Openwall Profile
Openwall

@Openwall

7,089
Followers
10
Following
1
Media
370
Statuses

Infosec focused free software, research, publications, community activities @oss_security . Tweets are announcements. Please direct questions to @solardiz .

Joined June 2010
Don't wanna be here? Send us removal request.
@Openwall
Openwall
5 years
After 4.5 years and 6000+ commits, John the Ripper 1.9.0-jumbo-1 password cracker is out:
3
166
290
@Openwall
Openwall
7 years
Announcing our most controversial project ever: Linux Kernel Runtime Guard is an LKM that post-detects kernel exploits
3
63
108
@Openwall
Openwall
3 years
Linux Kernel Runtime Guard (LKRG) now has its own website and Twitter account @lkrg_org . Version 0.9.2 by @Adam_pi3 et al. adds support for new Linux kernels (5.14 to 5.16-rc* and hopefully beyond).
0
22
51
@Openwall
Openwall
10 years
John the Ripper 1.8.0-jumbo-1 is out after 2+ years in development: http://t.co/dv6szrF4Pf
4
110
47
@Openwall
Openwall
5 years
John the Ripper 1.9.0 core is out: Stay tuned for 1.9.0-jumbo-1, which will be "the real one".
3
24
36
@Openwall
Openwall
4 months
Just published slides of @solardiz 's @offensive_con keynote talk "Password cracking: past, present, future"
0
13
39
@Openwall
Openwall
10 years
"yescrypt - password hashing scalable beyond bcrypt and scrypt" #PHDays talk slides by @solardiz : http://t.co/Ok4LUdsSKU
0
37
35
@Openwall
Openwall
9 years
CVE IDs difficult and slow to obtain? Enter OVE: Problem solved?
3
39
32
@Openwall
Openwall
6 years
yespower 1.0.0 - a proof-of-work (PoW) focused fork of yescrypt:
2
21
28
@Openwall
Openwall
4 years
Juho Junnila's Master's Thesis "Effectiveness of Linux Rootkit Detection Tools" shows our LKRG as by far the most effective kernel rootkit detector (of those tested), even though that wasn't our primary focus: h/t @Adam_pi3
0
14
29
@Openwall
Openwall
12 years
John the Ripper 1.7.9-jumbo-6 adds GPU support (CUDA & OpenCL) and A LOT more, biggest -jumbo update ever: http://t.co/506zPgZj
0
119
27
@Openwall
Openwall
11 years
Our USENIX WOOT'13 slides and paper "Looking inside the (Drop) box" (Security Analysis of #Dropbox ): http://t.co/YmS1T6Yp17
0
19
25
@Openwall
Openwall
7 months
Linux Kernel Runtime Guard (LKRG) 0.9.8 by @Adam_pi3 et al. is out, adding a remote kernel message logging capability sponsored by @binarly_io . This update is already packaged for Rocky Enterprise Linux 8.9 and 9.3 @rocky_linux .
1
13
26
@Openwall
Openwall
6 years
Linux Kernel Runtime Guard (LKRG) 0.6 by @Adam_pi3 adds poor man's CFI, systemd support, and much more:
1
15
24
@Openwall
Openwall
1 year
Slides of @solardiz 's opening keynote talk at @SSTIC and its revision at @BSidesLjubljana held in @muzej , entitled "15+ years of oss-security":
0
11
24
@Openwall
Openwall
6 years
Linux Kernel Runtime Guard (LKRG) 0.2 is out; adds loading at early boot stage, reduced performance impact, bugs fixed:
0
17
21
@Openwall
Openwall
5 years
Linux Kernel Runtime Guard (LKRG) 0.7 by @Adam_pi3 adds experimental support for ARM64 (AArch64) and grsecurity, support for Linux 5.1 and 5.2+, greater SMEP enforcement, and much more:
0
13
22
@Openwall
Openwall
6 years
All of our slides (2001 to 2018) are now available not only at but also on SpeakerDeck
1
12
22
@Openwall
Openwall
8 years
We're looking for freelancers to join our team as independent contractors for occasional software security audits and such. Email @solardiz .
