Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-28-2013, 01:50 PM   #1
Nasty
Confirmed User
 
Nasty's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: Sunny Fucking California
Posts: 1,575
Hackers crack 16-character passwords in less than an HOUR

This is pretty disturbing

During an experiment for Ars Technica hackers managed to crack 90% of 16,449 hashed passwords. Six passwords were cracked each minute including 16-character versions such as 'qeadzcwrsfxv1331'

A 25-computer cluster that can cracks passwords by making 350 billion guesses per second. It was unveiled in December by Jeremi Gosney, the founder and CEO of Stricture Consulting Group. It can try every possible Windows passcode in the typical enterprise in less than six hours to get plain-text passwords from lists of hashed passwords.

The article
http://www.dailymail.co.uk/sciencete...ords-hour.html
__________________

“Ours is a world of nuclear giants and ethical infants. We know more about war than we know about peace, more about killing than we know about living. If we continue to develop our technology without wisdom or prudence, our servant may prove to be our executioner.” ― Omar Bradley (1948)
Nasty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:52 PM   #2
nexcom28
So Fucking Banned
 
Join Date: Jan 2005
Posts: 3,716
350 billion guesses per second...
nexcom28 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:54 PM   #3
Intrinsic
Confirmed User
 
Intrinsic's Avatar
 
Industry Role:
Join Date: Jun 2008
Posts: 1,589
I heard the safest passwords were four word combos with dashes (??) and would take forever to crack

example: take-fish-dirt-reed
example: sdfk-fjsd-weij-akji
Intrinsic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:56 PM   #4
shake
frc
 
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,663
Wow that's a lot of GPU power.
__________________
Crazy fast VPS for $10 a month. Try with $20 free credit
shake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:57 PM   #5
_Richard_
Too lazy to set a custom title
 
_Richard_'s Avatar
 
Industry Role:
Join Date: Oct 2006
Location: Vancouver
Posts: 30,985
damn they're coming along nicely
_Richard_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:57 PM   #6
ajrocks
Confirmed User
 
ajrocks's Avatar
 
Join Date: Nov 2004
Location: On Uranus
Posts: 4,526
most systems have brute force prevention in place to prevent this sort of stuff. But if they came in using a bot net you would be in trouble until you caught it.
__________________
SEO Strategy - Digital Strategy - Cannabis Lead Generation

Skype aj.durden1
ajrocks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:57 PM   #7
shake
frc
 
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,663
Quote:
Originally Posted by Intrinsic View Post
I heard the safest passwords were four word combos with dashes (??) and would take forever to crack

example: take-fish-dirt-reed
example: sdfk-fjsd-weij-akji
Pass phrases were all the rage for a bit, but I think even those would be crackable, unless they are very long. Pretty soon we'll have to use a USB drive with a megabyte size password or something.
__________________
Crazy fast VPS for $10 a month. Try with $20 free credit
shake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:59 PM   #8
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
but this will work to unpack and unprotect files, to access your NET accounts, he can't do it via bruteforce, server and program will just take it down...
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 01:59 PM   #9
nexcom28
So Fucking Banned
 
Join Date: Jan 2005
Posts: 3,716
Quote:
Originally Posted by Intrinsic View Post
I heard the safest passwords were four word combos with dashes (??) and would take forever to crack

example: take-fish-dirt-reed
example: sdfk-fjsd-weij-akji
I doubt that would take much working out.

1. You have x4 dictionary words
2. Just putting 4 dashes in aint gonna fool no-one.

I think site owners really need to make their sites secure against multiple login attempts rather than getting us to remember 5%6Yy*5$fdd1$8>KKhJo)o or some such shit.
nexcom28 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 02:30 PM   #10
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by nexcom28 View Post
I doubt that would take much working out.

