Demonstration of RainbowCrack 1.2 software to crack 5 alpha only windows password in 30 seconds. Below is the screen output of the cracking process. The pwfile file contain 5 windows password hashes in pwdump format. The *.rt file are precomputed hash table files (rainbow table) we generated before with rtgen.exe utility. The rcrack.exe program find all plaintext in 24 seconds, with additional 6 seconds to load the files from disk. This demonstration run on a PC with one P4 3.0GHz processor and 512MB memory. ============================================================================================================= D:\rainbowcrack-1.2-win>type pwfile user0:1455:686f63d42397d2e30f97d26b0aca50d3:4170b8c7ef39e916ddffb3a2c61a6c61::: user1:1456:9ebd77263561ef2d0d075e2a1597d7bc:d5ec0d453fade7329c81eaa4fd78fc63::: user2:1457:1a993db3c3a8a908eb5e0c18c96b74de:c514fc8b1803747aa8be2fe087289fc2::: user3:1458:377f3240bafa098d5dca0224fb2b1540:7d9ddf6199d27e12f50f5920f14c4dfd::: user4:1459:25a1d3832aaf6f83caa7a34441025581:2eb5e84791b35ba90480004a28787753::: D:\rainbowcrack-1.2-win>dir k:\rt0\*.rt 驱动器 K 中的卷是 SATA0 卷的序列号是 64BE-26CB k:\rt0 的目录 2003-09-01 09:59 128,000,000 lm_alpha_0_2100x8000000_all.rt 2003-09-01 09:59 128,000,000 lm_alpha_1_2100x8000000_all.rt 2003-09-01 10:00 128,000,000 lm_alpha_2_2100x8000000_all.rt 2003-09-01 10:00 128,000,000 lm_alpha_3_2100x8000000_all.rt 2003-09-01 10:01 128,000,000 lm_alpha_4_2100x8000000_all.rt 5 个文件 640,000,000 字节 0 个目录 9,026,281,472 可用字节 D:\rainbowcrack-1.2-win>rcrack k:\rt0\*.rt -f pwfile lm_alpha_0_2100x8000000_all.rt: 128000000 bytes read, disk access time: 3.55 s verifying the file... searching for 10 hashes... plaintext of 686f63d42397d2e3 is WHJJGXA plaintext of 1a993db3c3a8a908 is JLXNYLY plaintext of 377f3240bafa098d is OFCVPLL plaintext of 5dca0224fb2b1540 is CGRVFOK plaintext of 25a1d3832aaf6f83 is DRLMYRX plaintext of caa7a34441025581 is GWEIVEK cryptanalysis time: 19.64 s lm_alpha_1_2100x8000000_all.rt: 128000000 bytes read, disk access time: 3.30 s verifying the file... searching for 4 hashes... plaintext of 0f97d26b0aca50d3 is JAQPRMN plaintext of 9ebd77263561ef2d is BMRBAHY plaintext of 0d075e2a1597d7bc is RHFKPQT plaintext of eb5e0c18c96b74de is LSKMQQT cryptanalysis time: 4.39 s statistics ------------------------------------------------------- plaintext found: 10 of 10 (100.00%) total disk access time: 6.84 s total cryptanalysis time: 24.03 s total chain walk step: 16450006 total false alarm: 15687 total chain walk step due to false alarm: 13952333 result ------------------------------------------------------- user0 whjJGXajAqpRMN hex:77686a4a4758616a417170524d4e user1 BmRbAHYrHfKPQt hex:426d52624148597248664b505174 user2 JlxNYLylskMqQt hex:4a6c784e594c796c736b4d715174 user3 ofCvPlLCgRvfok hex:6f664376506c4c43675276666f6b user4 drLmYRxgWeivek hex:64724c6d5952786757656976656b