0
17
21
@Openwall
Openwall
7 months
Slides of @solardiz 's talk "Linux kernel remote logging: approaches, challenges, implementation" from @BSidesZagreb The talk also included live demo of LKRG @lkrg_org catching @chompie1337 's CVE-2021-3490 exploit and logging this event on another continent
1
10
19
@Openwall
Openwall
3 years
yescrypt is now the default password hashing scheme on Debian 11 (released recently) and Fedora 35 (released today). Perhaps Ubuntu and RHEL next? Updated the per-distro references at
1
8
21
@Openwall
Openwall
5 years
passwdqc 1.4.0, a new version of our password/passphrase strength checking and enforcement tool set, is out. This version adds optional non-English messages, Linux-PAM audit support, and includes portability and documentation fixes:
0
11
18
@Openwall
Openwall
3 years
Linux Kernel Runtime Guard (LKRG) 0.9.1 by @Adam_pi3 et al. addresses issues reported against the 0.9.0 release and continues to evolve:
0
8
18
@Openwall
Openwall
1 year
Linux Kernel Runtime Guard (LKRG) 0.9.7 by @Adam_pi3 et al. is out, adding support for Linux 6.4 to 6.5.x and hopefully beyond, as well as for new RHEL 9.1 and 9.2 kernels.
0
7
18
@Openwall
Openwall
3 years
Linux Kernel Runtime Guard (LKRG) 0.9.0 by @Adam_pi3 et al. is out, adding support for new Linux kernels, optionally building LKRG in-tree, Continuous Integration (boot tests in VMs, including with Ubuntu's daily updated mainline kernels), and much more:
0
7
18
@Openwall
Openwall
6 years
Linux Kernel Runtime Guard (LKRG) 0.3 by @Adam_pi3 is sort of a stable release and here are Adam's slides from CONFidence on LKRG under the hood
0
20
16
@Openwall
Openwall
12 years
PHP mt_rand() seed crackers for CPU (5 minutes) and GPU (seconds): http://t.co/JL3tAoFS
0
22
18
@Openwall
Openwall
4 years
Linux Kernel Runtime Guard (LKRG) 0.8 by @Adam_pi3 adds support for latest kernels, 32-bit ARM (already had 64), Raspberry Pi 3 & 4, better scalability, performance, and tradeoffs, the notion of profiles, new documentation, @Phoronix benchmarks, and more:
0
14
17
@Openwall
Openwall
4 years
All of our projects previously maintained in CVS are now in Git (yes, older ones with commit histories for ~20 years) and under the Openwall organization on GitHub. There are a total of 22 Git repositories now.
1
9
15
@Openwall
Openwall
4 years
Linux Kernel Runtime Guard (LKRG) in a nutshell, @Adam_pi3 's slides presented a few days ago at @OSTconf (online; formerly Linux Piter): (announcement: )
@OSTconf
OSTconf
4 years
🗓 10-13 августа 2020 / OSTсonf 0 Спикер: 👤 Adam Zabrocki​​ / USA. Kings Park, NY / NVIDIA Тема: 📋 LKRG in a nutshell #OSTconf
Tweet media one
0
3
8
0
11
15
@Openwall
Openwall
6 years
Linux Kernel Runtime Guard (LKRG) 0.5 by @Adam_pi3 has more robust integrity checking of modules, new GCC support
0
12
14
@Openwall
Openwall
11 years
John the Ripper 1.8: http://t.co/urWBYGPLKC New incremental mode, status line, --fork, --node. Sponsored under @Rapid7 's #Magnificent7 .
1
63
16
@Openwall
Openwall
4 years
We've just launched Openwall Password Recovery and Password Security Auditing Bundle in @awsmarketplace . Start your password recovery or audit in #AWS cloud in minutes, complete it within our 5-day free trial or support our Open Source project afterwards.
Tweet media one
Tweet media two
0
15
14
@Openwall
Openwall
4 years
Linux Kernel Runtime Guard (LKRG) 0.8.1 by @Adam_pi3 is a bug fix release to address a user-triggerable Oops (read via a near-NULL pointer) on 64-bit Linux 4.17+ first reported by @zx2c4 :
0
9
15
@Openwall
Openwall
10 years
New all.lst wordlist with better handling of European languages and Russian. JtR 1.8.0 Pro for Linux. http://t.co/0a4rsBRZmY
1
15
14
@Openwall
Openwall
4 years
John the Ripper "in the cloud" got its own homepage:
@Openwall
Openwall
4 years
We've just launched Openwall Password Recovery and Password Security Auditing Bundle in @awsmarketplace . Start your password recovery or audit in #AWS cloud in minutes, complete it within our 5-day free trial or support our Open Source project afterwards.
