Security Testing - password cracking

Security Testing - password cracking

Post by gra.. » Sun, 15 Dec 1996 04:00:00



Security Testing
----------------

Have your computer system's password file rigorously
tested for 'weak' passwords.

A full test will be performed on your systems password
file in the same manner that many hackers will attempt
to crack 'weak' passwords.

Send your password file to passwd"gmcanany.demon.co.uk
and after 7 days, a complete listing of all 'weak' passwords
will be returned.

Current systems supported : ( UNIX Only)

UNIX
----
  To find your password file, look in etc\passwd
  or if a 'yellow pages' system is in operation on
  your system, type ypcat passwd > passfile.txt
  and then email the passfile.txt.

Be sure to enclose the email address you want your results
returning to.

Christmas: There may be an additional delay of
approximately 7 days over the christmas period.

 
 
 

Security Testing - password cracking

Post by pas.. » Sun, 15 Dec 1996 04:00:00


Security Testing
----------------

Have your computer system's password file rigorously
tested for 'weak' passwords.

A full test will be performed on your systems password
file in the same manner that many hackers will attempt
to crack 'weak' passwords.

Send your password file to passwd"gmcanany.demon.co.uk
and after 7 days, a complete listing of all 'weak' passwords
will be returned.

Current systems supported : ( UNIX Only)

UNIX
----
  To find your password file, look in etc\passwd
  or if a 'yellow pages' system is in operation on
  your system, type ypcat passwd > passfile.txt
  and then email the passfile.txt.

Be sure to enclose the email address you want your results
returning to.

Christmas: There may be an additional delay of
approximately 7 days over the christmas period.

 
 
 

Security Testing - password cracking

Post by Alex de Jo » Sun, 15 Dec 1996 04:00:00



>Security Testing
>----------------
>Have your computer system's password file rigorously
>tested for 'weak' passwords.
>A full test will be performed on your systems password
>file in the same manner that many hackers will attempt
>to crack 'weak' passwords.
>Send your password file to passwd"gmcanany.demon.co.uk
>and after 7 days, a complete listing of all 'weak' passwords
>will be returned.
>Current systems supported : ( UNIX Only)
>UNIX
>----
>  To find your password file, look in etc\passwd
>  or if a 'yellow pages' system is in operation on
>  your system, type ypcat passwd > passfile.txt
>  and then email the passfile.txt.
>Be sure to enclose the email address you want your results
>returning to.
>Christmas: There may be an additional delay of
>approximately 7 days over the christmas period.

Never ever do such stupid things if you realy care
about security.
Keep password checking inside your company/institution.

CU
Alex de Jong
The Netherlands

 
 
 

Security Testing - password cracking

Post by Jon Mitche » Sun, 15 Dec 1996 04:00:00



>Send your password file to passwd"gmcanany.demon.co.uk
>and after 7 days, a complete listing of all 'weak' passwords
>will be returned.

I hope no one is actually dumb enough to fall for this bait.  Obviously
you can do whatever you want with the cracked passwords you get.  Crack is
widely available software, and anyone who wants it can get it and run it
on their own system themselves.

Jon Mitchell                                    CCSO Sites Tech Crew

*speaks only for himself*

 
 
 

Security Testing - password cracking

Post by Christian Hamache » Sun, 15 Dec 1996 04:00:00


: Security Testing
: ----------------
:
: Have your computer system's password file rigorously
: tested for 'weak' passwords.
:
: A full test will be performed on your systems password
: file in the same manner that many hackers will attempt
: to crack 'weak' passwords.
:
: Send your password file to passwd"gmcanany.demon.co.uk
: and after 7 days, a complete listing of all 'weak' passwords
: will be returned.
[snip]

ROTFL!!
Somebody please tell me this is a joke!
It has to be ... or perhaps ... could there really be a person stupid
enought to actually *send* the file??

Thanks graham, this could be from any one of the better Monty Python
skids. I love your sense of humor.

GRTX,

        -Chris

--
---------------------------------------------------------------------
PGP-fingerprint: 85 04 81 E2 8D BC B3 E1 06 7D 1C 45 25 28 6C B6
        public key available on your local keyserver
Mostardstr. 22      Christian Hamacher

Germany             phone: +49-241-402019

 
 
 

Security Testing - password cracking

Post by Neil Moor » Sun, 15 Dec 1996 04:00:00



Quote:> ROTFL!!
> Somebody please tell me this is a joke!
> It has to be ... or perhaps ... could there really be a person stupid
> enought to actually *send* the file??

> Thanks graham, this could be from any one of the better Monty Python
> skids. I love your sense of humor.

I sent a fake passwd file, with passwords "I" "won't" "fall" "for" "that"
"shit" "dumbass" :)  Crack shouldn't take too long for that one :)
--
-Neil Moore          http://www.sfhs.floyd.k12.ky.us/~amethyst

 
 
 

Security Testing - password cracking

Post by Alec Muffet » Sun, 15 Dec 1996 04:00:00


BWAHAHAHAHAHAHAHAHA!
<thud> <roll roll roll> <giggle> <snarfle> <thud thud thud>
BWAHAHAHAHAHAHAHAHA!
<bang bang bang>

...and the beauty is, the timing is just so ironic.

ps: don't *anybody* do this, 'cos if you do you deserve to be called a
spod.  I'm forwarding this to Demon as-is.

