3 ms·
AOL had some crazy password vulnerabilities. For awhile "12345678" would validate if your password was actually 1234, 12345, 123456, 1234567. So that means you
by ry4nf 3y ago
AOL had some crazy password vulnerabilities. For awhile "12345678" would validate if your password was actually 1234, 12345, 123456, 1234567. So that means you could speed up your cracking by removing some of those shorter passwords from your list. Another I remember was for awhile(99-2000ish?) you could change your password and old passwords still worked. I don't know how long it took AOL to fix those but at least a few months for each one from the time I found out about them.
If you first connected to another dialup company like Earthlink you could then change AOL's connection settings to TCP/IP instead of dialup which let you go from the AOL sign-in window to completely logged in just in a few seconds. That means you could skip the entire dialup process when having to re-connect to AOL after either getting a successful crack or disconnected from the guest login screen for too many invalid guesses. Later on some guys figured out how to make "winsock crackers" that were actually really fast but would get patched when too many people started using the different methods people were finding.
- Dylan16807 3y ago> AOL had some crazy password vulnerabilities. For awhile "12345678" would validate if your password was actually 1234, 12345, 123456, 1234567. So that means you could speed up your cracking by removing some of those shorter passwords from your list. I wouldn't call that a vulnerability, even if lets you attack passwords 2% faster.
- ry4nf 3y agoYeah I don't know what it would be called but it was a nice trick for the type of cracking like was being described by harvesting names out of public chats. People normally used short password lists with variations of a lot of common things when they were trying running a list of thousands of names to crack. No clue exactly how much it improved hit rates or speed but I remember being it helpful for sure