Showing posts with label Hacking Passwords. Show all posts
Showing posts with label Hacking Passwords. Show all posts

Monday, 14 September 2015

Users Ashley Madison Had Often Name As Password


Users of the Ashley Madison website often used their username and password, so researchers have discovered. The group of researchers called Cynosure Prime showed last week that by some programming errors crack the password hashes of Ashley Madison are simple. At the hack of the cheaters website approximately 36 million password hashes were stolen.

Hashes to ensure that the user passwords are not immediately visible to an attacker in case the website is hacked. Ashley Madison used before a strong hashing algorithm, but by various programming errors hashes prove yet easy to crack. The researchers have cracked 11.7 million password hashes.

It shows that mainly weak and insecure passwords were used. So there were three million passwords of six characters and there were slightly less than 3 million, which consisted of eight males kara. The shortest password was cracked one character long. Nearly 10 million passwords only consisted of small letters or lowercase letters and numbers.

User Name

The researchers were also curious how many users are using their username and password. A total of 630 000 passwords were found that matched the user name. The investigators noted that the actual number is higher as possible, since there are obvious only obvious mutations were used. If there was more combinations of uppercase and lowercase letters sought was the true number is likely higher. The researchers argue that these passwords could be cracked too easily without programming errors found.

Striking Passwords

Instead of publishing a list of the Top 10 most common passwords, the researchers decided to create a collection of distinctive passwords. It is about passwords as allthegoodpasswordshavegone ',' youwillneverfindout ',' everynameitriedwastaken ',' goodguydoingthewrongthing ',' thisisagoodpassword 'and' correct horse battery staple ", known from the xkcd strip.

Thursday, 10 September 2015

Researchers Crack 11 Million Passwords Ashley Madison


Researchers have managed to crack more than 11 million passwords of Ashley Madison users, as they have announced today. The group of researchers called himself the cynosure Prime and examined the data that was stolen by the cheaters website. Attackers managed to steal gigabytes of data at Ashley Madison, including hashed passwords of users.

It involves a total of 36 million password hashes. Ashley Madison had the passwords are not stored in plain text, but in hashed form. This makes them not directly readable, but they can be cracked. For hashing the password had Ashley Madison the bcrypt algorithm used, and there was also a "salt-made 'use. This makes it much more difficult to crack password hashes. In a weaker algorithm, such as MD5, it is possible to try millions of password combinations per second. In the case of the gesalte bcrypt hashes came another researcher with his computer not go beyond 156 hashes per second. This investigator knew in five days 4000 passwords to crack.

It was therefore argued that the cracking of all Ashley Madison password hashes would last for centuries. That now seems not to be so. The researchers from Cynosure Prime investigated namely the second amount of data that was recently put online. In it they found information that helps them with the bcrypt hashed passwords could crack much faster. "Instead of cracking the slow bcrypt hashes, which is currently a hot topic, we decided to choose a more efficient approach and attack the MD5 tokens," the researchers said in their explanation.

The cheaters website appears to have used for reasons still unknown MD5 tokens. These tokens can be cracked much simpler than the bcrypt hashes. The information from the cracked tokens could then be used to crack the hashes bcrypt, she discovered. Since the researchers two weeks ago with their research, they began now more than 11.2 million bcrypt hashes cracked. In total there were in the stolen data over 15 million tokens.

Friday, 26 June 2015

Man Mails More Than 97,000 People Their Password


With great regularity on websites like Pastebin stolen passwords and other credentials posted. The reason for a programmer named Julian alias' aTechDad 'to collect all kinds of stolen email addresses and passwords via a script and then warn the user.

For example, some Internet users use Google Alerts or other services to warn if their data appear anywhere on the internet.Most Internet users may not know such services exist and users who know there is much that their data would rather not leave you in this kind of party, said the programmer. He therefore decided to create a script, which he in a three-day period on Pastebin 97 931 combinations of email addresses and passwords collected.

Last month, he decided to warn users. Through a simple e-mail, he said that the account of the user probably was compromised, which he also co-stared the password. The nearly 98,000 sent emails yielded only nine thanked by. 100 e-mails could not be delivered, while 41 people sent back a request to be unsubscribed. Yet Julian considers the experiment a success. At this time he started a second experiment, in which he has already collected 300,000 passwords. "I might do it again," said the programmer.

Friday, 15 May 2015

Hacker Makes 3D Printed Robot Creating Combination Locks



The famous hacker Samy Kamkar has developed a robot that costs less than $ 100, partly to make is via a 3D printer and combination locks of the Master Lock brand in eight attempts to crack. "The CCCC-Combo Breaker! "as Kamkar his robot calls is an Arduino-based lock cracker. In addition to the Arduino, which is a small minicomputer, the device consists of several parts that cost less than $ 100 together. Several of the components can be printed using a 3D printer.


According Kamkar makes the Combo Breaker using a new technique he discovered cracking combination locks. Last month, the hacker already see how he had managed to reduce the maximum number of combinations of a combination lock from 64,000 to 8. A technique that both old and new Master Lock locks work, let him in this video show. The technique he has now added an Arduino-based robot. Both the 3D models as the source code for the open source software Kamkar has made ​​and via GitHub download.

Tuesday, 10 February 2015

Researcher Publishes File With 10 Million Passwords


A researcher has published a file of 10 million passwords and usernames in order to improve the security of passwords. According to researcher and security consultant Mark Burnett gives his "carefully selected" dataset insight into user behavior.

Yet he hesitated to make the file public. Following the sentencing of Barrett Brown, the self-proclaimed spokesman for Anonymous. He received a sentence of 15 months because of the link to a file with stolen data. It was here that stolen data was already public. In his own case Burrnett fear not to be arrested. Indeed, he has no intention to commit fraud or facilitate unauthorized access to systems.

Therefore, he has removed as much as possible identifying information, including the domain of the e-mail addresses. In addition to the variety of data sets and the data will not be traced back to one company. Also keywords like company names removed, leading to the possible source of a data breach may indicate. The same applies to information that can be traced back to an individual. The now published passwords, which were collected over a period of 15 years, according to the researcher also mostly "dead passwords".

Yet he publishes them because this is a topic largely ignored and understanding password use can offer. Most researchers, however, would be afraid to publish passwords and usernames together because the two are an authentication feature together, making them a potential threat to be prosecuted. Furthermore Burnett has been download includes a disclaimer, which is necessary for it.