1. You have x4 dictionary words
2. Just putting 4 dashes in aint gonna fool no-one.

I think site owners really need to make their sites secure against multiple login attempts rather than getting us to remember 5%6Yy*5$fdd1$8>KKhJo)o or some such shit.
Actualy it's better to have password like "iliketurtlesandsausegeswithcream12345"which is long enough yet still easy to remember.

Beside as longest you have some sort of bruteforce protection things like this dont mean much.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 02:45 PM   #11
edgeprod
Permanently Gone
 
Industry Role:
Join Date: Mar 2004
Posts: 10,019
edgeprod is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 03:15 PM   #12
Lichen
Tube Master
 
Lichen's Avatar
 
Industry Role:
Join Date: May 2004
Posts: 1,640
Quote:
Originally Posted by Intrinsic View Post
I heard the safest passwords were four word combos with dashes (??) and would take forever to crack

example: take-fish-dirt-reed
example: sdfk-fjsd-weij-akji

Include numbers, special characters and uppercase/lowercase. Like this:

71#Testpassword
Lichen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 03:22 PM   #13
spiederman
Confirmed User
 
spiederman's Avatar
 
Industry Role:
Join Date: Nov 2012
Posts: 1,216
surrentlysober is pretty safe with Icunta4rdapassw0rd
spiederman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 03:30 PM   #14
grumpy
Too lazy to set a custom title
 
grumpy's Avatar
 
Join Date: Jan 2002
Location: Holland
Posts: 9,870
great server if it allows you 3.5 billion tries a second.
__________________
Don't let greediness blur your vision | You gotta let some shit slide
icq - 441-456-888
grumpy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 03:35 PM   #15
nexcom28
So Fucking Banned
 
Join Date: Jan 2005
Posts: 3,716
Quote:
Originally Posted by grumpy View Post
great server if it allows you 3.5 billion tries a second.
I could do with it for my sites
nexcom28 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 03:39 PM   #16
_Richard_
Too lazy to set a custom title
 
_Richard_'s Avatar
 
Industry Role:
Join Date: Oct 2006
Location: Vancouver
Posts: 30,985
Quote:
Originally Posted by edgeprod View Post
_Richard_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 03:44 PM   #17
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,035
Quote:
The example, Ars Technica use is: hashing the password 'arstechnica' produced the hash c915e95033e8c69ada58eb784a98b2ed

Read more: http://www.dailymail.co.uk/sciencete...#ixzz2Ud94lCOi
md5 hashing... this problem is not new
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 04:01 PM   #18
edgeprod
Permanently Gone
 
Industry Role:
Join Date: Mar 2004
Posts: 10,019
Quote:
Originally Posted by grumpy View Post
great server if it allows you 3.5 billion tries a second.
Likely, the crackers had the hashes available, and were cracking against the hashes, versus against a live server.
edgeprod is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 05:05 PM   #19
Grapesoda
So Fucking Banned
 
Industry Role:
Join Date: Jul 2003
Location: Montana
Posts: 46,238
Quote:
Originally Posted by nexcom28 View Post
I doubt that would take much working out.

1. You have x4 dictionary words
2. Just putting 4 dashes in aint gonna fool no-one.

I think site owners really need to make their sites secure against multiple login attempts rather than getting us to remember 5%6Yy*5$fdd1$8>KKhJo)o or some such shit.
I use passwords like this: `#LG\`yf8tyLkx5([Rd9RA ....the only issue is some sites won't allow special characters...

Last edited by Grapesoda; 05-28-2013 at 05:06 PM..
Grapesoda is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 08:14 PM   #20
The Heron
Confirmed User
 
Industry Role:
Join Date: Apr 2001
Location: Michigan
Posts: 4,487
I don't use a password, just leave it blank they can guess all they want they'll never solve it!!
The Heron is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 08:49 PM   #21
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Did any of you guys actually read the article? correcthorsebatterystaple is a little harder to crack, but not impossible. They use custom dictionaries that brute force multiple WORDS as well as multiple characters.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 10:43 PM   #22
Basileus
Confirmed User
 
