Results 1 to 13 of 13

Thread: Syrian President's Emails Hacked - Password 12345

  1. #1
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Syrian President's Emails Hacked - Password 12345

    throw new ArgumentException (String, String, Exception)

  2. #2
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: Syrian President's Emails Hacked - Password 12345

    Hmmm. I'd have guessed at "open sesame".

  3. #3
    Oh Crumbs.... Biscuit's Avatar
    Join Date
    Feb 2007
    Location
    N. Yorkshire
    Posts
    11,193
    Thanks
    1,394
    Thanked
    1,091 times in 833 posts
    • Biscuit's system
      • Motherboard:
      • MSI B450M Mortar
      • CPU:
      • AMD 2700X (Be Quiet! Dark Rock 3)
      • Memory:
      • 16GB Patriot Viper 2 @ 3466MHz
      • Storage:
      • 500GB WD Black
      • Graphics card(s):
      • Sapphire R9 290X Vapor-X
      • PSU:
      • Seasonic Focus Gold 750W
      • Case:
      • Lian Li PC-V359
      • Operating System:
      • Windows 10 x64
      • Internet:
      • BT Infinity 80/20

    Re: Syrian President's Emails Hacked - Password 12345


  4. #4
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: Syrian President's Emails Hacked - Password 12345

    On a forum I ran many years ago, I did a database search and it was astonishing how many people used "password" as their password. And "open sesame" ran it a fairly close second. Mind you, that's a trivial forum, not a head of state's email account (allegedly).

  5. #5
    WEEEEEEEEEEEEE! MadduckUK's Avatar
    Join Date
    May 2006
    Location
    Lytham St. Annes
    Posts
    17,297
    Thanks
    653
    Thanked
    1,579 times in 1,005 posts
    • MadduckUK's system
      • Motherboard:
      • MSI B450M Mortar
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • 32GB 3200 DDR4
      • Storage:
      • 1x480GB SSD, 1x 2TB Hybrid, 1x 3TB Rust Spinner
      • Graphics card(s):
      • Radeon 5700XT
      • PSU:
      • Corsair TX750w
      • Case:
      • Phanteks Enthoo Evolv mATX
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • Samsung SJ55W, DELL S2409W
      • Internet:
      • Plusnet 80

    Re: Syrian President's Emails Hacked - Password 12345

    Quote Originally Posted by Saracen View Post
    On a forum I ran many years ago, I did a database search and it was astonishing how many people used "password" as their password.
    no, that's not the astonishing thing here.
    Quote Originally Posted by Ephesians
    Do not be drunk with wine, which will ruin you, but be filled with the Spirit
    Vodka

  6. #6
    radix lecti dave87's Avatar
    Join Date
    Sep 2005
    Location
    England
    Posts
    12,806
    Thanks
    657
    Thanked
    931 times in 634 posts
    • dave87's system
      • Motherboard:
      • Asus
      • CPU:
      • i5 3470k under Corsair H80 WC
      • Memory:
      • 8gb DDR3
      • Storage:
      • 240gb SSD + 120gb SSD
      • Graphics card(s):
      • Asus HD7950
      • PSU:
      • XFX 600w Modular
      • Case:
      • Lian Li PC-A05FNB + Acoustipack
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2x Dell S2309W (1920x1080)
      • Internet:
      • BT Infinity Option 2

    Re: Syrian President's Emails Hacked - Password 12345

    Quote Originally Posted by Saracen View Post
    On a forum I ran many years ago, I did a database search and it was astonishing how many people used "password" as their password. And "open sesame" ran it a fairly close second. Mind you, that's a trivial forum, not a head of state's email account (allegedly).
    You stored passwords in plaintext?

  7. #7
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: Syrian President's Emails Hacked - Password 12345

    Quote Originally Posted by MadduckUK View Post
    no, that's not the astonishing thing here.
    It was the astonishing thing there. The point, by the way, was to assess the situation prior to tightening security, which subsequently forced a password change and precluded the more obvious ones.

