3 ms·
Did you just give away very predictable credentials from a very predictable person with full access to very predictable IT equipment?
by ifdefdebug 5y ago
Did you just give away very predictable credentials from a very predictable person with full access to very predictable IT equipment?
- moron4hire 5y agoWith passwords that simple, it's crackable almost instantaneously without any preknowledge of the password format. That, coupled with the fact that systems get randomly attacked all the time, I doubt it's really that big of a deal. Attackers don't need hints on passwords, they don't need hints on targets. They just target everyone, and try all easy passwords.
- hsbauauvhabzb 5y agoIt depends on the context, if I have a hash it’s trivial to crack dictionaryword29, if I’m brute forcing a VPN/RDP endpoint, generally fail2ban are hard enough to block mass attempts (an AD default, iirc), the latter is usually solved by phishing which has the added benefit of MFA capture also. Pentester here, to clear any dubious assumptions.
- ivalm 5y agoBut if the password is salted is it still easy to crack?
- hansvm 5y agoYes, definitely. The salt just means you have to compute a few hashes yourself rather than relying on a lookup table.
- tracker1 5y agoYes... there are lists that are generally used for common variants of passphrases and can generally crack a simple passphrase like ggp in less than a day easily, faster or slower depending on hardware in use, concurrency and order. 4-5 dictionary words with proper sentence structure is a lot safer for the most part. Random safer still, but much harder to remember... my current password for work in a sentence with 24 characters. spaces, capitals and punctuation. Other than my OS and password manager, I really don't remember any other passwords I use, and the majority are random generated at this point. I also use a wildcard mail forwarder, so most new sites I've used in the past year or two are all unique emails as well.
- OJFord 5y agoIf you're relying on all former colleagues not inadvertently (or otherwise) giving away details that may (slightly aid in the) comprise (of) your systems...