[Crime2.0] Cracking Prompt Helper (Fix #324) | Tools & Userscr…

[Crime2.0] Cracking Prompt Helper (Fix #324)

​

    • nodelore [2786679]
    • Role: Civilian
    • Level: 100
    • Posts: 568
    • Karma: 607
    • Last Action: 18 minutes
      • 1
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Thread created on 14:22:13 - 21/12/23 (2 years ago)
    |
    Last replied 23:48:50 - 05/09/26 (24 days ago)
    1.2 version release
    This version solves the issue caused by Patch #324
    Before, the script watches the location hash to update crime page, and since #324 update, TORN uses history.pushState to update location url, making the script unavailable in some cases(It can still work if you go directly into the crack page and refresh)
    This version solves several leftover issues, including the latest on mentioned above:
    1. Intercept history.pushState action to update crime page correctly
    2. Fix duplicated index which hinders the display of crime options. (Before, if you accumulate a lot of crack crime options, some of them will not have result panel. And now this is fixed.)
    3. Remove leftover candidates when there are actual no results.(Before, after you brute force a password, if there are no results, the previous candidates will mislead player.)
    4. Remove useless expire time which does not actually work.
    5. Switch letter in candidates to upper form to be unified with provided ones.
    Since the Patch has severe effect on previous version of script, I recommend you to UPDATE as soon as possible. Besides, the script should work on PDA as well, I have done limited tests so there may be leftover issues.

    Future plan:
    1. On PDA, due to the limitation of APP implementation, now I only provide with direct access to password list, which limits the precision of results. I did some search for work solver API which can help mobile platform without taking much space or time to load, but found none. If you have any clues about the API, please contact with me.
    2. For now, users may focus on the first candidates provided by script. However, this way does not promise the correctness of passwords. In the following version, the letter which shows up more frequently will be highlighted. And the candidates containing the highlighted letter will also be moved to front of queue.

    1.1 version release
    This version has fixed some severe bugs that may harm experience
    1. Now the script will be correctly loaded when you enter the page from crime main entry, no need to refresh anymore
    2. The script will correctly work on encrypted password
    3. The script will match correct target after finishing a cracking
    4. The script will not prevent users from operating Rig components
    5. Add 10m work list to options(it will be more accurate, but take much more network performance. You need to know a 10m worklist may take up 90M space!)
    6. Support automatic generation of password database list, now you customize your own database and the options will be updated.(In the previous version this feature actually does not work)
    I would recommend you upgrade to the new version ASAP
    And if you meet any issues about this version, please contact with me to report it, thanks :)


    1.0.4 version release
    After the refactoring, now the script will support mobile platform!
    However, there are still issues in it, take care about the following issues:

    1. Copy and paste the script into PDA
    2. Open crime page, enter cracking link, you would need to refresh the page for one or two times to make it correctly load styles
    3. By default, the dictionary on mobile platform is set to 100k, which is small enough to load quickly and has potential to be cached
    4. Now you don't need to modify script any more, just choose the dictionary you want to use by clicking the select component:

    Besides, the script provide with an experimental feature that:
    * when you guess an incorrect option, it will except the word out of candidates
    * the exception list will be refreshed if you reload the page


    I also make use of network injection instead of mutationobserver to capture the page changing more accurate
    The new version may also introduce some unexpected issues, welcome to report and help me improve the script, thanks!
    =====================

    Since the new crime has been released, as ched said:
    Online infrastructure in Torn mainly uses a weaker encryption method known as ICE (Individual Character Encryption), where each character in a password is encrypted separately. Although this might seem more secure, it actually allows the password's length to be known and makes each character vulnerable to brute-force attacks.
    This script is a beta version, which starts by simple idea: we can utilize open source weak password database to guess cracking result

    Here is the example:



    Usage
    1. Install Link
    2. I would recommend you to brute force at least half of total words and then take the results from the script as reference

    Customization
    For now, I am using the password dictionary from Pwdb-Public, which is a list containing 1m weak passwords.
    I also provide you with several alternative:
    You can simply open the script, change the CRACKER_SEL to the key of dictionary you want to use, for example, 1m_alter or 10k.
    You just need to choose the dictionary you need in the page, the script will load it directly
    Note that, a larger dictionary may provide you with more accurate results along with higher performance cost, while a smaller dictionary may be inaccurate.
    Besides, I do not have time to test more password list, if you have better choices, welcome to inform me about that.

    Known Issue
    1. If you have any ideas about migrating the script to mobile platform like PDA or kiwi browsers, welcome to tell me your ideas. I'm not good at frontend design and don't find a good way to display it in mobile.
    2. The script only gives you prompts about possible results, but does not promise the correcteness.

