Skip to main content
Back to Contest Archive

Crack Me If You Can 2010

DEF CON 18 contest materials with hashcat winning, plus early CMIYC rules, teams, wordlists, downloads, password-creation notes, and scoreboards.

Event
DEF CON 18
Dates
July 2010
Winner
hashcat

Updates

  • Update: (12:10AM PST - SUNDAY) - Contest is DONE. See the high scorers on the stats page (winners will be declared later). We will be crunching stats like crazy starting tomorrow. We will be confirming all the password cracks, and look for missed points.

  • Update: (11:59PM PST - Saturday) - Lots of updates coming in rapidly now, updates to the stats page are going to get slightly lagged, but after we cut off new submissions in 10 minutes, the crunching will catch up.

  • Update: (11:21PM PST - Saturday) - We will officially accept submissions until 12:10 AM PST Sunday, since we were a few minutes late sending out the hashes in the beginning. Also, while we will freeze the official scores at that time, we'll continue processing submissions afterwards if anyone wants to keep going.

  • Update: (11:21PM PST - Saturday) - We will officially accept submissions until 12:10 AM PST Sunday, since we were a few minutes late sending out the hashes in the beginning. Also, while we will freeze the official scores at that time, we'll continue processing submissions afterwards if anyone wants to keep going.

  • Update: (3:55PM PST - Saturday) - 6PM "Meet and Greet" for all team members! Come by the table and meet the other teams! Talk shop!

  • Update: (3:25PM PST - Saturday) - Chris O'Donnell figured out the easter egg in our tshirts!

  • Update: (12PM PST - Saturday) - We are now displaying the stats page on the ceiling in the contest room.

  • Update: (6PM PST - Friday) - Something has come up w/several different people so we thought we would just clarify:
    We want *complete passwords*. Which means, when cracking an LanMan hash and it's broken into two chunks, we don't want the chunks independent of one another; we want the actual, usable resulting password.

    So if you crack 'PASSWORD', we don't want two lines in the submission, one for 'PASSWOR' and one for 'D'. To put it in terms of JtR, we want to see passwords extracted from john -show output, not from your john.pot file.

    Similarly if you have cracked only the second half, don't send us '???????D'. If you couldn't sit down on the network and log in with it, it's not been cracked yet.

  • Update: (NOON PST - Friday) - The complete hash list is available to the public now!!

  • Update: (NOON PST - Friday) - The complete hash list is available to the public now!!! Anyone can play Click here for the hashes

  • Update: (11:45AM PST - Friday) - Teams: Come by our table in the contest area to get your registration code and get the magic piece of paper that allows you to win the $$$$

  • Update: (11:45AM PST - Friday) - Teams: Teams: Come by for your FREE Tshirts as well!

  • Update: (10:00 am PST - Friday) - If you are having problems with PGP - or havent received the hashes - please email a __HUMAN__ at defcon-2010-contest@korelogic.com (or stop by our booth in the contest area)

  • Update: (9:15 am PST - Friday) - Stats page is in BETA! We are working on finalizing it - stay tuned

  • Update: (9:15 am PST - Friday) - When submitted cracked passwords, DO NOT send the hash - just the plain-text passwords (via PGP)

  • Update: (9:00 am PST - Friday) - Contest is underway!

  • Update: (8:00 pm PST) Registration is open! If you are registered, you will automatically be emailed the hashes tonight at midnight. Otherwise, you have to wait till NOON on Friday for the public list to be revealed.