»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 07-23-2003, 12:17 AM   #1 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
MS - Easy to crack passwords?

http://news.com.com/2100-1009_3-5053063.html?tag=fd_top

I'm not posting this to discuss how to crack the passwords Passwords are a huge security risk

I'm posting as people do take these things seriously.
The EASIEST way into any system is BAD passwords by users. With different methodologies taking advantage of weaknesses in Windows encryption algorithim these passwords are even MORE important to keep DIFFICULT to crack.

Quote:
Microsoft has used two encoding schemes, also known as hashing functions, to encrypt passwords. The first, known as LANManager or LANMan, was used by Windows 3.1, 95, 98, Me and early NT systems to secure passwords that were used to connect to early Windows networks.

The LANMan scheme has several weaknesses, including converting all characters to uppercase, splitting passwords into 7-byte chunks, and not using an additional random element known as "salt." While the more recent NTHash fixes the first two weaknesses, it still does not use a random number to make the hashes more unique.

The result: The same password encoded on two Windows machines will always be the same. That means that a password cracker can create a large lookup table and break passwords on any Windows computer. Unix, Linux and the Mac OS X, however, add a 12-bit salt to the calculation, making any brute force attempt to break the encryption take 4,096 times longer or require 4,096 times more memory.

vass0922 is offline   Reply With Quote
Old 07-23-2003, 12:42 AM   #2 (permalink)
Registered User
 
OuTpaTienT's Avatar
 
Join Date: Oct 2001
Location: Bay Area, CA USA
Posts: 6,966
OuTpaTienT is on a distinguished road
Send a message via ICQ to OuTpaTienT
So what do you mean? Using "password" as your password is not a good idea?

Well damn. If I change one of my passwords then I gotta change them all, because all my passwords are "password".

What should I change them to? hmmmm. How about "password007"? Huh? Huh? Pretty good huh? I figure by the time they tried to hack their way into "password000" through "password006" they'll get tired of failing and just give up. They'll never even make it to "password007".

Now don't tell anybody.
OuTpaTienT is offline   Reply With Quote
Old 07-23-2003, 12:43 AM   #3 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
Hmm
Is that the 7 minute abs theory?

Better than 8 minute abs!
__________________
<< Insert exceedingly large and overly verbose message of how 1337 you are here including full specs of every vehicle you've ever driven and PC you've owned >>
vass0922 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 05:09 AM.