    1. On PDA, the script need the page to be refreshed for several times before it could work, I need to investigate the source of the problem and find some way to fix it
    2. On PDA, a large dictionary will not be cached due to the limitation of localStorage. Besides, the persistence of small dictionary may also have issues(but since the dictionary can be as small to less than 1Mb, I think it will not have severe problems)
    3. I do not test the script on Alook browser and not sure about whether it could work

    Acknowledgement
    Thanks to contr4l_[2893026], a lots of ideas of the script comes from my friend :D
    Thanks to helpful suggestions from Kwack [2190604] and BigManBilly [2636589]
    Last edited by nodelore on 14:25:00 - 07/02/24 (2 years ago)
    • contr4l_ [2893026]
    • Role: Civilian
    • Level: 88
    • Posts: 129
    • Karma: 186
    • Last Action: 1 day
      • 1
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 14:35:27 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    love my jdmm. :3
    • SoftRabbit [2776069]
    • Role: Civilian
    • Level: 100
    • Posts: 39
    • Karma: 23
    • Last Action: 4 hours
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 14:42:31 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    Good job!

    bc005738-413f-4429-bece-c3ba6d334322-2776069.gif

    • aban15mm [2703793]
    • Role: Civilian
    • Level: 100
    • Posts: 69
    • Karma: 63
    • Last Action: 30 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 14:44:52 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    Greatly speeds us up
    Last edited by aban15mm on 14:45:15 - 21/12/23 (2 years ago)

    Every day after work, I want to stay alone in the car for a few minutes……

    • Lenin [2199004]
    • Role: Civilian
    • Level: 100
    • Posts: 9,031
    • Karma: 22,486
    • Last Action: 25 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 15:26:18 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    ahahahah f**k yes
    1710f7f8-1b8a-14b0-2199004.png
    • masheen [2625139]
    • Role: Civilian
    • Level: 100
    • Posts: 5,894
    • Karma: 8,743
    • Last Action: 2 months
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 16:04:13 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    You're awesome! Thank you so much!

    ◉_◉

    • Baxia [2456400]
    • Role: Civilian
    • Level: 100
    • Posts: 2,414
    • Karma: 4,624
    • Last Action: 10 hours
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 18:38:42 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    Thank you so much, can’t wait to try it out. But I have to ask for shits and giggles. Will I need to put my full access api key there?
    • nodelore [2786679]
    • Role: Civilian
    • Level: 100
    • Posts: 568
    • Karma: 607
    • Last Action: 18 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 18:57:34 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    Baxia [2456400]

    Thank you so much, can’t wait to try it out. But I have to ask for shits and giggles. Will I need to put my full access api key there?
    No need for any APIs, this script works by simply regex matching and open-source database
    • MightyGoober [812478]
    • Role: Civilian
    • Level: 100
    • Posts: 6,717
    • Karma: 21,041
    • Last Action: 21 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 22:51:58 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    nodelore [2786679]

    [color=blue][size=24]1.2 version release[/size][/color] This version solves the issue caused by [url=https://www.torn.com/forums.php#/p=threads&f=1&t=16381254&b=0&a=0]Patch #324 [/url]Before, the script watches the location hash to update crime page, and since #324 update, TORN uses history.pushState to update location url, making the script unavailable in some cases(It can still work if you go directly into the crack page and refresh) This version solves several leftover issues, including the latest on mentioned above: 1. Intercept history.pushState action to update crime page correctly 2. Fix duplicated index which hinders the display of crime options. (Before, if you accumulate a lot of crack crime options, some of them will not have result panel. And now this is fixed.) 3. Remove leftover candidates when there are actual no results.(Before, after you brute force a password, if there are no results, the previous candidates will mislead player.) 4. Remove useless expire time which does not actually work. 5. Switch letter in candidates to upper form to be unified with provided ones. [color=#d6336c][size=18]Since the Patch has severe effect on previous version of script, I recommend you to [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper]UPDATE[/url] as soon as possible. Besides, the script should work on PDA as well, I have done limited tests so there may be leftover issues. [/size][/color] [size=18][color=#0ca678]Future plan:[/color] [/size]1. On PDA, due to the limitation of APP implementation, now I only provide with direct access to password list, which limits the precision of results. I did some search for work solver API which can help mobile platform without taking much space or time to load, but found none. If you have any clues about the API, please contact with me. 2. For now, users may focus on the first candidates provided by script. However, this way does not promise the correctness of passwords. In the following version, the letter which shows up more frequently will be highlighted. And the candidates containing the highlighted letter will also be moved to front of queue. [color=blue][size=24]1.1 version release[/size][/color] This version has fixed some severe bugs that may harm experience 1. Now the script will be correctly loaded when you enter the page from crime main entry, no need to refresh anymore 2. The script will correctly work on encrypted password 3. The script will match correct target after finishing a cracking 4. The script will not prevent users from operating Rig components 5. Add 10m work list to options(it will be more accurate, but take much more network performance. You need to know a 10m worklist may take up 90M space!) 