Go Back   Science Forums
View Single Post
Old 03-21-2009   #25 (permalink)
freeztar's Avatar
freeztar
M.C. Grillmeister



Location:
ATL, GA, USA
Latest blog entry:
 
freeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond repute
 



Not Ranked  0 score     
Re: Password Length And Complexity

Quote:
Originally Posted by alexander View Post
freezy, it could be arranged, you know, it would require written and signed permission from you, but a pen test is something rather fun to do, and i am sure not only myself, but some people i know would not mind performing one, if you are really serious about that...
Hmm...I'll get back to you on that. It might be fun to try.

Quote:
also, if you happen to post the format of your password, i can run a test on approximately how long it would take me to break that hash, lets agree on how you will post your password though.

format can be such:
a - alphas, meaning letters
n - numerals, meaning numbers
s - symbols, meaning special symbols
e - extended, meaning extended ascii (space or anything typed with alt+)

PM it to me if you dont feel safe with posting it here (pm is what i would do).

So for example, one of the passwords that was used prior to my involvement with IT at my company was of the form aaaaann. Took about 2 and a half hours to break the hash.
Most of my passwords take that form, aaaaaann. That only takes 2.5 hours?
What about a different orientation of the same chars, say, aaanaana?

Quote:
Just so you know, exactly how i am going to test the password strength.

I will take a clean vm, and set the admin and user passwords to 2 i generate of the form given to me. I will then grab the hash and run it through a couple of programs for breaking passwords (and decrypting hashes), nothing anyone who might want your password would not have access to... Log the time it took to to crack each account password with each software, average it out, give you back an average time...
I understand how you can run a program to list out all possible combinations of aaaaaann, but how does it apply them in the real world? In other words, say you are trying to figure out your forgotten password for your hotmail account. How would the program test each password with hotmail? Wouldn't this add a significant amount of time to the process? Wouldn't it lock the account after several false tries?


----------------
Hypography Science Forums Moderator
---
"There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan

"We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie
Reply With Quote
 
» Advertisement
» Current Poll
Who's the sexiest man alive? Johnny Depp or Robert Pattinson?
Johnny Depp - 30.00%
3 Votes
Robert Pattinson - 0%
0 Votes
Someone else (please specify) - 40.00%
4 Votes
I'm too macho to think a guy is sexy - 30.00%
3 Votes
Total Votes: 10
You may not vote on this poll.


All times are GMT -8. The time now is 11:37 AM.

Hypography?

Hypography [n.]: A combination of "hyperlink" and "bibliography" - ie, a list of links to electronic documents. Comparable to discography and bibliography, but not cartography.

We have been online since May 2000, and aim to be the best place to find and share science-related content of all kinds.

Share the love!

Please add more science to your life. Use our RSS feeds on your blog, your portal, or your favorite feedreader!


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright © 2000-2009 Hypography
Part of the Hypography - Science for Everyone Network