Tag Archives: Passwords

How strong is your password

http://www.passwordsafepro.com/images/secure_passwords.gifIf you invited me to try and crack your password, you know the one that you use over and over for like every web page you visit, how many guesses would it take before I got it?

Let’s see… here is my top 10 list. I can obtain most of this information much easier than you think, then I might just be able to get into your e-mail, computer, or online banking. After all, if I get into one I’ll probably get into all of them.

  1. Your partner, child, or pet’s name, possibly followed by a 0 or 1 (because they’re always making you use a number, aren’t they?)
  2. The last 4 digits of your social security number.
  3. 123 or 1234 or 123456.
  4. “password”
  5. Your city, or college, football team name.
  6. Date of birth – yours, your partner’s or your child’s.
  7. “god”
  8. “letmein”
  9. “money”
  10. “love”

Statistically speaking that should probably cover about 20% of you. But don’t worry. If I didn’t get it yet it will probably only take a few more minutes before I do…

Hackers, and I’m not talking about the ethical kind, have developed a whole range of tools to get at your personal data. And the main impediment standing between your information remaining safe, or leaking out, is the password you choose. (Ironically, the best protection people have is usually the one they take least seriously.)

One of the simplest ways to gain access to your information is through the use of a Brute Force Attack. This is accomplished when a hacker uses a specially written piece of software to attempt to log into a site using your credentials. Insecure.org has a list of the Top 10 FREE Password Crackers right here.

So, how would one use this process to actually breach your personal security? Simple. Follow my logic:

  • You probably use the same password for lots of stuff right?
  • Some sites you access such as your Bank or work VPN probably have pretty decent security, so I’m not going to attack them.
  • However, other sites like the Hallmark e-mail greeting cards site, an online forum you frequent, or an e-commerce site you’ve shopped at might not be as well prepared. So those are the ones I’d work on.
  • So, all we have to do now is unleash Brutus, wwwhack, or THC Hydra on their server with instructions to try say 10,000 (or 100,000 – whatever makes you happy) different usernames and passwords as fast as possible.
  • Once we’ve got several login+password pairings we can then go back and test them on targeted sites.
  • But wait… How do I know which bank you use and what your login ID is for the sites you frequent? All those cookies are simply stored, unencrypted and nicely named, in your Web browser’s cache. (Read this post to remedy that problem.)

And how fast could this be done? Well, that depends on three main things, the length and complexity of your password, the speed of the hacker’s computer, and the speed of the hacker’s Internet connection.

Assuming the hacker has a reasonably fast connection and PC here is an estimate of the amount of time it would take to generate every possible combination of passwords for a given number of characters. After generating the list it’s just a matter of time before the computer runs through all the possibilities – or gets shut down trying.

Pay particular attention to the difference between using only lowercase characters and using all possible characters (uppercase, lowercase, and special characters – like @#$%^&*). Adding just one capital letter and one asterisk would change the processing time for an 8 character password from 2.4 days to 2.1 centuries.

Password Length All Characters Only Lowercase
3 characters
4 characters
5 characters
6 characters
7 characters
8 characters
9 characters
10 characters
11 characters
12 characters
13 characters
14 characters
0.86 seconds
1.36 minutes
2.15 hours
8.51 days
2.21 years
2.10 centuries
20 millennia
1,899 millennia
180,365 millennia
17,184,705 millennia
1,627,797,068 millennia
154,640,721,434 millennia
0.02 seconds
.046 seconds
11.9 seconds
5.15 minutes
2.23 hours
2.42 days
2.07 months
4.48 years
1.16 centuries
3.03 millennia
78.7 millennia
2,046 millennia

Remember, these are just for an average computer, and these assume you aren’t using any word in the dictionary. If Google put their computer to work on it they’d finish about 1,000 times faster.

Via One Mans Blog
image: Passwordsafepro

Twitter – forbidden passwords

Below this text is a list of passwords not accepted by Twitter in their signup process. The list is copied from the HTML source at https://twitter.com/signup. You might call it the flip side of a dictionary attack, a list of common passwords that they won’t let you use, perhaps because they detected attacks trying to hack accounts with these passwords.

They’re not the only bad passwords out there, but you’d probably do well to avoid all these for other services as well.

111111 dakota maverick sophie
112233 dallas maxwell spanky
121212 daniel melissa sparky
123123 danielle member spider
123456 debbie mercedes squirt
1234567 dennis merlin srinivas
131313 diablo michael startrek
232323 diamond michelle starwars
654321 doctor mickey steelers
666666 doggie midnight steven
696969 dolphin miller sticky
777777 dolphins mistress stupid
7777777 donald monica success
8675309 dragon monkey summer
987654 dreams monkey sunshine
aaaaaa driver monster superman
abc123 eagle1 morgan surfer
abc123 eagles mother swimming
abcdef edward mountain sydney
abgrtyu einstein muffin taylor
access erotic murphy tennis
access14 extreme mustang teresa
action falcon naked tester
albert fender nascar testing
alexis ferrari nathan theman
amanda firebird naughty thomas
amateur fishing ncc1701 thunder
andrea florida newyork thx1138
andrew flower nicholas tiffany
angela flyers nicole tigers
angels football nipple tigger
animal forever nipples tomcat
anthony freddy oliver topgun
apollo freedom orange toyota
apples gandalf packers travis
arsenal gateway panther trouble
arthur gators panties trustno1
asdfgh gemini parker tucker
asdfgh george password turtle
ashley giants password twitter
august ginger password1 united
austin golden password12 vagina
badboy golfer password123 victor
bailey gordon patrick victoria
banana gregory peaches viking
barney guitar peanut voodoo
baseball gunner pepper voyager
batman hammer phantom walter
beaver hannah phoenix warrior
beavis hardcore player welcome
bigdaddy harley please whatever
bigdog heather pookie william
birdie helpme porsche willie
bitches hockey prince wilson
biteme hooters princess winner
blazer horney private winston
blonde hotdog purple winter
blondes hunter pussies wizard
bond007 hunting qazwsx xavier
bonnie iceman qwerty xxxxxx
booboo iloveyou qwertyui xxxxxxxx
booger internet rabbit yamaha
boomer iwantu rachel yankee
boston jackie racing yankees
brandon jackson raiders yellow
brandy jaguar rainbow zxcvbn
braves jasmine ranger zxcvbnm
brazil jasper rangers zzzzzz
bronco jennifer rebecca
broncos jeremy redskins
bulldog jessica redsox
buster johnny redwings
butter johnson richard
butthead jordan robert
calvin joseph rocket
camaro joshua rosebud
cameron junior runner
canada justin rush2112
captain killer russia
carlos knight samantha
carter ladies sammy
casper lakers samson
charles lauren sandra
charlie leather saturn
cheese legend scooby
chelsea letmein scooter
chester little scorpio
chicago london scorpion
chicken lovers secret
cocacola maddog sexsex
coffee madison shadow
college maggie shannon
compaq magnum shaved
computer marine sierra
cookie marlboro silver
cooper martin skippy
corvette marvin slayer
cowboy master smokey
cowboys matrix snoopy
crystal matthew soccer