6. Support automatic generation of password database list, now you customize your own database and the options will be updated.(In the previous version this feature actually does not work) I would recommend you upgrade to the new version ASAP And if you meet any issues about this version, please contact with me to report it, thanks :) [color=blue][size=24]1.0.4 version release[/size][/color] After the refactoring, now the script will support mobile platform! However, there are still issues in it, take care about the following issues: [color=red] 1. Copy and paste the script into PDA 2. Open crime page, enter cracking link, you would need to refresh the page for one or two times to make it correctly load styles 3. By default, the dictionary on mobile platform is set to 100k, which is small enough to load quickly and has potential to be cached 4. Now you don't need to modify script any more, just choose the dictionary you want to use by clicking the select component: [center][img width=360]https://media.discordapp.net/attachments/822890599669563446/1188152179467493417/Screenshot_20231224_001023_com.manuito.tornpda_ed.jpg[/img][/center] [/color] Besides, the script provide with an experimental feature that: [b][color=#f76707][size=16]* when you guess an incorrect option, it will except the word out of candidates * the exception list will be refreshed if you reload the page[/size][/color][/b] I also make use of network injection instead of mutationobserver to capture the page changing more accurate The new version may also introduce some unexpected issues, welcome to report and help me improve the script, thanks! ===================== Since the new crime has been released, as ched said: [quote]Online infrastructure in Torn mainly uses a weaker encryption method known as ICE (Individual Character Encryption), where each character in a password is encrypted separately. Although this might seem more secure, it actually allows the password's length to be known and makes each character vulnerable to brute-force attacks. [/quote][color=#95ccff][size=24]This script is a beta version, which starts by simple idea: we can utilize open source weak password database to guess cracking result[/size][/color] Here is the example: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1188163714382299298/cracking_example.jpg[/img] [/center] [color=orange][size=24]Usage[/size][/color] 1. [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper][size=18]Install Link[/size][/url] 2. I would recommend you to brute force [b][size=18]at least half of total words[/size][/b] and then take the results from the script as reference [color=#1c7cd6][size=24]Customization[/size][/color] For now, I am using the password dictionary from [url=https://github.com/ignis-sec/Pwdb-Public/blob/master/wordlists/ignis-1M.txt]Pwdb-Public[/url], which is a list containing 1m weak passwords. I also provide you with several alternative: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1187395707582304387/customization.jpg[/img][/center] [s]You can simply open the script, change the [b]CRACKER_SEL[/b] to the key of dictionary you want to use, for example, 1m_alter or 10k.[/s] You just need to choose the dictionary you need in the page, the script will load it directly Note that, a larger dictionary may provide you with more accurate results along with higher performance cost, while a smaller dictionary may be inaccurate. Besides, I do not have time to test more password list, if you have better choices, welcome to inform me about that. [color=red][size=24]Known Issue[/size][/color] [s]1. If you have any ideas about migrating the script to mobile platform like PDA or kiwi browsers, welcome to tell me your ideas. I'm not good at frontend design and don't find a good way to display it in mobile. 2. The script only gives you prompts about possible results, but does not promise the correcteness.[/s] 1. On PDA, the script need the page to be refreshed for several times before it could work, I need to investigate the source of the problem and find some way to fix it 2. On PDA, a large dictionary will not be cached due to the limitation of localStorage. Besides, the persistence of small dictionary may also have issues(but since the dictionary can be as small to less than 1Mb, I think it will not have severe problems) 3. I do not test the script on Alook browser and not sure about whether it could work [color=green][size=24]Acknowledgement[/size][/color] [b]Thanks to [b][url=https://www.torn.com/profiles.php?XID=2893026]contr4l_[2893026][/url][/b], a lots of ideas of the script comes from my friend :D [/b]Thanks to helpful suggestions from [b][url=https://www.torn.com/profiles.php?XID=2190604]Kwack [2190604][/url] and [b][url=https://www.torn.com/profiles.php?XID=2636589]BigManBilly [2636589][/url][/b][/b]
    Couldn't you have the script (on first ever load), download all the lists in to browser storage?

