13urnzz
Banned
+5,830|6771

>9000
RTHKI
mmmf mmmf mmmf
+1,742|7011|Cinncinatti
100 million
42 years for bf2s


Morpheus wrote:

http://static.bf2s.com/files/user/31499 … sword-.png
good thing it's only on my luggage....
..spaceballs
https://i.imgur.com/tMvdWFG.png
Cheez
Herman is a warmaphrodite
+1,027|6712|King Of The Islands

Uh huh. It reckons my super easy password is 11 years, yet my mega bastard password (a serial number on the front of my television, including capital letters and symbols for good measure) is 200 days.

gg.
My state was founded by Batman. Your opinion is invalid.
tazz.
oz.
+1,339|6448|Sydney | ♥

https://u.tazz.me/16_10_10_17_30_17.jpg

Fuck Yea.

XD XD
everything i write is a ramble and should not be taken seriously.... seriously.
FloppY_
­
+1,010|6559|Denmark aka Automotive Hell

Cheez wrote:

Uh huh. It reckons my super easy password is 11 years, yet my mega bastard password (a serial number on the front of my television, including capital letters and symbols for good measure) is 200 days.

gg.
From what I tried, it is based more on a brute force crack than guessing words...

e.g. the number of letters affects it more than how complicated it is....
­ Your thoughts, insights, and musings on this matter intrigue me
tazz.
oz.
+1,339|6448|Sydney | ♥

FloppY_ wrote:

Cheez wrote:

Uh huh. It reckons my super easy password is 11 years, yet my mega bastard password (a serial number on the front of my television, including capital letters and symbols for good measure) is 200 days.

gg.
From what I tried, it is based more on a brute force crack than guessing words...

e.g. the number of letters affects it more than how complicated it is....
I lol'd at the guys faq page.

He's such a comedian. Read it.
everything i write is a ramble and should not be taken seriously.... seriously.
SEREVENT
MASSIVE G STAR
+605|6381|Birmingham, UK
about a billion years
SEREMAKER
BABYMAKIN EXPERT √
+2,187|6842|Mountains of NC

5 mins to 20 mins



hmmmmmmmmm ...................... who really has 5 mins to kill
https://static.bf2s.com/files/user/17445/carhartt.jpg
RDMC
Enemy Wheelbarrow Spotted..!!
+736|6839|Area 51
Most basic password: 5 hours.
Next password: 242 days.
Mostly used password: 252 days.
Password used for important stuff: 237 years.
FEOS
Bellicose Yankee Air Pirate
+1,182|6684|'Murka

Ever wonder if this guy is just harvesting people's passwords?
“Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid.”
― Albert Einstein

Doing the popular thing is not always right. Doing the right thing is not always popular
SEREVENT
MASSIVE G STAR
+605|6381|Birmingham, UK

FEOS wrote:

Ever wonder if this guy is just harvesting people's passwords?
you've got me scared now
FEOS
Bellicose Yankee Air Pirate
+1,182|6684|'Murka

SEREVENT wrote:

FEOS wrote:

Ever wonder if this guy is just harvesting people's passwords?
you've got me scared now
I'm just saying...it's a great way to do it.
“Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid.”
― Albert Einstein

Doing the popular thing is not always right. Doing the right thing is not always popular
FloppY_
­
+1,010|6559|Denmark aka Automotive Hell

FEOS wrote:

SEREVENT wrote:

FEOS wrote:

Ever wonder if this guy is just harvesting people's passwords?
you've got me scared now
I'm just saying...it's a great way to do it.
>Implying he doesn't need a username & location too

Last edited by FloppY_ (2010-10-16 07:14:15)

­ Your thoughts, insights, and musings on this matter intrigue me
GC_PaNzerFIN
Work and study @ Technical Uni
+528|6688|Finland

Put the input gathered from this to brute force database and yeah you don't need to know exact place.

Everyone who puts their best passwords on webpage like that forgot the most basic rule of security: NEVER tell your password to ANYONE
3930K | H100i | RIVF | 16GB DDR3 | GTX 480 | AX750 | 800D | 512GB SSD | 3TB HDD | Xonar DX | W8
Jenspm
penis
+1,716|7006|St. Andrews / Oslo

FloppY_ wrote:

FEOS wrote:

SEREVENT wrote:


you've got me scared now
I'm just saying...it's a great way to do it.
>Implying he doesn't need a username & location too
. . .
https://static.bf2s.com/files/user/26774/flickricon.png https://twitter.com/phoenix/favicon.ico
FEOS
Bellicose Yankee Air Pirate
+1,182|6684|'Murka

FloppY_ wrote:

FEOS wrote:

SEREVENT wrote:

you've got me scared now
I'm just saying...it's a great way to do it.
>Implying he doesn't need a username & location too
Location is irrelevant.

True, username is helpful, but the password is the difficult part. If you harvest an assload of passwords--to include difficult ones--you've populated a database that reduces your brute-force requirements. You have KNOWN passwords. And since people often use the same password for multiple uses...

