Results 1 to 16 of 16

Passwords - The problems

  1. #1
    Banned Spey's Avatar
    Join Date
    Dec 2008
    Location
    The heart of the Galaxy (Balcora)

    Passwords - The problems

    At the moment, people seem to be making obvious passwords, such as "password" or "1234". Please, do not use these passwords or combinations of these as they are very easy for a registered user to use a spambot and compromise a user account. A few instances of this can be found in a thread created by ami in one of the forums. It is currently closed. Here are some tips to use when creating a password, as well as the tips to avoid certain passwords. But first, let me explain some things people may not know.

    What is a password?

    A password is simply a combinations of letters, numbers and special characters (*, ^, _etc) that people use to log onto gaming sites and forums. In the olden days, passwords had no minimum length, which made it very easy for people to have their bank accounts hacked and money removed without your knowledge. Nowadays, password protection is getting stronger, where a minimum of 6 letters must appear in the password, but must contain a number or numbers, or for the more advanced, a couple of special characters.

    What are some rules for creating passwords?




    • On many registration websites, you may notice a bar to the left or right of the create password box. This a very useful indicator of your passwords strength.
    • For example, some websites require a user to create a password that is at least 6 characters long including at least one number
    • You are advised to write down the password you created and keep it in a safe place, and also a place where a robber cannot find it.
    • Do not use passwords that are easy to guess. For example, passwords should not, in any circumstances, be your birthday, the word "mum", "password" or "1234": these are first guesses for any hacker.
    • Use strong passwords, such as your Car Registration Number. You could even use your National Insurance number Pun-intended.
    • Making your passwords complicated is good. So instead of a straight forward word, take a word you know and mix it up with numbers and special characters.
    What are some tools I can use?

    Out there, people are registering on banking websites, forums, logging onto their favourite shopping site, etc. What you don't know is that these users are using extremely easy and guessable passwords. Many passwords are not even logged on encrypted websites. Here are some tools you can use:

    • Cain&Abel: Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols. The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort. It covers some security aspects/weakness present in protocol's standards, authentication methods and caching mechanisms; its main purpose is the simplified recovery of passwords and credentials from various sources, however it also ships some "non standard" utilities for Microsoft Windows users. Cain & Abel has been developed in the hope that it will be useful for network administrators, teachers, security consultants/professionals, forensic staff, security software vendors, professional penetration tester and everyone else that plans to use it for ethical reasons.
    Maybe you could suggest some others things to add to this post.
    Last edited by Spey; 27th Feb 09 at 9:44 AM. Reason: Uber's and Moe's request.

  2. #2
    Member Jake's Avatar
    Join Date
    Nov 2008
    Location
    Dorset UK
    A couple of strong, ready-made and easily recalled passwords are your Social Security number or its local equivalent and the registration number of your car, if you have one; I'd counsel against using these to protect stuff you use for work, where you might come up against social-engineering attacks, but for anything up to your Paypal account they're more than adequate.

  3. Gamers Lounge Senior Member Boardwars Senior Member  #3
    Moe~ money, moe~ problems Mokino's Avatar
    Join Date
    Oct 2007
    Location
    Canuckistan
    I like to use punctuation marks in passwords a lot. Mixing in one or more periods or other symbols in the middle of your password can make it a lot harder to guess.

    Odd capitalization also helps.

  4. Child's Play Donor Technical Help Senior Member General Discussions Senior Member Homeworld Senior Member Forum Subscriber  #4
    Gimme your lunch Moeney! Moe's Avatar
    Join Date
    Oct 2003
    Location
    #homeworld
    I'm moving this to The Workshop because frankly it doesn't meet the quality standards required for the tutorials subforum.

    A password is not just limited to games and online forums. The part about banks is just plain wrong, the minimum of six letters is completely arbitrary and misleading.

    "All websites require that enter a password at least 6 characters long and containing a number."
    That is both factually and grammatically incorrect. I could go on, but I'm sure you get the idea at this point.

    If someone wants to write a proper tutorial on how to create passwords and outline some of the problems with passwords, how passwords are commonly cracked (social engineering, brute-force attacks, cracking the password hash, XSS and so forth) and how to better defend against attacks, go right ahead. But the majority of "facts" in the first post are just plain wrong.

  5. #5
    Banned BmB's Avatar
    Join Date
    Apr 2004
    Location
    Denmark
    To be honest I am also pretty sure that if you are reading this thread you already know what a password is. Since most likely you are logged in, using your password.