    Then, the script would do a simple local check without the need to ping out? Plus, you would have every available word from all the lists.
    Last edited by MightyGoober on 22:52:19 - 21/12/23 (2 years ago)

    • VioletStorm [2233317]
    • Role: Civilian
    • Level: 15
    • Posts: 1,433
    • Karma: 1,448
    • Last Action: 2 months
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 22:55:13 - 21/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    Absolutely wonderful work m8! Torn PDA would really benefit from this script, you should join the discord! We've got a dedicated discussion channel for PDA scripts!

    • Ahab [1735214]
    • Role: Civilian
    • Level: 100
    • Posts: 5,749
    • Karma: 11,059
    • Last Action: 7 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 00:58:58 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    That 1m list seems to be it.

    Could you not add the matched passes to the relevant section instead of off to the side covering chat
    • nodelore [2786679]
    • Role: Civilian
    • Level: 100
    • Posts: 568
    • Karma: 607
    • Last Action: 18 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 01:34:18 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    nodelore [2786679]

    [color=blue][size=24]1.2 version release[/size][/color] This version solves the issue caused by [url=https://www.torn.com/forums.php#/p=threads&f=1&t=16381254&b=0&a=0]Patch #324 [/url]Before, the script watches the location hash to update crime page, and since #324 update, TORN uses history.pushState to update location url, making the script unavailable in some cases(It can still work if you go directly into the crack page and refresh) This version solves several leftover issues, including the latest on mentioned above: 1. Intercept history.pushState action to update crime page correctly 2. Fix duplicated index which hinders the display of crime options. (Before, if you accumulate a lot of crack crime options, some of them will not have result panel. And now this is fixed.) 3. Remove leftover candidates when there are actual no results.(Before, after you brute force a password, if there are no results, the previous candidates will mislead player.) 4. Remove useless expire time which does not actually work. 5. Switch letter in candidates to upper form to be unified with provided ones. [color=#d6336c][size=18]Since the Patch has severe effect on previous version of script, I recommend you to [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper]UPDATE[/url] as soon as possible. Besides, the script should work on PDA as well, I have done limited tests so there may be leftover issues. [/size][/color] [size=18][color=#0ca678]Future plan:[/color] [/size]1. On PDA, due to the limitation of APP implementation, now I only provide with direct access to password list, which limits the precision of results. I did some search for work solver API which can help mobile platform without taking much space or time to load, but found none. If you have any clues about the API, please contact with me. 2. For now, users may focus on the first candidates provided by script. However, this way does not promise the correctness of passwords. In the following version, the letter which shows up more frequently will be highlighted. And the candidates containing the highlighted letter will also be moved to front of queue. [color=blue][size=24]1.1 version release[/size][/color] This version has fixed some severe bugs that may harm experience 1. Now the script will be correctly loaded when you enter the page from crime main entry, no need to refresh anymore 2. The script will correctly work on encrypted password 3. The script will match correct target after finishing a cracking 4. The script will not prevent users from operating Rig components 5. Add 10m work list to options(it will be more accurate, but take much more network performance. You need to know a 10m worklist may take up 90M space!) 6. Support automatic generation of password database list, now you customize your own database and the options will be updated.(In the previous version this feature actually does not work) I would recommend you upgrade to the new version ASAP And if you meet any issues about this version, please contact with me to report it, thanks :) [color=blue][size=24]1.0.4 version release[/size][/color] After the refactoring, now the script will support mobile platform! However, there are still issues in it, take care about the following issues: [color=red] 1. Copy and paste the script into PDA 2. Open crime page, enter cracking link, you would need to refresh the page for one or two times to make it correctly load styles 3. By default, the dictionary on mobile platform is set to 100k, which is small enough to load quickly and has potential to be cached 4. Now you don't need to modify script any more, just choose the dictionary you want to use by clicking the select component: [center][img width=360]https://media.discordapp.net/attachments/822890599669563446/1188152179467493417/Screenshot_20231224_001023_com.manuito.tornpda_ed.jpg[/img][/center] [/color] Besides, the script provide with an experimental feature that: [b][color=#f76707][size=16]* when you guess an incorrect option, it will except the word out of candidates * the exception list will be refreshed if you reload the page[/size][/color][/b] I also make use of network injection instead of mutationobserver to capture the page changing more accurate The new version may also introduce some unexpected issues, welcome to report and help me improve the script, thanks! ===================== Since the new crime has been released, as ched said: [quote]Online infrastructure in Torn mainly uses a weaker encryption method known as ICE (Individual Character Encryption), where each character in a password is encrypted separately. Although this might seem more secure, it actually allows the password's length to be known and makes each character vulnerable to brute-force attacks. [/quote][color=#95ccff][size=24]This script is a beta version, which starts by simple idea: we can utilize open source weak password database to guess cracking result[/size][/color] Here is the example: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1188163714382299298/cracking_example.jpg[/img] [/center] [color=orange][size=24]Usage[/size][/color] 1. [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper][size=18]Install Link[/size][/url] 2. I would recommend you to brute force [b][size=18]at least half of total words[/size][/b] and then take the results from the script as reference [color=#1c7cd6][size=24]Customization[/size][/color] For now, I am using the password dictionary from [url=https://github.com/ignis-sec/Pwdb-Public/blob/master/wordlists/ignis-1M.txt]Pwdb-Public[/url], which is a list containing 1m weak passwords. I also provide you with several alternative: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1187395707582304387/customization.jpg[/img][/center] [s]You can simply open the script, change the [b]CRACKER_SEL[/b] to the key of dictionary you want to use, for example, 1m_alter or 10k.[/s] You just need to choose the dictionary you need in the page, the script will load it directly Note that, a larger dictionary may provide you with more accurate results along with higher performance cost, while a smaller dictionary may be inaccurate. Besides, I do not have time to test more password list, if you have better choices, welcome to inform me about that. [color=red][size=24]Known Issue[/size][/color] [s]1. If you have any ideas about migrating the script to mobile platform like PDA or kiwi browsers, welcome to tell me your ideas. I'm not good at frontend design and don't find a good way to display it in mobile. 2. The script only gives you prompts about possible results, but does not promise the correcteness.[/s] 1. On PDA, the script need the page to be refreshed for several times before it could work, I need to investigate the source of the problem and find some way to fix it 2. On PDA, a large dictionary will not be cached due to the limitation of localStorage. Besides, the persistence of small dictionary may also have issues(but since the dictionary can be as small to less than 1Mb, I think it will not have severe problems) 3. I do not test the script on Alook browser and not sure about whether it could work [color=green][size=24]Acknowledgement[/size][/color] [b]Thanks to [b][url=https://www.torn.com/profiles.php?XID=2893026]contr4l_[2893026][/url][/b], a lots of ideas of the script comes from my friend :D [/b]Thanks to helpful suggestions from [b][url=https://www.torn.com/profiles.php?XID=2190604]Kwack [2190604][/url] and [b][url=https://www.torn.com/profiles.php?XID=2636589]BigManBilly [2636589][/url][/b][/b]

    MightyGoober [812478]

    Couldn't you have the script (on first ever load), download all the lists in to browser storage? Then, the script would do a simple local check without the need to ping out? Plus, you would have every available word from all the lists.
    The cache has already been used to save the chosen list.
    However, since the 1M list is 8m size which exceeds the limit of localstorage which is 5m, now we use tampermonkey storage to save it.
    • nodelore [2786679]
    • Role: Civilian
    • Level: 100
    • Posts: 568
    • Karma: 607
    • Last Action: 18 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 01:39:16 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    Ahab [1735214]