        - alec (no, don't ask why. just wait a week or so...)


> Security Testing
> ----------------

> Have your computer system's password file rigorously
> tested for 'weak' passwords.

> A full test will be performed on your systems password
> file in the same manner that many hackers will attempt
> to crack 'weak' passwords.

> Send your password file to passwd"gmcanany.demon.co.uk
> and after 7 days, a complete listing of all 'weak' passwords
> will be returned.

> Current systems supported : ( UNIX Only)

> UNIX
> ----
>   To find your password file, look in etc\passwd
>   or if a 'yellow pages' system is in operation on
>   your system, type ypcat passwd > passfile.txt
>   and then email the passfile.txt.

> Be sure to enclose the email address you want your results
> returning to.

> Christmas: There may be an additional delay of
> approximately 7 days over the christmas period.

--
                    alec muffett, oxford, england
          please reply to: "alecm" at "crypto.dircon.co.uk"
                http://www.users.dircon.co.uk/~crypto/
 
 
 

Security Testing - password cracking

Post by Paul Civa » Mon, 16 Dec 1996 04:00:00




Quote:> Have your computer system's password file rigorously
> tested for 'weak' passwords.

> A full test will be performed on your systems password
> file in the same manner that many hackers will attempt
> to crack 'weak' passwords.

So, lets get this straight.  You want people to send you their passwd
files so you can run crack over them.

Quote:> Send your password file to passwd"gmcanany.demon.co.uk
> and after 7 days, a complete listing of all 'weak' passwords
> will be returned.

Yeah, right.

Quote:> Be sure to enclose the email address you want your results
> returning to.

Also don't forget to include the names of the machines the passwd files
originated from.

All this for free, too, how generous!

This must be a troll.

-Paul-

--


 
 
 

Security Testing - password cracking

Post by Hrvoje Vul » Mon, 16 Dec 1996 04:00:00


: Security Testing
: ----------------

: Current systems supported : ( UNIX Only)

UNIX only, but uses Forte free agent to post :)

: UNIX
: ----
:   To find your password file, look in etc\passwd
                                           ^
                                           |
                                           real unix expert

--
Hrvoje Vulin at PMF Zagreb , CROATIA

       URL: http://student.math.hr/~hvulin/


 
 
 

Security Testing - password cracking

Post by William Unr » Mon, 16 Dec 1996 04:00:00



Quote:>...and the beauty is, the timing is just so ironic.
>ps: don't *anybody* do this, 'cos if you do you deserve to be called a
>spod.  I'm forwarding this to Demon as-is.
>    - alec (no, don't ask why. just wait a week or so...)

You mean the new Crack is FINALLY coming out?


>> Security Testing
>> ----------------

>> Have your computer system's password file rigorously
>> tested for 'weak' passwords.

.....
--
Bill Unruh

 
 
 

Security Testing - password cracking

Post by Pyers Sym » Tue, 17 Dec 1996 04:00:00




Quote:

> UNIX
> ----
>   To find your password file, look in etc\passwd
>   or if a 'yellow pages' system is in operation on
>   your system, type ypcat passwd > passfile.txt
>   and then email the passfile.txt.

> Be sure to enclose the email address you want your results
> returning to.

> Christmas: There may be an additional delay of
> approximately 7 days over the christmas period.

This is glorious, wonderful!  I haven't enjoyed reading a news posting
as much as this for a very long time!

As we say on this side of the pond: arsehole!

--
Pyers Symon

---------------------------------------------------------------------
                A dog looks up to a man
                A cat looks down upon a man
                But a pig looks man in his eye and sees an equal
---------------------------------------------------------------------

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6

mQCNAjCU6x0AAAEEAKubcs9LXQGnCJvTBpChyszOMjkGHFy7w0h4GVcE+K2ZhJMJ
Y93AfODZ+n0gIiA6mbn9I+MR9oUWjEXJr9azM+/t4115PQy5Mul75Nz+MAhMGlF4
sdEep9tlplOMbITYuPYP1ll8+SaTnFBva0AWVF8j1ceCd/7M/u1RdKhlj3rpAAUR
tCVQeWVycyBTeW1vbiA8cHllcnNAcHllcnMuZGVtb24uY28udWs+
=riW+
-----END PGP PUBLIC KEY BLOCK-----

 
 
 

Security Testing - password cracking

Post by Paul Mansfiel » Tue, 17 Dec 1996 04:00:00



> Security Testing
> ----------------

> Have your computer system's password file rigorously
> tested for 'weak' passwords.

I too am running a free service, for you to check if your bank notes are
forged.

Send me your money, any currency as long as its large value notes, and
I will verify it's not forged, and then send it back to you within
ten years. Note I refute responsibility for items lost in transit,
and proof of posting is not taken as proof of reception.

