PDA

View Full Version : Passwords and Haxx0r5



Yates
August 12th, 2003, 01:30 PM
Thanks to the hard-working and industrious hacker community, the company where I serve my internship had a free holiday today that hopefully won't cost us all our jobs.

How did such a nefarious denizen of the digital underground infiltrate our most vital server?

Well, in classic "the Boss" fashion, the Boss changed the system administrator password to "password."


This post serves as a warning to everyone out there about passwords . I know most of you have heard this a million times, but KEEP YOUR PASSWORDS HARD TO GUESS! All a hacker needs is an opportunity like:

Boss: Oh... the system admin is on vacation. I'll just change his password to "password." It will only until he comes back. No big deal.

REMEMBER: NEVER USE THE FOLLOWING PASSWORDS

-password
-admin
-user name (which is the user name associated with the pass)
-"" (null string, just press return. You think this is clever, but trust me, you're not the only one who's come up with this)


Other passwords to stay away from includes personal information a hacker can easily find out about. For example, if your name is Drew Yates and your birthday is 7/23/1984, then don't make your password yates72384

NOTE:: that's not my password, but I know someone will try anyways! :chinaman: So in advanced: it wont work!



:::::::THIS HAS BEEN A COMMUNITY SERVICE ANNOUNCEMENT::::::
:::::WE NOW RETURN TO YOUR REGULARLY SCHEDULED PROGRAM::::

Yates
August 12th, 2003, 01:40 PM
PS:: If you're AFRAID to answer because somebody may crack your password, that is fair warning to you that your password is NO GOOD and should be CHANGED.

Jubba
August 12th, 2003, 01:43 PM
yea some people are stupid. I think there was a poll before about the most popular passwords and they were something like:

password, god, sex, power

my passwords are not anything like that, just random letters and numbers...

Jubba
August 12th, 2003, 01:43 PM
I fixed it for you. ;)

reverendflash
August 12th, 2003, 01:58 PM
I use a variance of letters and numbers. They are always the same letters and/or numbers, but are arranged in different sequences.

a friend used to have Joe1969 as his pswd. By the time he had been in the business for a few years, half of SF knew his pswd, and abused it terribly...

it was actually funny.

Revhttp://www.aulman.com/rev.gif

Yates
August 12th, 2003, 02:01 PM
Thanks Jubba for the fix :thumb:

kirupa
August 12th, 2003, 02:20 PM
My password is just a random combination of letters and numbers. The problem is, no matter how sophisticated your password, anybody who is interested in finding it will get at it. Maybe the regular users or casual hackers can get by, but the hackers who are serious can get pretty much anything from you :)

Yates
August 12th, 2003, 06:41 PM
Perhaps, but the least you can do is not make it easy for them!

Soul
August 12th, 2003, 06:51 PM
Random numbers, that I've memorised :bad:

RussianBeer
August 12th, 2003, 07:12 PM
My password is very very simple.. or else I would forget it..!
:beam:

Yo, soul whats up with the fruity colors?

Soul
August 12th, 2003, 08:37 PM
I had a temporary sex change

- Soulette http://www.awhiteflame.com/soulgirl.gif

senocular
August 12th, 2003, 08:57 PM
:!: you just listed all the passwords I use!


:quickly changes kirupa log-in pass:

fester8542
August 14th, 2003, 03:32 PM
I keep different passwords for different uses.

I have one for sites that I dont transmit any sensitive information (I.E. Kirupa)

And then I have the other passwords for bank accts/etc that I change every six months or so.

grandsp5
August 16th, 2003, 01:38 AM
I have different passwords for everything and they are all random. One for logon, one for email, one for aim, one for kirupa, on for geocities, etc. How i remember, them I don't know.

davetamzin
August 23rd, 2003, 08:23 PM
Take a look here for some interesting myths about passwords and security.

http://www.securityfocus.com/infocus/1554

after reading this I tried an experiment with lopht,

6 digit password with characters that can't be typed on the keyboard, it went in 58 mins.

9 digit mixed case and numeric bit the dust in 3 hrs 27 mins

"once more unto the breech dear friends" - 38 digits, very easy to remember, still hasn't gone after 6 days...

something to consider when choosing your next password?

Yates
August 23rd, 2003, 09:50 PM
Hmmmm... yes....

andr.in
August 24th, 2003, 02:13 AM
I have a few compound-words that use everywhere but I always throw dots, numbers and stuff somewhere in there so it won't be easily crackable!

Yates
August 24th, 2003, 02:16 AM
huh, I guess the movie "Hackers" is wrong, people just don't use the password: "GOD" like they used to. I guess hackers also stopped flying around in digital landscapes when they surfed the Internet, too... oh well.

Voetsjoeba
August 24th, 2003, 02:26 AM
I use a word from another language. Like 'puppetmastery' in Swahili or something :P That's not what I use, it's just an example. Before, I used funny names of African villages :P

Jasninder
August 24th, 2003, 03:28 PM
I have bin an ex-member of phrozen crew and my password style is very different and not in the list=)

mlk
August 24th, 2003, 06:20 PM
phrozen-crew ?

my pass for sensible things (such as my e-mail account) is always the maximum number of letters possible and keep it sentences as much as possible, sometimes a mixed french english sentence with numbers in it like a phone number....

but whoodda f*ck would wanna hack my pass and whatfor ?

Jasninder
September 5th, 2003, 06:40 AM
check this out

http://www.wikipedia.org/wiki/Phrozen_Crew

APDesign
September 16th, 2003, 05:58 AM
When I made my password I used the keypad to create a 9 digit random number that felt right to type in, I didn't even memorize the numbers, I just went by hand movement (I play guitar so my hands have good muscle memory) then I just tacked on two letters to the front, so it is something like this (but obviously not this exactly)

cv824752473

Think that would be horribly easy to crack? I always used to use stuff like this ittkdcin1 (I think that Kirupa dot com is number 1)

ave
September 17th, 2003, 03:12 PM
davetamzin

Take a look here for some interesting myths about passwords and security.http://www.securityfocus.com/infocus/1554after reading this I tried an experiment with lopht, 6 digit password with characters that can't be typed on the keyboard, it went in 58 mins.9 digit mixed case and numeric bit the dust in 3 hrs 27 mins"once more unto the breech dear friends" - 38 digits, very easy to remember, still hasn't gone after 6 days...something to consider when choosing your next password?

would be good if you hadnt just printed it here :beam: hehe

never mind hey :trout:

[m]
September 17th, 2003, 04:13 PM
I use a standard easy-to-type password for not important things like forums. (sorry kirupa) The password i use for things that really needs a password is much harder to crack, but not as hard to type. It does use numbers, uppercase, lowercase and symbols and is 6+ characters long.


Yup.

Yates
September 18th, 2003, 12:03 AM
Why was this moved to Random?