    That 1m list seems to be it. Could you not add the matched passes to the relevant section instead of off to the side covering chat
    I'm not sure about what is the meaning of the off to the side covering chat, if there is detailed description or any illustration it would be helpful.
    Thanks
    • nodelore [2786679]
    • Role: Civilian
    • Level: 100
    • Posts: 568
    • Karma: 607
    • Last Action: 18 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 01:42:49 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    VioletStorm [2233317]

    Absolutely wonderful work m8! Torn PDA would really benefit from this script, you should join the discord! We've got a dedicated discussion channel for PDA scripts!
    Thanks for your advice.
    I should have joined PDA channel, if meeting any troubles in the following migration, I will ask for some advice
    • cankles [2137519]
    • Role: Civilian
    • Level: 100
    • Posts: 2,341
    • Karma: 5,814
    • Last Action: Now
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 01:53:11 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    SMTH using their powers for good. R+
    • Winguem [2862329]
    • Role: Civilian
    • Level: 91
    • Posts: 461
    • Karma: 470
    • Last Action: 16 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 06:19:36 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    nodelore [2786679]

    [color=blue][size=24]1.2 version release[/size][/color] This version solves the issue caused by [url=https://www.torn.com/forums.php#/p=threads&f=1&t=16381254&b=0&a=0]Patch #324 [/url]Before, the script watches the location hash to update crime page, and since #324 update, TORN uses history.pushState to update location url, making the script unavailable in some cases(It can still work if you go directly into the crack page and refresh) This version solves several leftover issues, including the latest on mentioned above: 1. Intercept history.pushState action to update crime page correctly 2. Fix duplicated index which hinders the display of crime options. (Before, if you accumulate a lot of crack crime options, some of them will not have result panel. And now this is fixed.) 3. Remove leftover candidates when there are actual no results.(Before, after you brute force a password, if there are no results, the previous candidates will mislead player.) 4. Remove useless expire time which does not actually work. 5. Switch letter in candidates to upper form to be unified with provided ones. [color=#d6336c][size=18]Since the Patch has severe effect on previous version of script, I recommend you to [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper]UPDATE[/url] as soon as possible. Besides, the script should work on PDA as well, I have done limited tests so there may be leftover issues. [/size][/color] [size=18][color=#0ca678]Future plan:[/color] [/size]1. On PDA, due to the limitation of APP implementation, now I only provide with direct access to password list, which limits the precision of results. I did some search for work solver API which can help mobile platform without taking much space or time to load, but found none. If you have any clues about the API, please contact with me. 2. For now, users may focus on the first candidates provided by script. However, this way does not promise the correctness of passwords. In the following version, the letter which shows up more frequently will be highlighted. And the candidates containing the highlighted letter will also be moved to front of queue. [color=blue][size=24]1.1 version release[/size][/color] This version has fixed some severe bugs that may harm experience 1. Now the script will be correctly loaded when you enter the page from crime main entry, no need to refresh anymore 2. The script will correctly work on encrypted password 3. The script will match correct target after finishing a cracking 4. The script will not prevent users from operating Rig components 5. Add 10m work list to options(it will be more accurate, but take much more network performance. You need to know a 10m worklist may take up 90M space!) 6. Support automatic generation of password database list, now you customize your own database and the options will be updated.(In the previous version this feature actually does not work) I would recommend you upgrade to the new version ASAP And if you meet any issues about this version, please contact with me to report it, thanks :) [color=blue][size=24]1.0.4 version release[/size][/color] After the refactoring, now the script will support mobile platform! However, there are still issues in it, take care about the following issues: [color=red] 1. Copy and paste the script into PDA 2. Open crime page, enter cracking link, you would need to refresh the page for one or two times to make it correctly load styles 3. By default, the dictionary on mobile platform is set to 100k, which is small enough to load quickly and has potential to be cached 4. Now you don't need to modify script any more, just choose the dictionary you want to use by clicking the select component: [center][img width=360]https://media.discordapp.net/attachments/822890599669563446/1188152179467493417/Screenshot_20231224_001023_com.manuito.tornpda_ed.jpg[/img][/center] [/color] Besides, the script provide with an experimental feature that: [b][color=#f76707][size=16]* when you guess an incorrect option, it will except the word out of candidates * the exception list will be refreshed if you reload the page[/size][/color][/b] I also make use of network injection instead of mutationobserver to capture the page changing more accurate The new version may also introduce some unexpected issues, welcome to report and help me improve the script, thanks! ===================== Since the new crime has been released, as ched said: [quote]Online infrastructure in Torn mainly uses a weaker encryption method known as ICE (Individual Character Encryption), where each character in a password is encrypted separately. Although this might seem more secure, it actually allows the password's length to be known and makes each character vulnerable to brute-force attacks. [/quote][color=#95ccff][size=24]This script is a beta version, which starts by simple idea: we can utilize open source weak password database to guess cracking result[/size][/color] Here is the example: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1188163714382299298/cracking_example.jpg[/img] [/center] [color=orange][size=24]Usage[/size][/color] 1. [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper][size=18]Install Link[/size][/url] 2. I would recommend you to brute force [b][size=18]at least half of total words[/size][/b] and then take the results from the script as reference [color=#1c7cd6][size=24]Customization[/size][/color] For now, I am using the password dictionary from [url=https://github.com/ignis-sec/Pwdb-Public/blob/master/wordlists/ignis-1M.txt]Pwdb-Public[/url], which is a list containing 1m weak passwords. I also provide you with several alternative: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1187395707582304387/customization.jpg[/img][/center] [s]You can simply open the script, change the [b]CRACKER_SEL[/b] to the key of dictionary you want to use, for example, 1m_alter or 10k.[/s] You just need to choose the dictionary you need in the page, the script will load it directly Note that, a larger dictionary may provide you with more accurate results along with higher performance cost, while a smaller dictionary may be inaccurate. Besides, I do not have time to test more password list, if you have better choices, welcome to inform me about that. [color=red][size=24]Known Issue[/size][/color] [s]1. If you have any ideas about migrating the script to mobile platform like PDA or kiwi browsers, welcome to tell me your ideas. I'm not good at frontend design and don't find a good way to display it in mobile. 2. The script only gives you prompts about possible results, but does not promise the correcteness.[/s] 1. On PDA, the script need the page to be refreshed for several times before it could work, I need to investigate the source of the problem and find some way to fix it 2. On PDA, a large dictionary will not be cached due to the limitation of localStorage. Besides, the persistence of small dictionary may also have issues(but since the dictionary can be as small to less than 1Mb, I think it will not have severe problems) 3. I do not test the script on Alook browser and not sure about whether it could work [color=green][size=24]Acknowledgement[/size][/color] [b]Thanks to [b][url=https://www.torn.com/profiles.php?XID=2893026]contr4l_[2893026][/url][/b], a lots of ideas of the script comes from my friend :D [/b]Thanks to helpful suggestions from [b][url=https://www.torn.com/profiles.php?XID=2190604]Kwack [2190604][/url] and [b][url=https://www.torn.com/profiles.php?XID=2636589]BigManBilly [2636589][/url][/b][/b]
    Technically it is totally working on Kiwi/Yandex browsers on mobile, just need to open page in desktop mode and it just works.
    • nodelore [2786679]
    • Role: Civilian
    • Level: 100
    • Posts: 568
    • Karma: 607
    • Last Action: 18 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 07:00:08 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    nodelore [2786679]