  8. #8
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: Syrian President's Emails Hacked - Password 12345

    Quote Originally Posted by dave87 View Post
    You stored passwords in plaintext?
    Nope. They were stored as MD5 hashes. But if you MD5 "password" and do a database search on that value, you got a list of hits. And by the way, I didn't write the software, or determine how it stored passwords, or have any control over how it did it. It was a commercial product.

  9. #9
    radix lecti dave87's Avatar
    Join Date
    Sep 2005
    Location
    England
    Posts
    12,806
    Thanks
    657
    Thanked
    931 times in 634 posts
    • dave87's system
      • Motherboard:
      • Asus
      • CPU:
      • i5 3470k under Corsair H80 WC
      • Memory:
      • 8gb DDR3
      • Storage:
      • 240gb SSD + 120gb SSD
      • Graphics card(s):
      • Asus HD7950
      • PSU:
      • XFX 600w Modular
      • Case:
      • Lian Li PC-A05FNB + Acoustipack
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2x Dell S2309W (1920x1080)
      • Internet:
      • BT Infinity Option 2

    Re: Syrian President's Emails Hacked - Password 12345

    I did think that might have been what you'd have done, but there was the niggling doubt mind....

  10. #10
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Syrian President's Emails Hacked - Password 12345

    Single MD5, un-salted? Amazing how many people think "job done"...
    throw new ArgumentException (String, String, Exception)

  11. #11
    HEXUS.social member finlay666's Avatar
    Join Date
    Aug 2006
    Location
    Newcastle
    Posts
    8,546
    Thanks
    297
    Thanked
    894 times in 535 posts
    • finlay666's system
      • CPU:
      • 3570k
      • Memory:
      • 16gb
      • Graphics card(s):
      • 6950 2gb
      • Case:
      • Fractal R3
      • Operating System:
      • Windows 8
      • Monitor(s):
      • U2713HM and V222H
      • Internet:
      • cable

    Re: Syrian President's Emails Hacked - Password 12345

    Quote Originally Posted by Saracen View Post
    Nope. They were stored as MD5 hashes. But if you MD5 "password" and do a database search on that value, you got a list of hits. And by the way, I didn't write the software, or determine how it stored passwords, or have any control over how it did it. It was a commercial product.
    You didn't salt your hash?

    Must be back in the day, anything less than a salted SHA256 is considered insecure by many techies I know as it's easier (especially in asp.net) to hash with md5/sha1 instead of taking the effort to build a hashing system for sha256/512 that can incorporate a salt.

    TheAnimus: We picked up a project for a large legal client, all their clientel passwords were stored in plain text, banking details too, it was a sony scale fail (the excuse from the previous dev was that it was not externally facing...)
    H3XU5 Social FAQ
    Quote Originally Posted by tiggerai View Post
    I do like a bit of hot crumpet

  12. #12
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: Syrian President's Emails Hacked - Password 12345

    Quote Originally Posted by finlay666 View Post
    You didn't salt your hash?
    I didn't pepper or vinegar it, either.

    As I said earlier ....

    1) It was "many years ago"
    2) I didn't have any control over how commercial software stored it's passwords.

    The software did it how the software did it, and that was that. I didn't write the stuff. I just used it.

  13. #13
    cat /dev/null streetster's Avatar
    Join Date
    Jul 2003
    Location
    London
    Posts
    4,138
    Thanks
    119
    Thanked
    100 times in 82 posts
    • streetster's system
      • Motherboard:
      • Asus P7P55D-E
      • CPU:
      • Intel i5 750 2.67 @ 4.0Ghz
      • Memory:
      • 4GB Corsair XMS DDR3
      • Storage:
      • 2x1TB Drives [RAID0]
      • Graphics card(s):
      • 2xSapphire HD 4870 512MB CrossFireX
      • PSU:
      • Corsair HX520W
      • Case:
      • Coolermaster Black Widow
      • Operating System:
      • Windows 7 x64
      • Monitor(s):
      • DELL U2311
      • Internet:
      • Virgin 50Mb

    Re: Syrian President's Emails Hacked - Password 12345

    Quote Originally Posted by Biscuit View Post
    I guessed the reference before clicking the link -- gotta love Archer

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •