Archive for the ‘Passwords’ Category

Followup to my Facebook research

Filed under: Passwords

Hey all,
Some of you may have heard what I did this month. It turns out, depending on who you listen to, that I'm either an evil "Facebook hacker" or just some mischievous individual doing "unsettling" research. But, one way or the other, a huge number of people have read or heard this story, and that's [...]

Read More
Permalink Comments (20) Ron Bowes Aug 12, 2010

Return of the Facebook Snatchers

Filed under: Hacking, Passwords

First and foremost: if you want to cut to the chase, just download the torrent. If you want the full story, please read on....
Background
Way back when I worked at Symantec, my friend Nick wrote a blog that caused a little bit of trouble for us: Attack of the Facebook Snatchers. I was blog editor at [...]

Read More
Permalink Comments (113) Ron Bowes Jul 26, 2010

robots.txt: important if you're hosting passwords

Filed under: Passwords

This is going to be a fun post that's related to some of my password work. Some of the text may not be PG13, so parental discretion is advised.
As most of you know, I've been collecting password lists. In addition to normal password lists that are useful in bruteforcing, I have a (so far) [...]

Read More
Permalink Comments (2) Ron Bowes Mar 16, 2010

The ultimate faceoff between password lists

Filed under: Nmap, Passwords

Yes, I'm still working on making the ultimate password list. And I don't mean the 16gb one I made by taking pretty much every word or word-looking string on the Internet when I was a kid; that was called ultimater dictionary. No; I mean one that is streamlined, sorted, and will make Nmap the bruteforce [...]

Read More
Permalink Comments (8) Ron Bowes Mar 11, 2010

Hard evidence that people suck at passwords

Filed under: Passwords

Hey everybody!
As you probably know, I've been working hard on generating and evaluating passwords. My last post was all about Rockyou.com's passwords; next post will (probably) be about different groups of passwords from my just updated password dictionaries page. This will be a little different, though.

Read More
Permalink Comments (0) Ron Bowes Mar 6, 2010