    [color=blue][size=24]1.2 version release[/size][/color] This version solves the issue caused by [url=https://www.torn.com/forums.php#/p=threads&f=1&t=16381254&b=0&a=0]Patch #324 [/url]Before, the script watches the location hash to update crime page, and since #324 update, TORN uses history.pushState to update location url, making the script unavailable in some cases(It can still work if you go directly into the crack page and refresh) This version solves several leftover issues, including the latest on mentioned above: 1. Intercept history.pushState action to update crime page correctly 2. Fix duplicated index which hinders the display of crime options. (Before, if you accumulate a lot of crack crime options, some of them will not have result panel. And now this is fixed.) 3. Remove leftover candidates when there are actual no results.(Before, after you brute force a password, if there are no results, the previous candidates will mislead player.) 4. Remove useless expire time which does not actually work. 5. Switch letter in candidates to upper form to be unified with provided ones. [color=#d6336c][size=18]Since the Patch has severe effect on previous version of script, I recommend you to [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper]UPDATE[/url] as soon as possible. Besides, the script should work on PDA as well, I have done limited tests so there may be leftover issues. [/size][/color] [size=18][color=#0ca678]Future plan:[/color] [/size]1. On PDA, due to the limitation of APP implementation, now I only provide with direct access to password list, which limits the precision of results. I did some search for work solver API which can help mobile platform without taking much space or time to load, but found none. If you have any clues about the API, please contact with me. 2. For now, users may focus on the first candidates provided by script. However, this way does not promise the correctness of passwords. In the following version, the letter which shows up more frequently will be highlighted. And the candidates containing the highlighted letter will also be moved to front of queue. [color=blue][size=24]1.1 version release[/size][/color] This version has fixed some severe bugs that may harm experience 1. Now the script will be correctly loaded when you enter the page from crime main entry, no need to refresh anymore 2. The script will correctly work on encrypted password 3. The script will match correct target after finishing a cracking 4. The script will not prevent users from operating Rig components 5. Add 10m work list to options(it will be more accurate, but take much more network performance. You need to know a 10m worklist may take up 90M space!) 6. Support automatic generation of password database list, now you customize your own database and the options will be updated.(In the previous version this feature actually does not work) I would recommend you upgrade to the new version ASAP And if you meet any issues about this version, please contact with me to report it, thanks :) [color=blue][size=24]1.0.4 version release[/size][/color] After the refactoring, now the script will support mobile platform! However, there are still issues in it, take care about the following issues: [color=red] 1. Copy and paste the script into PDA 2. Open crime page, enter cracking link, you would need to refresh the page for one or two times to make it correctly load styles 3. By default, the dictionary on mobile platform is set to 100k, which is small enough to load quickly and has potential to be cached 4. Now you don't need to modify script any more, just choose the dictionary you want to use by clicking the select component: [center][img width=360]https://media.discordapp.net/attachments/822890599669563446/1188152179467493417/Screenshot_20231224_001023_com.manuito.tornpda_ed.jpg[/img][/center] [/color] Besides, the script provide with an experimental feature that: [b][color=#f76707][size=16]* when you guess an incorrect option, it will except the word out of candidates * the exception list will be refreshed if you reload the page[/size][/color][/b] I also make use of network injection instead of mutationobserver to capture the page changing more accurate The new version may also introduce some unexpected issues, welcome to report and help me improve the script, thanks! ===================== Since the new crime has been released, as ched said: [quote]Online infrastructure in Torn mainly uses a weaker encryption method known as ICE (Individual Character Encryption), where each character in a password is encrypted separately. Although this might seem more secure, it actually allows the password's length to be known and makes each character vulnerable to brute-force attacks. [/quote][color=#95ccff][size=24]This script is a beta version, which starts by simple idea: we can utilize open source weak password database to guess cracking result[/size][/color] Here is the example: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1188163714382299298/cracking_example.jpg[/img] [/center] [color=orange][size=24]Usage[/size][/color] 1. [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper][size=18]Install Link[/size][/url] 2. I would recommend you to brute force [b][size=18]at least half of total words[/size][/b] and then take the results from the script as reference [color=#1c7cd6][size=24]Customization[/size][/color] For now, I am using the password dictionary from [url=https://github.com/ignis-sec/Pwdb-Public/blob/master/wordlists/ignis-1M.txt]Pwdb-Public[/url], which is a list containing 1m weak passwords. I also provide you with several alternative: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1187395707582304387/customization.jpg[/img][/center] [s]You can simply open the script, change the [b]CRACKER_SEL[/b] to the key of dictionary you want to use, for example, 1m_alter or 10k.[/s] You just need to choose the dictionary you need in the page, the script will load it directly Note that, a larger dictionary may provide you with more accurate results along with higher performance cost, while a smaller dictionary may be inaccurate. Besides, I do not have time to test more password list, if you have better choices, welcome to inform me about that. [color=red][size=24]Known Issue[/size][/color] [s]1. If you have any ideas about migrating the script to mobile platform like PDA or kiwi browsers, welcome to tell me your ideas. I'm not good at frontend design and don't find a good way to display it in mobile. 2. The script only gives you prompts about possible results, but does not promise the correcteness.[/s] 1. On PDA, the script need the page to be refreshed for several times before it could work, I need to investigate the source of the problem and find some way to fix it 2. On PDA, a large dictionary will not be cached due to the limitation of localStorage. Besides, the persistence of small dictionary may also have issues(but since the dictionary can be as small to less than 1Mb, I think it will not have severe problems) 3. I do not test the script on Alook browser and not sure about whether it could work [color=green][size=24]Acknowledgement[/size][/color] [b]Thanks to [b][url=https://www.torn.com/profiles.php?XID=2893026]contr4l_[2893026][/url][/b], a lots of ideas of the script comes from my friend :D [/b]Thanks to helpful suggestions from [b][url=https://www.torn.com/profiles.php?XID=2190604]Kwack [2190604][/url] and [b][url=https://www.torn.com/profiles.php?XID=2636589]BigManBilly [2636589][/url][/b][/b]