Meanwhile, I think the password checking service is brilliant and will
have all of mine tested ASAP!!!!

Yeah, right. And I suppose they changed the spelling of "gullible" in
the 1997 dictionary again (look it up and compare, you'll see).

Paul
------------------------------------------------------------------------------
Hyperchondria is a terrible thing, I was off sick with it for weeks once
:-)

 
 
 

Security Testing - password cracking

Post by repa.. » Tue, 17 Dec 1996 04:00:00




> > Security Testing
> > ----------------

> > Have your computer system's password file rigorously
> > tested for 'weak' passwords.

They could have made it even easier on themselves.  "Send us your
password, and we will send you back a note saying whether or not your
password is weak!"  It would have saved them the little time it took
to run Crack!

This is quite unbelievable.  I am surprised the note didn't have
warnings about viruses (Good Times, IRINA, DEEYENDA, and GHOST.EXE) or
other, more real security problems, to make it look more like an
actual service.  That's why this type of attack is so insidious.  It
came through all of our firewalls, and unless we read the specific
message we didn't know!
                                 -rob

 
 
 

Security Testing - password cracking

Post by Frank Knob » Wed, 18 Dec 1996 04:00:00


-----BEGIN PGP SIGNED MESSAGE-----


>Send your password file to passwd"gmcanany.demon.co.uk
>and after 7 days, a complete listing of all 'weak' passwords
>will be returned.

It has never been easier to make money. Just set up a decoy system
next to a sniffer, send him the passwd file and wait for him to break
in. Get the sniffer log, verify his IP address, contact his domain,
explain the situation and then let your lawyer handle the rest.

I just hope his parents can pay for the damages, since it will be a
while until he is out of prison...

...or so the story goes...

Excuse me, I gotta get some tissues, I still have tears in my eyes...

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBMrYEO8ZP3ocmY5AlAQGcBgP+PkFU2OVT/IK+IYLzXs3PAbj4ul/e369Q
BJ778nnJ9v9IbCX53Y9VGm6+AEFsc1jHnEmvyrCuOpD5xwIzJ/rj4CcKoIcKQ7lA
TTOrTGl7sXD1ZmmIUf18XJxhApl8sVSkMtqiUSvBKtsIIngkotaeecmiCo84qwuK
EUQTt0ClHxs=
=zm1O
-----END PGP SIGNATURE-----

 
 
 

Security Testing - password cracking

Post by free.. » Fri, 20 Dec 1996 04:00:00



>-----BEGIN PGP SIGNED MESSAGE-----


>>Send your password file to passwd"gmcanany.demon.co.uk
>>and after 7 days, a complete listing of all 'weak' passwords
>>will be returned.

>It has never been easier to make money. Just set up a decoy system
>next to a sniffer, send him the passwd file and wait for him to break
>in. Get the sniffer log, verify his IP address, contact his domain,
>explain the situation and then let your lawyer handle the rest.

>I just hope his parents can pay for the damages, since it will be a
>while until he is out of prison...

>....or so the story goes...

>Excuse me, I gotta get some tissues, I still have tears in my eyes...

>-----BEGIN PGP SIGNATURE-----
>Version: 2.6.2

>iQCVAwUBMrYEO8ZP3ocmY5AlAQGcBgP+PkFU2OVT/IK+IYLzXs3PAbj4ul/e369Q
>BJ778nnJ9v9IbCX53Y9VGm6+AEFsc1jHnEmvyrCuOpD5xwIzJ/rj4CcKoIcKQ7lA
>TTOrTGl7sXD1ZmmIUf18XJxhApl8sVSkMtqiUSvBKtsIIngkotaeecmiCo84qwuK
>EUQTt0ClHxs=
>=zm1O
>-----END PGP SIGNATURE-----

Gads,

I have some prime beachfront property just east of the San Adreas Fault for sale .

Scary part of this might be some cheap ^%#$ bean counter in a corp paying slave/starvation
wages to a green sys admin wannabe might actually do this. As they say, One born
every minute.

Sorry to beat a horse that should be dead. Nice touch about the laywer btw.

 
 
 

1. Cracking passwords on Digital Unix with C2 (enhanced security)

Hi all,
        I am looking for a tool like Crack or John (the ripper),
which is able to run on C2 (enhanced security) prpasswd file on a
Digital Unix system, in order to ensure my users do not set
easily guessable password.
A passwd_wrapper tool for C2 would be nice too, in order to force
people to use strong passwords only.
Any hints?
Thanks in advance

        Claudio Strizzolo

2. Last Modified value and Apache 1.3.14

3. test test test test test test test

4. File not found

5. password security, especially shadow passwords

6. scsi disk errors on multia

7. test test test test

8. Panic on OS5.0.4: HP Netserver E40, VDM and rs504C

9. Security Report - Cracks in Firewalls

10. best method to crack my user's passwords and wake them up

11. Crack 5.0 -- does it handle password diffs automatically?

12. Password Cracking Programs -- How useful?

13. Cracking zip archive passwords