I was logging in tonight and forgot to press shift, turns out, it accepted the password anyway.
Is it common for sites to do this? sounds like pretty piss poor security practices if you ask me...
![]() ![]() ![]() |
|
Kyanar: Well, most banks are case insensitive for their online banking too, so... yes.
I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.
19,921,814,720,464,100,000
I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.
Lias: I don't believe it allows special characters, only alphanumeric (and not case sensitive at that).
10 characters of {a-z,0-9} is 3,656,158,440,062,976 possible, which sounds heaps until you consider that last December a security researched built a 25 GPU cracking rig that could do around 350 billion NTLM attempts per second.. Which would eat that entire range in under 3 hours.. or 6 hours for MD5
Even a decent semi-highend home gaming rig can crank out as many as 5 billion attempts per second. That would chew through that range in a mere 8.5 days..
*EDIT* and that's purely brute forcing the range.. It doesn't even begin to take into account someone with a bit of knowledge and skill applying various "Smart" rules or rainbow tables or what have you to the attempt.
itxtme:Lias: I don't believe it allows special characters, only alphanumeric (and not case sensitive at that).
10 characters of {a-z,0-9} is 3,656,158,440,062,976 possible, which sounds heaps until you consider that last December a security researched built a 25 GPU cracking rig that could do around 350 billion NTLM attempts per second.. Which would eat that entire range in under 3 hours.. or 6 hours for MD5
Even a decent semi-highend home gaming rig can crank out as many as 5 billion attempts per second. That would chew through that range in a mere 8.5 days..
*EDIT* and that's purely brute forcing the range.. It doesn't even begin to take into account someone with a bit of knowledge and skill applying various "Smart" rules or rainbow tables or what have you to the attempt.
I would love to see you hit the IRD login system 5 billion times.......
I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.
|
![]() ![]() ![]() |