    Winguem [2862329]

    Technically it is totally working on Kiwi/Yandex browsers on mobile, just need to open page in desktop mode and it just works.
    Yep, but I think the display way is not satisfactory.
    I may consider about display information in the above of page in mobile view.
    • Ahab [1735214]
    • Role: Civilian
    • Level: 100
    • Posts: 5,749
    • Karma: 11,059
    • Last Action: 7 minutes
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 07:24:13 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    nodelore [2786679]

    I'm not sure about what is the meaning of the off to the side covering chat, if there is detailed description or any illustration it would be helpful. Thanks

    Not like that

    But under the relevant cracking line
    • Freshmentality [2954019]
    • Role: Civilian
    • Level: 51
    • Posts: 928
    • Karma: 373
    • Last Action: 2 years
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 19:50:32 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link
    Amazing job, could you maybe collect data from players about their results and after the database is big enough, use that passwords to check instead of a public database? I'm sure cracking has limited passwords per crime, unless they also use a public database like yours :P
    • Pistachio [1595823]
    • Role: Civilian
    • Level: 100
    • Posts: 1,043
    • Karma: 1,022
    • Last Action: 1 hour
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 21:01:49 - 22/12/23 (2 years ago)
    Post link copied to clipboard Copy post link

    nodelore [2786679]

