Moderator's introduction
So, before I introduce our next speaker, let me clear up one thing right away: there is no magic today, no sorcery, no wizardry. Maslenitsa is over, and we won't need to burn anyone today. Let's dot all the i's right away.
It's just that, you know, the password "password" still comes up quite often. But all of that will be covered today by not just our marketing director, but the head of Brute Force module development for Mobile Criminalist, Valeria Vakhrushina. Let's give her a round of applause.
Dear beloved boss, your microphone and your clicker.
Talk and Q&A
He made me come up on stage. Good afternoon, colleagues. I'm very glad to welcome you. Yuri Mikhailovich, please don't bury me in questions today. Thank you.
So, today I'm going to tell you about MK Brute Force — dictionary or mask, how it works. Dima's already introduced me; you all know my split personality as a marketer, but I also work on this module. We live in an age not only of digital forensics, but also of total digitalization. What do we have? We have loads of apps, phones, tablets, smartphones, laptops, and we put passwords on all of them. That's as safe as it gets, but I also know that both security folks and IT folks always say: please, set proper passwords, please make them long, use mixed case, use special characters, letters, make passwords at least 10 characters.
Well, I understand that among you, yes, surely everyone follows that advice. Unfortunately, among ordinary users — and fortunately for us forensics people — it usually isn't followed. Here are the most popular passwords. Well, we all know qwerty, password, guest, admin, admin — nothing's off the table. How often do you think they're used? I found some very curious statistics that horrify me. But then again, for brute-forcing that's good.
And then there are people who think they'll use some simple combinations. Like, a digit, two letters, the next digit, the two adjacent letters. Straight along the keyboard — very convenient to type all that. We understand perfectly well that if we run a mask attack, and we understand what the combination is and how to define it, then that password will be cracked just as easily. I also want to show you some interesting statistics on the most used passwords in the Russian Federation. The stats aren't the freshest: 2023–2024. I especially liked "Baltika 9" and "Sotochka". Really great passwords. But home phone numbers, cell phone numbers — of course, again, a lot of people use those. Why memorize something extra?
So, the usual advice? Change it regularly, the password must consist of at least refrain from using, blah-blah-blah-blah-blah. I recommend to everyone — to you, not to those whose passwords we'll be cracking — I recommend to everyone: 2FA, always. Okay, let's talk about password cracking itself. Whatever we're cracking, whatever we're cracking the password to, in any case, in any tool, it always comes down to two methods. It's either a dictionary or a mask. A dictionary, in principle, also counts as brute force, but how does it work? We have some dictionary pre-loaded into the program — it could be our MK Brute Force or some other solution, open source, paid, doesn't matter.
And it contains a certain set of characters, a certain set of strings. In our case, for example, it's a txt file with the most popular or, say, leaked passwords, or ones you created yourself, and so on. And the attack runs directly through those combinations that are defined. What matters? A dictionary is a great thing, of course; an attack with it will go much faster, but if the password is, let's say, safe, following all the recommendations of IT and security people, we're unlikely to crack it with a dictionary. That said, I want to note that it's a must when cracking passwords to phones. Because there we're dealing with either PINs or patterns, and in that case a mask takes longer; easier to run it all through a dictionary.
I know there are lots of tools now — again, that's what they write online — that people have started using AI to create new dictionaries based on some leaked data. Well, let's say, applying some mutations in advance in order to later load that into some brute-forcing tool and crack the password. A cool thing. We made something roughly similar. In Mobile Criminalist, in MK Brute Force, we call it a dictionary based on personal data. What is it? If you choose this method, a password manager opens, and it holds as much data as could be gathered from the extraction. That's personal data: the first part of emails, phone numbers, surnames, etc. Based on that, you can build a dictionary, which, again, can speed up cracking. But here you do have to do some magic.
If we're talking about something complex — the mask. A head-on mask — I'll say it right away, don't use a mask head-on. That's 26 letters of the Latin alphabet in upper case, the same number of letters in lower case, plus 10 digits, plus 33, I think, special characters. So if you launch such an attack head-on, we need either super-powerful hardware, or, I don't know, or there has to be some element of luck. Just as an example. A ten-character password made up of just lowercase letters. 141 trillion possible combinations, well, more than that.
Now we add uppercase to that. At this point I even — sorry — googled what these numbers are called. More than three quadrillion. Let's add digits. At this point we're already talking more than a quintillion passwords. Well, sorry, I'm used to working in powers, so I'm checking my notes. Well, basically, cracking such a thing, I don't know, is unlikely to work out. That's why we have standard commands. I specifically put the commands up — how to create a mask, how to set it. Makes things a lot easier. Basically, these are hashcat commands, applicable to MK Brute Force. So in this case, name is a fixed value, either at the beginning or at the end.