Tweet media one
Tweet media two
0
15
14
0
7
14
@Openwall
Openwall
9 years
Johnny 2.0 cross-platform GUI frontend for John the Ripper is ready for testing http://t.co/eAF5G7STdm including Windows and OS X binaries
0
22
14
@Openwall
Openwall
8 years
Just published: An analysis of Zcash's use of the Equihash proof-of-work scheme, by @solardiz Thanks to @zcashco
0
18
12
@Openwall
Openwall
12 years
PHP mt_rand() seed cracking in 1 minute (worst case) on inexpensive CPU: http://t.co/wQaWNzSZ
0
19
13
@Openwall
Openwall
10 years
We are umbrella org for radare reverse-engineering framework in #GSoC 2015. @radareorg ideas are ours too! http://t.co/YreksKOJP9
0
30
13
@Openwall
Openwall
13 years
John the Ripper 1.7.7-jumbo-6 cracks SSH keys ( #OpenMP ), PDF, RAR, Sybase ASE, hmailserver, MediaWiki: http://openwall.com/1776
0
38
13
@Openwall
Openwall
2 years
John the Ripper "in the cloud" update: Updated JtR, Amazon Linux 2, NVIDIA GPU driver. Enabled new AWS instance types. Benchmarks for new largest Intel 128x AVX-512 and AMD 192x AVX2 instances. Spot instance friendliness and updated launch instructions.
0
3
12
@Openwall
Openwall
1 year
passwdqc 2.0.3 releases for Unix-like and Windows systems are out, with many minor additions and changes. Leaked password filter files updated to HIBP v8, encoding the 847+ million unique passwords (from billions of accounts) in a 3.5 GB file.
0
4
13
@Openwall
Openwall
1 year
Arch Linux's default password hashing algorithm changed to yescrypt:
0
5
13
@Openwall
Openwall
13 years
Effects of password policies on keyspace reduction (at least 2 of each class is 53x): http://t.co/WQnUj5t8
0
16
13
@Openwall
Openwall
7 years
yescrypt 1.0.0 KDF and password hashing scheme, release timed for #BSidesLjubljana :
0
17
12
@Openwall
Openwall
4 years
We've started consolidating our Git repositories under the newly setup Openwall organization on GitHub:
0
7
12
@Openwall
Openwall
6 years
yescrypt KDF & password hash release 1.0.1 adds guidelines on parameters by use case, comparison to scrypt & Argon2:
0
9
12
@Openwall
Openwall
7 years
yescrypt: large-scale password hashing Haswell metaprogramming by @solardiz #BSidesLjubljana
1
7
12
@Openwall
Openwall
12 years
John the Ripper patch to crack the leaked #LinkedIn raw SHA-1 hashes with first 20 bits 0'ed: http://t.co/LpL87Cwd (by JimF)
0
31
12
@Openwall
Openwall
11 years
Our #passwords13 slides, "Energy-efficient bcrypt cracking" by Katja Malvoni and @solardiz : http://t.co/CAx73rcN14
1
16
12
@Openwall
Openwall
10 years
#ZeroNights keynote game by @solardiz , magic PDF by @angealbertini , screenshots, references http://t.co/4bWqJEErfM Play online or in DOSBox
1
25
11
@Openwall
Openwall
13 years
John the Ripper 1.7.8-jumbo-2 cracks password-protected WinZip archives with AES encryption: http://openwall.com/1782
0
17
11
@Openwall
Openwall
7 years
Linux Kernel Runtime Guard (LKRG) 0.1 is out, cleaned up and with support for Linux kernel 4.15 and RHEL 7.4:
0
20
11
@Openwall
Openwall
8 years
DES-based crypt(3) cracking on ZTEX 1.15y FPGA boards with JtR: 740M/s, 40W, mask & hybrid, multi-hash, multi-board
1
10
11
@Openwall
Openwall
8 years
Attend @BSidesLjubljana on March 10 for @solardiz 's talk "yescrypt: large-scale password hashing" & much more
0
8
10
@Openwall
Openwall
5 years
yescrypt KDF and password hashing scheme updated to 1.1.0 and included in Fedora 29+ and ALT Linux via libxcrypt: yespower PoW scheme updated to 1.0.1:
1
5
10
@Openwall
Openwall
7 months
Thank you @binarly_io for sponsoring the remote logging research and implementation, @CtrlIQ @Rocky_Linux for encouraging this release and talk, @chompie1337 for the reliable exploit, and @BSidesZagreb organizers, sponsors, speakers for such a great event.