    [color=blue][size=24]1.2 version release[/size][/color] This version solves the issue caused by [url=https://www.torn.com/forums.php#/p=threads&f=1&t=16381254&b=0&a=0]Patch #324 [/url]Before, the script watches the location hash to update crime page, and since #324 update, TORN uses history.pushState to update location url, making the script unavailable in some cases(It can still work if you go directly into the crack page and refresh) This version solves several leftover issues, including the latest on mentioned above: 1. Intercept history.pushState action to update crime page correctly 2. Fix duplicated index which hinders the display of crime options. (Before, if you accumulate a lot of crack crime options, some of them will not have result panel. And now this is fixed.) 3. Remove leftover candidates when there are actual no results.(Before, after you brute force a password, if there are no results, the previous candidates will mislead player.) 4. Remove useless expire time which does not actually work. 5. Switch letter in candidates to upper form to be unified with provided ones. [color=#d6336c][size=18]Since the Patch has severe effect on previous version of script, I recommend you to [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper]UPDATE[/url] as soon as possible. Besides, the script should work on PDA as well, I have done limited tests so there may be leftover issues. [/size][/color] [size=18][color=#0ca678]Future plan:[/color] [/size]1. On PDA, due to the limitation of APP implementation, now I only provide with direct access to password list, which limits the precision of results. I did some search for work solver API which can help mobile platform without taking much space or time to load, but found none. If you have any clues about the API, please contact with me. 2. For now, users may focus on the first candidates provided by script. However, this way does not promise the correctness of passwords. In the following version, the letter which shows up more frequently will be highlighted. And the candidates containing the highlighted letter will also be moved to front of queue. [color=blue][size=24]1.1 version release[/size][/color] This version has fixed some severe bugs that may harm experience 1. Now the script will be correctly loaded when you enter the page from crime main entry, no need to refresh anymore 2. The script will correctly work on encrypted password 3. The script will match correct target after finishing a cracking 4. The script will not prevent users from operating Rig components 5. Add 10m work list to options(it will be more accurate, but take much more network performance. You need to know a 10m worklist may take up 90M space!) 6. Support automatic generation of password database list, now you customize your own database and the options will be updated.(In the previous version this feature actually does not work) I would recommend you upgrade to the new version ASAP And if you meet any issues about this version, please contact with me to report it, thanks :) [color=blue][size=24]1.0.4 version release[/size][/color] After the refactoring, now the script will support mobile platform! However, there are still issues in it, take care about the following issues: [color=red] 1. Copy and paste the script into PDA 2. Open crime page, enter cracking link, you would need to refresh the page for one or two times to make it correctly load styles 3. By default, the dictionary on mobile platform is set to 100k, which is small enough to load quickly and has potential to be cached 4. Now you don't need to modify script any more, just choose the dictionary you want to use by clicking the select component: [center][img width=360]https://media.discordapp.net/attachments/822890599669563446/1188152179467493417/Screenshot_20231224_001023_com.manuito.tornpda_ed.jpg[/img][/center] [/color] Besides, the script provide with an experimental feature that: [b][color=#f76707][size=16]* when you guess an incorrect option, it will except the word out of candidates * the exception list will be refreshed if you reload the page[/size][/color][/b] I also make use of network injection instead of mutationobserver to capture the page changing more accurate The new version may also introduce some unexpected issues, welcome to report and help me improve the script, thanks! ===================== Since the new crime has been released, as ched said: [quote]Online infrastructure in Torn mainly uses a weaker encryption method known as ICE (Individual Character Encryption), where each character in a password is encrypted separately. Although this might seem more secure, it actually allows the password's length to be known and makes each character vulnerable to brute-force attacks. [/quote][color=#95ccff][size=24]This script is a beta version, which starts by simple idea: we can utilize open source weak password database to guess cracking result[/size][/color] Here is the example: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1188163714382299298/cracking_example.jpg[/img] [/center] [color=orange][size=24]Usage[/size][/color] 1. [url=https://greasyfork.org/en/scripts/482828-torn-crime-crack-helper][size=18]Install Link[/size][/url] 2. I would recommend you to brute force [b][size=18]at least half of total words[/size][/b] and then take the results from the script as reference [color=#1c7cd6][size=24]Customization[/size][/color] For now, I am using the password dictionary from [url=https://github.com/ignis-sec/Pwdb-Public/blob/master/wordlists/ignis-1M.txt]Pwdb-Public[/url], which is a list containing 1m weak passwords. I also provide you with several alternative: [center][img width=600]https://media.discordapp.net/attachments/822890599669563446/1187395707582304387/customization.jpg[/img][/center] [s]You can simply open the script, change the [b]CRACKER_SEL[/b] to the key of dictionary you want to use, for example, 1m_alter or 10k.[/s] You just need to choose the dictionary you need in the page, the script will load it directly Note that, a larger dictionary may provide you with more accurate results along with higher performance cost, while a smaller dictionary may be inaccurate. Besides, I do not have time to test more password list, if you have better choices, welcome to inform me about that. [color=red][size=24]Known Issue[/size][/color] [s]1. If you have any ideas about migrating the script to mobile platform like PDA or kiwi browsers, welcome to tell me your ideas. I'm not good at frontend design and don't find a good way to display it in mobile. 2. The script only gives you prompts about possible results, but does not promise the correcteness.[/s] 1. On PDA, the script need the page to be refreshed for several times before it could work, I need to investigate the source of the problem and find some way to fix it 2. On PDA, a large dictionary will not be cached due to the limitation of localStorage. Besides, the persistence of small dictionary may also have issues(but since the dictionary can be as small to less than 1Mb, I think it will not have severe problems) 3. I do not test the script on Alook browser and not sure about whether it could work [color=green][size=24]Acknowledgement[/size][/color] [b]Thanks to [b][url=https://www.torn.com/profiles.php?XID=2893026]contr4l_[2893026][/url][/b], a lots of ideas of the script comes from my friend :D [/b]Thanks to helpful suggestions from [b][url=https://www.torn.com/profiles.php?XID=2190604]Kwack [2190604][/url] and [b][url=https://www.torn.com/profiles.php?XID=2636589]BigManBilly [2636589][/url][/b][/b]

    Winguem [2862329]

    Technically it is totally working on Kiwi/Yandex browsers on mobile, just need to open page in desktop mode and it just works.
    My desktop mode doesn't work on torn :(
Reply
Thread Title: