records. I cannot say that it&#8217;s a good protection. New versions of MS Office may not work correctly with damaged files.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/10/need-to-protect-your-vba-macro-simply-damage-the-file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Now: long-awaited ElcomSoft Password Recovery KIT</title>
		<link>http://blog.crackpassword.com/2009/10/now-long-awaited-elcomsoft-password-recovery-kit/</link>
		<comments>http://blog.crackpassword.com/2009/10/now-long-awaited-elcomsoft-password-recovery-kit/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 10:32:14 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1005</guid>
		<description><![CDATA[Our it-friends from Ukraine (KARPOLAN and Dmitry) highly optimized our developing processes and helped us finalize long-awaited Password Recovery KIT. We won&#8217;t go deep into technical details, just have a look at rough visualization.]]></description>
			<content:encoded><![CDATA[<p><a title="Click to see this fat and full of cholesterol image in details" target="_blank" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" href="http://blog.crackpassword.com/userfiles/06102009087.jpg"><img alt="Click to see this fat and full of cholesterol image in details" width="500" height="375" src="/userfiles/06102009087.jpg" /></a></p>
<p>Our it-friends from Ukraine (<a target="_blank" nofollow="" href="http://karpolan.livejournal.com/">KARPOLAN</a> and Dmitry) highly optimized our developing processes and helped us finalize long-awaited Password Recovery KIT. We won&rsquo;t go deep into technical details, just have a look at rough visualization.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/10/now-long-awaited-elcomsoft-password-recovery-kit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Advanced Office Password Recovery: customizing the preliminary attack</title>
		<link>http://blog.crackpassword.com/2009/08/advanced-office-password-recovery-customizing-the-preliminary-attack/</link>
		<comments>http://blog.crackpassword.com/2009/08/advanced-office-password-recovery-customizing-the-preliminary-attack/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 20:10:23 +0000</pubDate>
		<dc:creator>Andrey Malyshev</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=963</guid>
		<description><![CDATA[&#160;Every time when you open a document in Advanced Office Password Recovery it performs the preliminary attack in case when the &#34;file open&#34; password is set. This attack tries all passwords that you recovered in past (which are stored in password cache), dictionary attack and finally the brute-force attack is running. The brute-force attack consists [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;Every time when you open a document in <a href="http://www.elcomsoft.com/aopr.html">Advanced Office Password Recovery</a> it performs the <a href="http://www.elcomsoft.com/help/aopr/prelattack.htm">preliminary attack </a>in case when the &quot;file open&quot; password is set. This attack tries all passwords that you recovered in past (which are stored in password cache), dictionary attack and finally the brute-force attack is running.</p>
<p>The brute-force attack consists of two parts:</p>
<p>1. Trying digits and latin letters<br />
2. Trying national characters depending on code page set in Windows.</p>
<p>Before this time these parts were hardcoded in the program. The new version of Advanced Office Password Recovery has an option to customize the preliminary brute-force attack.&nbsp;</p>
<p>Look to the directory where AOPR is installed. There is <strong>&quot;attacks.xml&quot;</strong> file inside. The first section of this file is the language map:</p>
<p><img width="236" height="117" alt="" src="/userfiles/2009-08-04_235815.gif" /></p>
<p>The codes are Windows <a href="http://msdn.microsoft.com/en-us/library/aa912040.aspx">language identifiers</a>. You can link any LID to your custom name.</p>
<p>The next section contains predefined charsets:</p>
<p><img width="511" height="74" alt="" src="/userfiles/attack_xml_charsets(1).gif" /></p>
<p>All charsets are in unicode so you can define any national characters here.</p>
<p>And the final section is &quot;documents&quot;. All parts of this section has comments about document types. You can define the &quot;common&quot; charsets and charsets that are related to system language. Each &quot;attack&quot; record defines password length and charset.</p>
<p>In this XML file you can simply change the standard preliminary attack and define the custom charsets for your language. I hope this will help to recover your Office passwords faster.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/08/advanced-office-password-recovery-customizing-the-preliminary-attack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Office 2010: two times more secure</title>
		<link>http://blog.crackpassword.com/2009/07/office-2010-two-times-more-secure/</link>
		<comments>http://blog.crackpassword.com/2009/07/office-2010-two-times-more-secure/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 09:43:01 +0000</pubDate>
		<dc:creator>Andrey Malyshev</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[GPU]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[speed]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=948</guid>
		<description><![CDATA[We are waiting for release of new Microsoft office suite &#8211; Office 2010. Right now Microsoft has only technical preview of new Office; this preview has been leaked from Microsoft and everyone can download it with the help of torrent trackers. We&#8217;ve got&#160;a copy of Office 2010 and analysed its (new) password protection. Starting from [...]]]></description>
			<content:encoded><![CDATA[<p>We are waiting for release of new Microsoft office suite &#8211; Office 2010. Right now Microsoft has only technical preview of new Office; this preview <a href="http://www.techspot.com/news/34747-microsoft-office-2010-tech-preview-hits-torrent-sites.html">has been leaked from Microsoft</a> and everyone can download it with the help of torrent trackers. We&#8217;ve got&nbsp;a copy of Office 2010 and analysed its (new) password protection.</p>
<p>Starting from Office 2007, Microsoft used password protection system called <a href="http://www.ecma-international.org/publications/standards/Ecma-376.htm">ECMA-376</a>, developed by <a href="http://www.ecma-international.org/default.htm">ECMA International</a>. This standard is open and everyone can write ECMA-376 based protection which will be accepted by Microsoft Office. The standard allows to select hash and encryption algorithms as well as the number of hash rounds (up to 10 millions is allowed).</p>
<p>In Office 2007, ECMA-376 with SHA-1 hash and AES-128 encryption is implemented. The number of hash rounds is 50000 that makes password recovery really difficult and slow. Office 2010 also uses SHA-1 and AES-128, but the number of hash rounds is now 100000. Therefore password recovery for new Office files will be two times slower.</p>
<p>Here is a diagram of password recovery speed for Office 2007:</p>
<p><img alt="" src="http://www.elcomsoft.com/images/gpu2.gif" /></p>
<p>To get&nbsp;a speed for Office 2010, simply divide these values to 2. We&#8217;ll get about 175 pps on Core2 6600 and about 8750 pps on Tesla S1070.</p>
<p>Why don&#8217;t increase the number of hash rounds to 10 millions ? Security is really important but it always affects usability. The hash is calculating to verify a password and when each document block is decrypted. If we add hash rounds &#8211; the document decryption time is increased.&nbsp;If&nbsp;a document&nbsp;is&nbsp;opening in MS Office during one hour &#8211; its unacceptable&nbsp;despite of high security.</p>
<p>Anyway &#8211; Office 2010&nbsp;documents will be more secure than Office 2007&nbsp;ones. And the new encryption&nbsp;has backward compatibility &#8211; all Office 2010 documents can be opened in Office 2007.&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/07/office-2010-two-times-more-secure/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