Next we've got a question mark plus an a — that's basically any character. So there's room to play around here. Well, I'll show you right now on video, using MK Brute Force as an example. So, we know that if we need to crack a password for something as part of some investigation, we're usually very tight on time. So for my part, I'd recommend: first we run through a dictionary, then we add a mask. That'll make life easier and speed things up a bit. And a second point. GPU power, CPU power. We've got hashcat built into MK Brute Force. So our password cracking runs faster on the graphics card. In some tools, password cracking runs faster on the CPU.
And of course, if your hardware allows it, distributed password cracking is a really great thing. It'll speed up the password-cracking process a lot, and you'll get a successful result much sooner. Anticipating your questions — we're working on it, since we've had lots of requests from you, but we haven't implemented it yet. A lot of tools have it. To sum up: cracking isn't just brute force for its own sake, to mess around, you really do need some meaningful hypotheses, to use some meaningful dictionaries, and keep all of it updated in time, so you don't sit there running hardware and burning electricity for nothing.
I'll show you a bit on video. So, what I was saying about the combination. Here I'm taking a standard ZIP archive. The hash will be recognized automatically, so with MK, we just load it in there. It takes some time to extract.
In the first case, we go by dictionary. I take the simplest preloaded dictionary — the 100,000 most popular passwords, no mutations, just head-on on the GPU.
With ZIP, we'll see the result during initialization — we won't even see the attack process, because ZIP is a very simple hash. So besides what I mentioned — the cracking complexity, the mask complexity, GPU power, the amount of GPU memory — what else matters? What also matters is the complexity, the heaviness, say, of the hash we crack. Because a ZIP archive will always crack fast. If we're talking Telegram Local Passcode or some Huawei HiSuite, things like that — of course, those use completely different encryption methods. My colleagues will talk about this a bit later — that'll be the next talk.
There, cracking will take much longer. So, we can see the dictionary run has finished. Not a single password matched. Unfortunately, no success. And so we try a mask. Here, of course, I know this ZIP archive's password, since I recorded the video. So I know right away that I've got 7 characters there. And that's how I set them up. And I suggest running it again. I know the password has caps and digits. Now let's just try it head-on. We're not going to crack it right now. We won't wait for it, I'll say right away. You'll just see the amount of time you could potentially spend on a task like this.
7.5 hours. Sounds scary, right? Now let's try a mask that's partly custom-written. Again, the commands are standard hashcat ones. Those who haven't tried using this — give it a try. It's a really great thing, it makes the task a lot easier. So at the start we've set 3 completely random characters, and then 4 fixed digits.
Just in case anyone has questions later, why initialization takes a while, if you've used the brute-force tool — and I hope you do use it — again, it's due to the heavy hash. So you can see, during initialization we got the password MFD2025.
We'll see exactly the same picture if we do it the other way around, that is, write a mask but specify the first three letters, then leave four digits to be cracked. It'll crack just as fast.
But for the full picture, right now we'll wait here for it to initialize, we'll make sure MK Brute Force works, and I'll be pleased.
There, we can see the password was again cracked in 11 seconds. Well, pretty cool overall, considering I can't say I've got the fanciest graphics card.
But for our real-world conditions, we'll again set it for 7 characters. This is what I'm creating right now. But the first three are completely random, and the last four are digits. And now, during initialization, we'll already see that it's not 7.5 hours, like when we run a mask over everything possible and impossible. It's, I think, something around an hour. Yeah, there — 51 minutes, a pretty decent hashrate. But in that case it's already worth a try. There's a chance of success. Okay, so, regarding MK Brute Force. I hope you've all used it. Let me remind you it's built on hashcat, which is considered one of the fastest solutions on the market.
I know hashcat 7.0 has come out — we'll soon build it into MK Brute Force. It's got quite a lot of updates that'll interest you. The main goal, actually, was an easy interface, to lower the barrier to entry. Because hashcat, if you're familiar with it, doesn't really have an interface. This is what MK Brute Force can currently crack passwords for. So, the super-useful stuff, I'd probably highlight this for you, I suppose — it's Androids, iTunes, HiSuites, and other cool things.
People often ask questions, so I put it on the slides, in the presentation. You need to know the hash in hashcat format. Where do I get the hash? For archives and office documents, we load them right into MK Brute Force, the hash is recognized. For a passcode for Telegram Desktop, BitLocker, NTLM — through Scout, Scout passes the hash to MK Brute Force automatically, and you launch the attack. For all the rest — that is, all mobile device backups plus Apple Notes, you load the backup into Mobile Criminalist, and a modal window will pop up, asking you to enter the password or crack it. When you click "Crack", again the hash is recognized, and you launch the attack.