  6. #6
    Banned Spey's Avatar
    Join Date
    Dec 2008
    Location
    The heart of the Galaxy (Balcora)
    @Moe: I've been on quite a few websites, and they ask for a minimum of 6 characters.

  7. #7
    Banned BmB's Avatar
    Join Date
    Apr 2004
    Location
    Denmark
    Some ask for a minimum of 8 while others go 9 while others again take 5. It's not a standard by any means.

  8. Technical Help Senior Member Modding Senior Member Homeworld Senior Member  #8
    www.relicnews.com ÜberJumper's Avatar
    Join Date
    Sep 1999
    Location
    South Surrey, BC Canada
    "All websites require that enter a password at least 6 characters long and containing a number."

    That's just wrong.

    "For example, some websites require a user to create a password that is at least 6 characters long including at least one number"

    Is better.
    Last edited by ÜberJumper; 26th Feb 09 at 4:50 PM.

  9. General Discussions Senior Member The Studio Senior Member Boardwars Senior Member  #9
    Beware of Zombified Terrorists Langy's Avatar
    Join Date
    Sep 2001
    Location
    Orlando, Florida
    Quite a few websites don't have any requirements for their passwords - they could be any numbers or letters or have any number of digits. Some websites even don't allow punctuation marks or other special characters (like @,%,^,<, etc).

    Also: Writing down your passwords isn't the best way to make them secure - instead, just memorize the bloody things.

  10. Child's Play Donor Technical Help Senior Member General Discussions Senior Member Homeworld Senior Member Forum Subscriber  #10
    Gimme your lunch Moeney! Moe's Avatar
    Join Date
    Oct 2003
    Location
    #homeworld
    Oh, and I would strongly advise against using your SSN as your password. That's just begging for trouble.

  11. #11
    Well, I would recommend LastPass ( https://lastpass.com/ ) for those looking for a good password manager. You still need to have a strong password for your log-in, but once that's out of the way you can generate long, random passwords and auto-fill and auto-log-in to sites. For example, the password I generated for this site is 32 characters long with a mix of numbers, letters, and special characters. Plus, it's multi-platform and works in both Firefox and Internet Explorer.

    When it comes to making passwords yourself, I like to substitute numbers and/or symbols for letters. For example, "apples" is not a very strong password, but "@ppl35" is.

  12. Gamers Lounge Senior Member Boardwars Senior Member  #12
    Moe~ money, moe~ problems Mokino's Avatar
    Join Date
    Oct 2007
    Location
    Canuckistan
    Quote Originally Posted by BmB
    Some ask for a minimum of 8 while others go 9 while others again take 5. It's not a standard by any means.
    SA's is now 12 characters, mixed case, with at least one number and one punctuation mark. Neither the number or punctuation can be at the beginning or end of the password either if they are the only one used.

    It's a pretty strict system but, given how much they're probably a target for hacking, understandable.

  13. #13
    magnet20: I went to a uni tutorial/lecture/thing the other day (just as a sample for what's to come at uni, i'm in my final year at school) on computer science, and we did a little talk on hacking & password cracking. In 30 seconds, the lecturer had created a program that would scan through network traffic for an encrypted password (in this example, it was a terminal logging onto a Windows server), and then decrypted it using a dictionary and all permutations of dictionary words, such as a=@, e=3, etc. The password (pR0t3cT-Me) was cracked within a second of it being recieved by the server. Dictionary words and permutations of, are in no way, secure.
    I guess day 1 DLC was too casual for EA, so let's start doing 8-month-early DLC! - Shuma
    Eagerly awaiting DoW3 with mod tools. You hear me Relic?!


  14. Child's Play Donor Technical Help Senior Member General Discussions Senior Member Homeworld Senior Member Forum Subscriber  #14
    Gimme your lunch Moeney! Moe's Avatar
    Join Date
    Oct 2003
    Location
    #homeworld
    Try downloading Cain&Able and have it listen in on your network traffic. The amount of passwords being sent as clear-text is staggering.

  15. #15
    Banned Spey's Avatar
    Join Date
    Dec 2008
    Location
    The heart of the Galaxy (Balcora)
    @Uber: Thanks, edited OP.
    @Moe: Will add tools section in OP. Thank you for that piece of info. Will remove part about using SSN.

  16. Child's Play Donor  #16
    Resident salvager mailpup's Avatar
    Join Date
    Dec 2002
    Location
    Los Angeles, CA
    FWIW, this forum is an example of one that doesn't require 6 characters in passwords.
    (\__/) This is bunny, taking over the world one
    (='.'=) signature at a time.
    (")_(")

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •