creates a massive credential database
Project description
CredentialDatabase
Create a massive credential database with collections like BreachCompilation or with credentials from password files
Features of CredentialDatabase:
- develop awesome brute-force/credstuffer attacks which are based on CredentialDatabase
- build up a huge hash table for SHA1, SHA256, SHA512 and md5 hashes
- create a REST API interface similar to the ghostproject
- create a massive password database
- multithreaded database scripts
BreachCompilation includes billion clear text credentials discovered in a single database
(file size: ~42GB)
Content
Installation
installation with pip
pip3 install CredentialDatabase
or from source
sudo python3 setup.py install
or create a wheel for installing the package with pip
sudo python3 setup.py bdist_wheel
install the package with pip
pip3 install CredentialDatabase-1.0.0-py3-none-any.whl
uninstall the package with pip
pip3 uninstall CredentialDatabase
Usage and Examples
BreachCompilationDatabase.py
execute the console script BreachCompilationDatabase
BreachCompilationDatabase --host 192.168.1.2 --port 5432 --user john --password test1234 --dbname breachcompilation --breachpath /path/to/BreachCompilation
insert subsequent command to run the script completely in background
nohup BreachCompilationDatabase --host 192.168.1.2 --port 5432 --user john --password test1234 --dbname breachcompilation --breachpath /path/to/BreachCompilation &>/dev/null &
or use a tool like screen
Database structure
schemas: 0-9, a-z, symbols (first character from email)
tables: 0-9, a-z, symbols (second character from email)
id | email | password | username | provider | sh1 | sh256 | sh512 | md5
- script runtime about 8 days
- needs disk space for about 569 GB
PasswordDatabase.py
execute the console script PasswordDatabase
with --breachpath
PasswordDatabase --host 192.168.1.2 --port 5432 --user john --password test1234 --dbname passwords --breachpath /path/to/BreachCompilation
or with --filepath
PasswordDatabase --host 192.168.1.2 --port 5432 --user john --password test1234 --dbname passwords --filepath /path/to/CredentialFile --proc 10
insert subsequent command to run the script completely in background
nohup PasswordDatabase --host 192.168.1.2 --port 5432 --user john --password test1234 --dbname breachcompilation --breachpath /path/to/BreachCompilation &>/dev/null &
or use a tool like screen
Database structure
schemas: 0-9, a-z, symbols (first character from password)
tables: 0-9, a-z, symbols (second character from password)
password | length | isnumber | issymbol | ts
Postgresql Database Settings
install PostgreSQL dependencies via apt
sudo apt-get install postgresql libpq-dev postgresql-client postgresql-client-common
Follow this tutorial to set up a
postgresql environment. For graphical visualization install pgAdmin4.
Postgresql Advanced
create an index only scan for columns email
and password
CREATE index idx_pass_email on "a"."d"(email, password);
vacuum the table, so that the visibility map to be up-to-date
VACUUM "a"."d";
Delete a table completely with
drop table "a"."d" cascade
Settings for tuning your postgresql server are here
Logs
logs can be found in /var/log/CredentialDatabase
Troubleshooting
add your current user to group syslog
, this allows the application/scripts to create a folder in
/var/log
. Replace <user>
with your current user
sudo adduser <user> syslog
to apply this change, log out and log in again and check with the terminal command groups
Changelog
All changes and versioning information can be found in the CHANGELOG
License
Copyright (c) 2019 Bierschneider Christian. See LICENSE for details
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file CredentialDatabase-1.0.2.tar.gz
.
File metadata
- Download URL: CredentialDatabase-1.0.2.tar.gz
- Upload date:
- Size: 22.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/42.0.2 requests-toolbelt/0.9.1 tqdm/4.41.0 CPython/3.6.9
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 3cf6e7b9cfdcb5369ae8a21e03bf08532771769007a80a1f107f994c62670eb3 |
|
MD5 | d2e9d0142b1a29703de4e8a028992781 |
|
BLAKE2b-256 | 09c1c9434d0a120bf53c07669bfddc072967b97e5a2334176fe02f08dcb5d14e |
File details
Details for the file CredentialDatabase-1.0.2-py3-none-any.whl
.
File metadata
- Download URL: CredentialDatabase-1.0.2-py3-none-any.whl
- Upload date:
- Size: 32.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/42.0.2 requests-toolbelt/0.9.1 tqdm/4.41.0 CPython/3.6.9
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | e995b079ca54f6de789cbe667917d25bb6871bfa88135b5f484e24adb9154dbf |
|
MD5 | a5383fabb8723b520e25bb0396eda0ce |
|
BLAKE2b-256 | 7719f505d458c8e5beb0be8f1eeec6d979a82e1865d4229e6f38eec1d4fcae67 |