This is social engineering 101. They get usernames some other way and just start bashing the passwords against them.

You're acting as if this single website is the only method of collecting the data they would need.
“Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid.”
― Albert Einstein

Doing the popular thing is not always right. Doing the right thing is not always popular
SEREMAKER
BABYMAKIN EXPERT √
+2,187|6842|Mountains of NC

FEOS wrote:

FloppY_ wrote:

FEOS wrote:


I'm just saying...it's a great way to do it.
>Implying he doesn't need a username & location too
Location is irrelevant.

True, username is helpful, but the password is the difficult part. If you harvest an assload of passwords--to include difficult ones--you've populated a database that reduces your brute-force requirements. You have KNOWN passwords. And since people often use the same password for multiple uses...

This is social engineering 101. They get usernames some other way and just start bashing the passwords against them.

You're acting as if this single website is the only method of collecting the data they would need.
we report to the local authorites



he's al qaeda
https://static.bf2s.com/files/user/17445/carhartt.jpg
Hurricane2k9
Pendulous Sweaty Balls
+1,538|5975|College Park, MD
Lest secure: 8 years, two thousand with one modification
Most secure: 10 million years
https://static.bf2s.com/files/user/36793/marylandsig.jpg
Finray
Hup! Dos, Tres, Cuatro
+2,629|6062|Catherine Black
https://imgs.xkcd.com/comics/password_reuse.png
https://i.imgur.com/qwWEP9F.png
Obiwan
Go Cards !!
+196|6968|The Ville
*******

Last edited by Obiwan (2010-10-16 16:55:44)

tazz.
oz.
+1,339|6448|Sydney | ♥

IS THIS SAFE?
It is actually. I'm not harvesting passwords into an EVIL database. Of course that's exactly the sort of thing I would say if I were harvesting them. And it wouldn't be hard to do it: a couple of lines of code and I'd have all your passwords. MWUHAHAHAHAHAA! But, to be honest, I don't know what I'd do with them. Make a cake perhaps.

The bit of code that does the calculations is done in JavaScript. And JavaScript is a "client-side" language. That means it runs on your computer – not on ours. No data ever travels from your computer back to the website. You can check this by loading up the webpage and then turning off your internet connection. You'll still be able to use the website to your heart's content.

However, for the SUPER-paranoid among you, you could just type in something a bit like your password rather than your actual password. In fact, that's probably a good idea anyway. Just in case I'm lying.
I seriously lol'd

SC: http://howsecureismypassword.net/faq/#safe
everything i write is a ramble and should not be taken seriously.... seriously.
FloppY_
­
+1,010|6559|Denmark aka Automotive Hell

tazz. wrote:

IS THIS SAFE?
It is actually. I'm not harvesting passwords into an EVIL database. Of course that's exactly the sort of thing I would say if I were harvesting them. And it wouldn't be hard to do it: a couple of lines of code and I'd have all your passwords. MWUHAHAHAHAHAA! But, to be honest, I don't know what I'd do with them. Make a cake perhaps.

The bit of code that does the calculations is done in JavaScript. And JavaScript is a "client-side" language. That means it runs on your computer – not on ours. No data ever travels from your computer back to the website. You can check this by loading up the webpage and then turning off your internet connection. You'll still be able to use the website to your heart's content.

However, for the SUPER-paranoid among you, you could just type in something a bit like your password rather than your actual password. In fact, that's probably a good idea anyway. Just in case I'm lying.
I seriously lol'd

SC: http://howsecureismypassword.net/faq/#safe
­ Your thoughts, insights, and musings on this matter intrigue me
ceslayer23
IN YOUR MIRROR
+142|6634|CLOSER THAN I APPEAR
penis is one of the 500 most used passwords, it would be cracked almost instantly
rdx-fx
...
+955|6865
Hah!  my password isn't on the list of 500 worst passwords!

Nobody would guess "fluffysnugglebunny" , it's like the perfect password!

oh.. um.. right.

In other words, what kind of rocket surgeon puts a password they actually use into a potential farming website that asks "hey, gimmie your password, so I can.. um.. see how secure it is!  yeah!  Gimmie your IP and password.  Just for fun!" ?

Last edited by rdx-fx (2010-10-17 10:49:09)

FloppY_
­
+1,010|6559|Denmark aka Automotive Hell

rdx-fx wrote:

Hah!  my password isn't on the list of 500 worst passwords!

Nobody would guess "fluffysnugglebunny" , it's like the perfect password!

oh.. um.. right.

In other words, what kind of rocket surgeon puts a password they actually use into a potential farming website that asks "hey, gimmie your password, so I can.. um.. see how secure it is!  yeah!  Gimmie your IP and password.  Just for fun!" ?
ITT: Everyone
­ Your thoughts, insights, and musings on this matter intrigue me

Board footer

Privacy Policy - © 2025 Jeff Minard