Archive for March, 2011
Filed under: Hacking, Passwords
Hey everybody! This is part 3 to my 2-part series on password reset attacks (Part 1 / Part 2). Overall, I got awesome feedback on the first two parts, but I got the same question over and over: what's the RIGHT way to do this? So, here's the thing. I like to break stuff, but [...]
Read More
Permalink Comments (9) Ron Bowes Mar 24, 2011
Filed under: Hacking, Passwords, Tools
Hey, In my last post, I showed how we could guess the output of a password-reset function with a million states. While doing research for that, I stumbled across some software that had a mere 16,000 states. I will show how to fully compromise this software package remotely using the password reset. The code First, [...]
Read More
Permalink Comments (5) Ron Bowes Mar 15, 2011
Filed under: Hacking, Passwords, Tools
Greetings, all! This is part one of a two-part blog on password resets. For anybody who saw my talk (or watched the video) from Winnipeg Code Camp, some of this will be old news (but hopefully still interesting!) For this first part, I'm going to take a closer look at some very common (and very [...]
Read More
Permalink Comments (11) Ron Bowes Mar 9, 2011