Industry Role:
Join Date: Sep 2003
Location: Planet Earth
Posts: 56
Because only retards use md5. If it was SHA512 we'd never see this article ;)
Basileus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-28-2013, 11:34 PM   #23
Chosen
 
Industry Role:
Join Date: Aug 2001
Posts: 63,151
Quote:
Originally Posted by spiederman View Post
surrentlysober is pretty safe with Icunta4rdapassw0rd
Chosen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 01:21 AM   #24
pimpmaster9000
Too lazy to set a custom title
 
pimpmaster9000's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 26,732
if your system is open to brute force then you pretty much deserve what happens...
pimpmaster9000 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 01:34 AM   #25
Markul
Likes Pie
 
Markul's Avatar
 
Industry Role:
Join Date: Dec 2007
Location: The land that liberated porn
Posts: 12,401
Quote:
Originally Posted by edgeprod View Post
That is awesome
Markul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 02:58 AM   #26
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,381
Quote:
Originally Posted by ajrocks View Post
most systems have brute force prevention in place to prevent this sort of stuff. But if they came in using a bot net you would be in trouble until you caught it.
Please read carefully. Whey did that on password hashes.
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 07:32 AM   #27
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
Quote:
Originally Posted by Basileus View Post
Because only retards use md5. If it was SHA512 we'd never see this article ;)
QFT
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 10:51 AM   #28
edgeprod
Permanently Gone
 
Industry Role:
Join Date: Mar 2004
Posts: 10,019
Quote:
Originally Posted by rowan View Post
Did any of you guys actually read the article? correcthorsebatterystaple is a little harder to crack, but not impossible. They use custom dictionaries that brute force multiple WORDS as well as multiple characters.
Against a hash .. which is an unlikely scenario in most cases. Against a weak remote web service, at 1,000/hr, I'm comfortable with 550 years of security versus 3 days.
edgeprod is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 11:35 AM   #29
KillerK
Confirmed User
 
Join Date: May 2008
Posts: 3,406
I've started using password as my password, I figure it's so common nobody would code a cracker to waste testing it.
KillerK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 11:42 AM   #30
brassmonkey
Pay It Forward
 
brassmonkey's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 77,053
ok thanx 4 the stress
__________________
TRUMP 2025 KEKAW!!! - The Laken Riley Act Is Law!
DACA ENDED - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com
brassmonkey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 12:45 PM   #31
x-rate
Confirmed User
 
Industry Role:
Join Date: Jun 2008
Location: Montreal
Posts: 725
I use 'wrong' as password so when I don't type it properly site tell me: your password is wrong
__________________
Have quality traffic? Make money with Crakrevenue
Email: misterxmtl @ hotmail.com
Skype: misterxmtl
x-rate is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 02:45 PM   #32
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Quote:
Originally Posted by x-rate View Post
I use 'wrong' as password so when I don't type it properly site tell me: your password is wrong
You should change it to incorrect, I hear it's the new thing
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 03:07 PM   #33
RyuLion
 
RyuLion's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,185
Quote:
Originally Posted by x-rate View Post
I use 'wrong' as password so when I don't type it properly site tell me: your password is wrong
Quote:
Originally Posted by Grapesoda View Post
I use passwords like this: `#LG\`yf8tyLkx5([Rd9RA ....the only issue is some sites won't allow special characters...
__________________

Adult Biz Consultant A tech head since 1995
RyuLion is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 04:00 PM   #34
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Quote:
Originally Posted by ajrocks View Post
most systems have brute force prevention in place to prevent this sort of stuff. But if they came in using a bot net you would be in trouble until you caught it.
You did not really say this...

Anyway, md5 is so 1990, not even sure who hashes with md5 anymore.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 05:25 PM   #35
blackmonsters
Making PHP work
 
blackmonsters's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: 🌎🌅🌈🌇
Posts: 20,272
Just buy a cheap server. A billion request will crash the motherfucker.

__________________
Make Money with Porn
blackmonsters is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.