Those who haven't used it and haven't bought MK yet for one reason or another, we have a free mobile version of MK Brute Force via the QR code. You can use it — it's specially for you. Oh, so many phones — how nice. Wait, wait, wait. Let me say right away that, if anything, you can go to the website, and there, in a separate tab, there's MK Brute Force, which you can download from a computer. Absolutely right.
Alright, wonderful. Use it. I'll be glad to hear your feedback. I hope there'll be a minimum of bugs. Thank you for your attention. I'm ready to hear your questions, wishes, suggestions, what's missing, what you'd like, which hashes you want supported. And if anyone wants a closer look at something, you're welcome at our booth, let's talk. The suggestions, I suggest we save for a bit later, for the roast, and move to questions for now. But before we get to them, I really loved your line when you said you don't have the best graphics card, and you've got five there. That was really good. I really don't have the best graphics card, some of us have the Ti ones.
Alright. Colleagues, any questions? There are. Ilya, go over there, please.
Two quick questions. Is the functionality available in the Brute Force application from the link? Specifically, is password cracking of a physical Android image available? And the second question. If automatic password cracking doesn't start on that same Android, we import the image into Mobile Criminalist, but it doesn't start automatically. Can it be set up for brute force manually? —
— FBE and FDE, that's my pain point, sorry. No, unfortunately, FBE and FDE aren't supported in the free version. I can tell you right away that there are specifics to hash support. We built in the most current versions of exactly these image types. So if something specific isn't supported and the attack doesn't start from Mobile Criminalist in automatic mode, then write to support, making sure to specify the device, because I'll need to do further research and add support for those hashes.
It will be possible, of course. We're happy to add to the backlog. Ilya, tell me please, is that all over there? Next question? —
— Wait, Ilya, Ilya, Ilya, one second. San Sanych is there. Ilya, one second, I also have a very... —
— Good afternoon, is distributed cracking ever going to happen? I did say, we're working on it. You're asking really hard, we're working really hard, honestly. I'm hoping for the first half of '26, but I'm not promising anything. The dark circles under your eyes confirm it, right? No, honestly, we started working on distributed cracking, but since hashcat released version 7.0 with a huge number of updates, which will be useful to you, so we decided to update the core first, after all, and only then deal with distributed cracking. Our developers have already lost 5 kilos. Ilya, there was another question over there. Valeria, I listened carefully. You were saying, on the one hand, there are possibilities for AI to create non-standard passwords, right?
Have you modeled the situation the other way around? AI capabilities for figuring out passwords, your developers in particular? —
— Honestly, no. Unfortunately, building artificial intelligence into Mobile Criminalist is prohibited. The legislation would object. But what's the difference? You'll get there anyway. No, San Sanych, honestly, not yet. The idea is interesting, trying it the other way around, but this is probably closer to rainbow tables. Anyway, we'll think about it. I see a raised hand, I'm on my way. Only thing is, I'll probably go around you from this side, because I might not squeeze through over there, so I'll need a little help. —
— Hello, a question has come up. You just said that the legislation prohibits the use of artificial intelligence. Can you say which specific provision prohibits it? Because from what's been said, it's not quite clear what's meant by the artificial intelligence used to crack passwords. And there's a chance that actually what's meant by that is just some traditional algorithms, the same ones used everywhere. And it's unclear how, in that sense, the legislation comes down with total clarity and says, oh no, that's not allowed now. So, I hope the question is clear. —
— The question is clear. Of course, I do have a law degree, but I won't answer this question from a legal standpoint. But I can say that Mobile Criminalist by itself doesn't analyze or accumulate your information. We hand you the software, and we get nothing back. So, to train anything, we'd need to get information back from you. And that would not be good. —
— Now it's clear.
Dmitry Yankovoy, are you going to let me go today? One more question. Alright, while Ilya Anatolyevich gets to the question, I have just one request, colleagues: all of you, literally all, will get a recording of today's event, so please put your phones away and don't film. We'll email everything to you later, it'll all look nice. Ilya Anatolyevich, the question now. Just one more, really quick. You mentioned that you can build a dictionary based on the data extracted from a specific device. In practice I haven't seen how that can be done from Mobile Criminalist? Yes, it's from Mobile Criminalist, that is, when you're in MK Brute Force. There are three methods. Standard dictionary, mask, and a dictionary based on personal data. If you select the dictionary based on personal data and click the "Add" button, it brings up exactly the password manager built into MK, and there you can build that dictionary.
Okay, I suggest we leave everything else for the roast. Valeria, thank you very much. Let's send Lera off with applause. We're leaving everything exactly as it is.