While I really don't care about BTC or Crypto-Currencies beside the technical underlying implementations and the math, I do care about their hardware. Because at the moment, the market is being flooded with different hardware Mining Rigs.  If you can get your hands on such a rig and you are willing to invest some time into modifying it, you can build a low-cost but very efficient GPU Hash Cracker. I just spent four days installing and setting up mine, so in this article I will try to give you some tips so that you can avoid the mistakes that I made.

First, let's see what a good professional Rig cost and what it can do:

A good Rig is the Sagitta Brutalis https://sagitta.pw/hardware/gpu-compute-nodes/brutalis/.

Specs (base config):

With this configuration the price is about 22.000 $. For smaller Companies or indepent Red Teamers/Pen.Testers/Researchers this is not feasible.

Of course, the performance is great as well, for example:

MD5: 200 GH/s

SHA256: 23012.1 MH/s

WPA/WPA2: 3177.6 kH/s

NTLMv2: 13149.5 MH/s

Full Benchmark here: https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a270c40

So I searched the local "yard sale apps" (willhaben.at in my case) and found a Miner. Equipped with 8 RX580, 1250 € is a good deal, especially since it was professional made and seemed in very good condition.

But there is something with miners, you should keep in mind:

So, all in all I paid (with some luck) roundabout 1500€. After the current Cracking Job, I will give a full Benchmark. Right now I'm cracking a WPA2-PMKID with roundabout 1700 KH/s. This is about 50%+ of the performance of the Sagitta Brutalis for less than 7% of its price. Very acceptable.

If you build your own

It took me a few days to get this one running (sometimes it's easier, sometimes it's harder). Here a few things:

If you can, go for NVidia

HashCats Support for NVidia is much better, especially with Linux (what would have been my favorite combination).

Sometimes you don't have the choice, like me in this case. I needed additional cracking power ASAP (Cloud is not an option!), so I just bought what was available. But if you have the time to wait, just wait for a NVidia Mining Rig.

Ask the Seller

Ask for the following things:

If you go for AMD, prepare for trouble

AMD is cheaper, but you should prepare to invest some time. There are reasons, why the Sagitta Brutalis is equipped like this, here are some things to consider with AMD:

kfd kfd: skipped device 1002:67df, PCI rejects atomics

If you can see this - bad luck. Check the BIOS if you can adjust the compatibility of the PCIE Ports, but in most cases, you will to get windows.

Flash the VBIOS

Especially if you run into BlueScreens or SegFaults like "THREAD_STUCK_IN_DRIVER", re-flash the original VBIOS on the Video Card.

You need the ATI/NVIDIA Flash Tool and the BIOS, which you can obtain here (most cases): https://www.techpowerup.com

Cloud?

Only if you have a just one hash or rarely usage. Otherwise Cloud is very expensive. For the Price of this Rig, you can get:

  1. Month of 2x2080TI from LeaderGPU
  2. Some days of very infeffecient (for that purpose) NVidia Tesla Cards at AWS.

Conclusion

If you are ready to invest some time, you can build a solid Cracking Rig for little money. But there is no guarantee, that everythign works out.

I will keep you posted with numbers, but all-in-all you can expect about the half performance of the already mentioned Sagitta Brutalis, if you have for example 8xRX580. The scaling is quite linear.

A last word: If you can't find the WPA/NTLM/... Hash in the first Week, you probaly find it never. I will make another tutorial howto generate effective Password Lists with OSINT and some standard Kali Tools.

The awesome image used to head this article is called "Shredder" and it was created by Zhivko Terziivanov.
源链接

Hacking more

...