1
1
11
@Openwall
Openwall
10 years
Openwall GNU/*/Linux (Owl) 3.1-stable is available http://t.co/Jk0TPUyp1u whereas 3.0-stable is EOL'ed
0
10
9
@Openwall
Openwall
9 years
We accepted 7 #GSoC students: 5 for Openwall and 2 for @radareorg . Most already made progress at their projects: http://t.co/g2JIuQc7a3
0
13
9
@Openwall
Openwall
7 years
php_mt_seed 4.0 mt_rand() seed cracker now supports PHP 3.0.7 to 7.1.x+ (was 5.2.1 to 7.0.x), has new documentation
0
6
9
@Openwall
Openwall
12 years
@solardiz 's "Password hashing at scale (for Internet companies with millions of users)" #YaC2012 slides: http://t.co/4tsaui6l
0
14
9
@Openwall
Openwall
10 years
Energy-efficient bcrypt cracking #passwords14 slides and #woot14 paper reflecting progress since last year: http://t.co/Hiu2ev8r9a #FPGA
0
10
8
@Openwall
Openwall
4 years
John the Ripper "in the cloud" update: Updated JtR, sample files. No free trial. More supported instance types. Benchmarks for p3.2xlarge (NVIDIA Tesla V100), c5.24xlarge (Intel Xeon, AVX-512), and c5a.24xlarge (AMD EPYC, AVX2). Spot instance instructions.
0
5
8
@Openwall
Openwall
9 years
Aleksey Cherepanov's "john-devkit: specialized compiler for hash cracking" presentation slides from #PHDays 2015: http://t.co/AiardEPea4
0
10
7
@Openwall
Openwall
13 years
John the Ripper 1.7.7: AVX & XOP, plaintext cracking, Apache hashes, ... Sponsored by @Rapid7 . http://openwall.com/j177
0
20
8
@Openwall
Openwall
6 years
yescrypt KDF & password hash release 1.0.2 drops MAP_POPULATE, adds an optimization, fixes a code correctness issue
0
6
8
@Openwall
Openwall
11 years
New php_mt_seed supports AVX2 & Xeon Phi, maps 1 or many, (non-)first, (in)exact PHP mt_rand() outputs back to seeds: http://t.co/9ac2Cr57Nh
0
13
6
@Openwall
Openwall
9 years
We've decided to skip #GSoC 2016. We hope that @radareorg will be accepted as a mentoring org of their own this time, and we vouch for them.
0
5
7
@Openwall
Openwall
4 years
passwdqc 2.0.0 is out, adding support for external wordlist, denylist, and binary filter files. The latter are improved cuckoo filters, for which the added pwqfilter program includes reusable grep-like functionality. HIBP v7 613M+ passwords fit in 2.3 GiB.
0
5
7
@Openwall
Openwall
7 years
blists 2.0 web interface to indexed mbox: attachment downloads, conversion to UTF-8, recent message lists, calendars
0
1
6
@Openwall
Openwall
6 years
Linux Kernel Runtime Guard (LKRG) 0.4 by @Adam_pi3 adds Linux 4.17+ support
0
5
7
@Openwall
Openwall
11 years
New version of our password/passphrase strength checking and policy enforcement tool set, passwdqc 1.3.0: http://t.co/IxMDhpJY1v
1
5
6
@Openwall
Openwall
7 years
phpass 0.5 is out, providing PHP 7 friendliness and other minor cleanups:
0
6
6
@Openwall
Openwall
9 years
New Openwall GNU/*/Linux ISOs & #OpenVZ templates with security updates since January, including for BIND TKEY DoS: http://t.co/77i8o68q0a
0
11
6
@Openwall
Openwall
8 years
Openwall GNU/*/Linux security fixes for Linux kernel "Dirty COW" and BIND DoS vulnerabilities:
0
13
6
@Openwall
Openwall
6 years
New Owl updates address Meltdown, Linux kernel "POP SS", and procps issues. RPMs, ISOs, OpenVZ templates.
