Business Wire
Welcome
  • Log In
  • Sign Up
Search News:
Help
http://www.rapid7.com
June 22, 2011 09:00 AM Eastern Daylight Time 

“John the Ripper” Open Source Password Cracker Offers Increased Speed Through 17 Percent Improvement in Gate Count for Data Encryption Standard (DES) Algorithm

MOSCOW--(BUSINESS WIRE)--Openwall, an open source-based, professional IT and security services company, has released an updated version of “John the Ripper,” a password security auditing tool and open source project, providing the community with significant improvements in the performance of cracking password hashes based on the Data Encryption Standard (DES) algorithm on CPUs. In an effort led by Roman Rusakov and Alexander Peslyak, the Openwall team’s breakthrough for more optimal DES S-box expressions provides a 17 percent improvement over the previous best results. The S-box expressions generated under this effort are being made publicly available, are not copyrighted and are free for reuse by anyone.

“This area has been a struggle for many years”

“This area has been a struggle for many years,” said Alexander Peslyak, Openwall founder and CTO, and a well-known security researcher. “We are thrilled to finally have an enhanced solution. We expect, and encourage, that many of our fellow password security auditing programs that support DES-based hashes will also make use of these new S-box expressions.”

Since 1998, numerous attempts have been made to arrive at more optimal DES S-box expressions. During the past year, Openwall researchers developed an idea to approach the optimization problem differently and, as a result, were able to design and successfully implement a new algorithm that significantly improves upon the corresponding prior results. This new approach is easily adaptable to arbitrary sets of "logic gates." The team has generated different S-box expressions targeting both typical CPUs with only basic instructions and CPUs/GPUs that have "bit select" instructions. The mentioned improvement over the corresponding previous best results is achieved in both cases.

"The continued improvement of John the Ripper is important to the IT audit field in general because it allows auditors to quickly evaluate system, application and database compliance with corporate password policies based on the user account samples they have selected for an audit. A 20 percent speedup where John the Ripper is used for testing can greatly reduce the time required for password policy validation, particularly for large enterprises," said Erik Winkler, vice president of North America, ControlCase, a compliance management company.

Besides generating simpler S-box expressions in terms of gate count, efficiency of the corresponding program code was considered and thousands of different same-gate-count expressions were created to generate the best possible code for specific CPU and GPU architectures.

Further, the Openwall researchers implemented and ran special-purpose CPU register allocation and code generation algorithms with intertwined S-box expression and code generation stages, allowing for a further performance boost of the resulting program code.

“The researchers at Openwall deserve significant recognition for discovering and providing a new approach to addressing performance-critical S-box expressions. By providing this new approach free-of-charge through John the Ripper, Openwall is making another major impact on the open source and security communities,” said HD Moore, Rapid7® CSO and Metasploit chief architect.

Continuing its active engagement and support for the open source community, Rapid7, the leading provider of unified vulnerability management and penetration testing solutions, has been supporting John the Ripper for the past year in order to help complete the project’s research. As well as sponsoring the development of this latest version of John the Ripper, Rapid7 backed the recent addition of support for Intel AVX and AMD XOP instruction set extensions, as well as parallelization of the bitslice DES implementation with OpenMP (for multi-core and multi-CPU machines). Working with Openwall to support this project has also enabled the Rapid7 team to develop greater technical integration with the John the Ripper solution for upcoming versions of Metasploit®.

This sponsorship adds to Rapid7’s growing community involvement. In 2009, Rapid7 acquired the Metasploit Project, the world’s largest database of public, tested exploits, supporting the project as it became the most widely used penetration testing solution in the market with more than one million unique downloads in the past year alone. In July 2010, Rapid7 announced a sponsorship and partnership with w3af, the open source Web application attack and audit framework, to expand its collaboration with the open source community and further provide the industry with solutions for securing Web and application infrastructure.

About Openwall

Openwall is an open source-based company that provides businesses with cost-effective and secure solutions and services for their information technology needs, including system administration, remote server administration, system integration and consulting. Openwall’s experts manage, contribute to and use open source projects and technologies, including the John the Ripper project, a password auditing tool, and Openwall GNU/*/Linux (Owl) project, a security-enhanced Linux distribution for servers, appliances and virtual appliances. For more information about Openwall, its open source projects and commercial products, including John the Ripper Pro, please visit www.openwall.com.

About Rapid7

Rapid7 is the leading provider of unified vulnerability management and penetration testing solutions, delivering actionable intelligence about an organization’s entire IT environment. Rapid7 offers the only integrated threat management solution that enables organizations to implement and maintain best practices and optimize their network security, Web application security and database security strategies.

