New tool to crack Internet passwords
A HACKING expert has launched a US$200 password-cracking tool that makes it easy to decipher Internet traffic sent through a widely used method for securing business communications.
Moxie Marlinspike, one of the world's top encryption experts, unveiled the tool on Saturday during a presentation at the Def Con hacking conference in Las Vegas.
Marlinspike said he developed the service, CloudCracker.com, by taking advantage of a vulnerability he discovered in a widely used virtual private network technology known as point-to-point tunneling protocol.
Virtual private networks, or VPNs, scramble traffic as it travels between a PC and its final destination so the data is useless to hackers if they eavesdrop on those communications.
But Marlinspike provides clients with a tool to analyze captured data streams and create a data file that they upload to his website. He then runs it through code-cracking programs to gain a password to unscramble the protected communications.
With access to Internet traffic, hackers could potentially steal passwords to financial accounts, read business e-mails and learn business secrets.
Marlinspike said he will not screen clients to determine whether they are using it for illegal purposes, but his ultimate intent is to pressure operating systems makers to create safer software.
Moxie Marlinspike, one of the world's top encryption experts, unveiled the tool on Saturday during a presentation at the Def Con hacking conference in Las Vegas.
Marlinspike said he developed the service, CloudCracker.com, by taking advantage of a vulnerability he discovered in a widely used virtual private network technology known as point-to-point tunneling protocol.
Virtual private networks, or VPNs, scramble traffic as it travels between a PC and its final destination so the data is useless to hackers if they eavesdrop on those communications.
But Marlinspike provides clients with a tool to analyze captured data streams and create a data file that they upload to his website. He then runs it through code-cracking programs to gain a password to unscramble the protected communications.
With access to Internet traffic, hackers could potentially steal passwords to financial accounts, read business e-mails and learn business secrets.
Marlinspike said he will not screen clients to determine whether they are using it for illegal purposes, but his ultimate intent is to pressure operating systems makers to create safer software.
- About Us
- |
- Terms of Use
- |
-
RSS
- |
- Privacy Policy
- |
- Contact Us
- |
- Shanghai Call Center: 962288
- |
- Tip-off hotline: 52920043
- 沪ICP证:沪ICP备05050403号-1
- |
- 互联网新闻信息服务许可证:31120180004
- |
- 网络视听许可证:0909346
- |
- 广播电视节目制作许可证:沪字第354号
- |
- 增值电信业务经营许可证:沪B2-20120012
Copyright © 1999- Shanghai Daily. All rights reserved.Preferably viewed with Internet Explorer 8 or newer browsers.