0
5
6
@Openwall
Openwall
13 years
Team john-users took 3rd place (of 22) in #CrackMeIfYouCan , and 1st for 5 of 20 hash types. Here's how: http://t.co/ZmvoyB9
0
8
6
@Openwall
Openwall
13 years
John the Ripper 1.7.8 released, reduces DES S-box gate count by 17%: http://openwall.com/j178 Research sponsor: @Rapid7
0
31
5
@Openwall
Openwall
10 years
New assembler for AMD GCN GPUs, in C# http://t.co/ZgH5J6Ipmq inspired by @balidani 's GSoC 2013 project with us
0
4
5
@Openwall
Openwall
12 years
"Password security: past, present, future" #passwords12 slides by @solardiz and @bartavelle : http://t.co/V7m2zZNJ
1
6
5
@Openwall
Openwall
13 years
John the Ripper 1.7.9-jumbo-5 adds RADIUS shared secrets, SHA-0, faster MSSQL/MySQL/Lotus5, build for Windows: http://t.co/WeQA0Ty3
0
18
4
@Openwall
Openwall
4 years
After 10 years since the previous release, we've just released version 1.2 of tcb, implementation of our alternative password shadowing scheme. Changes include libxcrypt and new glibc support, non-English messages support, and dropping of NIS/NIS+ support.
0
8
5
@Openwall
Openwall
13 years
John the Ripper 1.7.9 has #OpenMP parallelization of bitslice DES and of MD5-crypt integrated: http://t.co/nIT8eOqu
0
29
5
@Openwall
Openwall
8 years
New Openwall GNU/*/Linux ISOs & #OpenVZ templates with minor security updates since last August:
2
3
4
@Openwall
Openwall
8 years
JtR jumbo binaries from our Ubuntu snap package also work on Windows 10 as-is
@Openwall
Openwall
8 years
JtR jumbo as snap package for Ubuntu 16.04 LTS via Ubuntu Store contributed by Claudio Andre
0
2
4
0
5
4
@Openwall
Openwall
13 years
John the Ripper 1.7.8-jumbo-7 cracks Mac OS X Lion salted SHA-512 (with #OpenMP ), old PKZIP, and lots more: http://t.co/Mty5RNzW
1
21
4
@Openwall
Openwall
13 years
John the Ripper 1.7.9 official build for Windows; Hash Suite GUI for Windows: http://t.co/3Z4D7MkV
0
9
3
@Openwall
Openwall
12 years
John the Ripper Cracks Slow Hashes On GPU (Slashdot submission with link to news story by The H): http://t.co/0UvS425n
0
10
4
@Openwall
Openwall
13 years
Openwall t-shirts are now available from 0-day Clothing: http://t.co/CAnSIgz2
0
2
4
@Openwall
Openwall
12 years
"Automatic wordlists mangling rules generation" #passwords12 slides by John the Ripper developer @bartavelle : http://t.co/IVQIObAv
1
4
4
@Openwall
Openwall
8 years
JtR jumbo as snap package for Ubuntu 16.04 LTS via Ubuntu Store contributed by Claudio Andre
0
2
4
@Openwall
Openwall
8 years
passwdqc for Windows (Active Directory) is now freely downloadable for pre-purchase evaluation:
0
4
4
@Openwall
Openwall
14 years
Owl and ALT Linux not vulnerable to #glibc bugs discovered by @taviso : http://openwall.com/lists/announce/2010/10/22/1
0
11
3
@Openwall
Openwall
12 years
@solardiz will speak at #ZeroNights on defensive use of gigabytes of RAM/SSDs for password hashing: http://t.co/jj3QMLEG Nov 19-20, Moscow
0
10
3
@Openwall
Openwall
13 years
Faster DES-based #tripcode cracking with John the Ripper: http://t.co/MMT4QGgg
0
5
3
@Openwall
Openwall
13 years
New t-shirts - gentleman John the Ripper, common passwords crossword, I love john.pot: http://t.co/uUb6hnGP
1
7
3
@Openwall
Openwall
4 years
Two minor updates: passwdqc 2.0.1 offers improved auto-generated password/passphrase policy descriptions: scanlogd 2.2.8 builds cleanly with recent glibc:
0
1
3
@Openwall
Openwall
13 years
John the Ripper 1.7.8 password cracker build for Android: http://openwall.com/lists/announce/2011/07/24/2
0
8
3