Recognized as the fastest growing vulnerability management company in the U.S. by Inc. Magazine, Rapid7 helps leading organizations such as Liz Claiborne, the United States Postal Service, Carnegie Mellon University and Red Bull to mitigate risk and maintain compliance for regulations such as PCI, HIPAA, FISMA, SOX and NERC. Rapid7 also manages the Metasploit Project, the leading open-source penetration testing platform with the world’s largest database of public, tested exploits. To obtain a free download of NeXpose® or Metasploit, please visit http://www.rapid7.com/resources/free-downloads.jsp.

For more information, visit www.rapid7.com.

Contacts

For Rapid7
Amanda Munroe, 617-779-1816
amunroe@shiftcomm.com

Recent Stories from Rapid7

  • View Press Release
    Rapid7 Starts 2012 With a 56% Year-Over-Year Revenue Increase for the First Quarter
    May 11, 2012
    BOSTON--(BUSINESS WIRE)--Rapid7 today announced it achieved its twelfth consecutive record quarter with a 56% increase in revenue growth in Q1 of 2012, compared to Q1 of 2011. This growth is a resu... more »
  • View Press Release
    Boston Business Journal Recognizes Rapid7 in its 2012 Pacesetters and Best Places to Work Honors
    May 04, 2012
    BOSTON--(BUSINESS WIRE)--Rapid7, the leading provider of security risk intelligence solutions, today announced its second consecutive year of recognition as one of the fastest-growing private compa... more »
  • View Press Release
    Richard Perkett Joins Rapid7 to Lead Product Development and Establish New Boston Innovation Center
    April 13, 2012
    BOSTON--(BUSINESS WIRE)--Rapid7, the leading provider of security risk intelligence solutions, today announced that Richard Perkett has joined the Company as vice president of engineering. Perkett ... more »
More Stories
RSS feed for Rapid7
http://www.rapid7.com

Release Versions

  • EON: Enhanced Online News

Company Information Center

Rapid7 RSS feed for Rapid7

Share

  • Facebook
  • Twitter
  • LinkedIn
  • Delicious
  • Reddit
  • StumbleUpon
  • Digg
  • MySpace
  • Newsvine
  • Google Bookmark
  • Yahoo! Bookmark
  • EmailEmail
Tweet
  • EmailEmail
All News
Business Wire
  • Home
    • Home
    • Membership Benefits
    • Submit a Press Release
  • News
    • All News
    • News with Multimedia
    • News by Industry
    • News by Subject
    • News by Language
    • RSS Feeds
    • Business Wire Mobile
    • Features
    • Company NewsCenters
    • Company Profiles
    • Annual Reports
  • Events
    • Trade Shows & Events
    • Earnings & Conference Calls
    • Business Wire Events
  • PR Services
    • Press Release Distribution
    • Distribution Lists
    • Industry Targeting
    • LatinoWire & Ethnic Media
    • Public Policy Wire
    • Trade Show Services
    • Photos & Multimedia Marketing
    • GloMoSoMe
    • Press Release Measurement
    • Mobile Alerts
    • Clips & Research
    • Fax & Email Services
    • Online Newsrooms
    • News Feeds
  • IR Services
    • Material News Disclosure
    • XBRL
    • EDGAR (US)
    • IPO Services
    • SEDAR (Canada)
    • European Disclosure
    • Corporate Social Responsibility (CSR)
    • Investor Targeting
    • Fax & Email Services
    • Online Investor Centers
    • IR Resource Center
  • SEO Services
    • Press Release Optimization
    • EON: Enhanced Online News
    • Webinars & Resources
  • Journalist Tools
    • PressPass: Your News
    • Conduct Surveys
    • Business Wire News Feeds
    • Business Wire News On Your Website
    • Journalism Associations
  • Support & Education
    • FAQ
    • How to Write a Press Release
    • How To Optimize a Press Release for Search
    • How to Distribute a Press Release
    • Find Your News Online
    • Sample Press Release
    • Features News Tips
    • International Media Tips
    • SEC Regulations
    • Exchange Guidelines
    • White Papers
    • Webinars & Podcasts
    • Get WiredIn!
  • About Us
    • Business Wire Newsroom
    • Contact Us
    • History
    • Jobs
  • About Us
  • Contact Us
  • Site Map
  • Privacy Statement
  • Terms of Use
  • ©2012 Business Wire

More Business Wire sites

  • Canada
  • UK/Ireland
  • Deutschland
  • France
  • Italy
  • Japan
  • EON: Enhanced Online News
  • Tradeshownews.com
  • PYMNTS.com

About Us

  • Business Wire Newsroom
  • Contact Us
  • Business Wired blog

News on BusinessWire.com

  • All News
  • RSS Feeds
  • Business Wire Mobile Apps

Follow Us on Twitter

  • @BusinessWire
  • @BWSportsWire
  • @BWPolitics
  • @BWCSRNews
  • @EONpr
  • @TradeshowNews
  • @BW_Canada
  • @BWIntlMedia
  • @BWInfoDiva
  • @BusinessWireFR
  • @BWLatinoWire

Like Us on Facebook

  • Business Wire
  • Tradeshow News