CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer
image Passwords: Everyone needs a good reminder about when it's time to change their passwords image
Privacy
Every year on March 15th my mother would act out the death of Julius Caesar. From the warning he received as a young child from the grimy soothsayer, his speech to his "Friends, Romans, Countrymen", the assassin sneaking up behind him for the strike, a truly pained "Et tu Brute?", and a couple of final gurgles. Oh, the last death throes of a great ruler, acted out yearly in the kitchen, or hallway, or -- if you were really late waking up -- your very own bedroom. Now that we're out of the house, March 15th means an early morning phone call from home, but it's lost none of it's potency.

Now you might be wondering why in the heck a security column should begin with the Ides of March. Or, even more interestingly, why it would begin with the Ides of March a week after the Ides of March.[1] Well, fear not, I'll get to the point.

I can't imagine what you might do should you be woken some morning to the retelling of the fall of an empire, but to me it reminds me that it's time to change my passwords. Most security folks suggest you change your passwords at least once or twice a year. One of the most frequently suggested times are the change to and from daylight savings time. But for me, it's the Ides of March.[2]

So what makes a bad password? Anything associated with you or your likes, desires, or quirks. Anything out of a dictionary in any language. The name of your relative, pet, significant other, favourite movie, phone number, birthday, or favourite colour. These things are either easy to guess if someone knows you, or are able to be cracked fairly easily by password guessing programs.

And most importantly, any password that you've used before is right out.

So what makes a good password? It depends somewhat on your password-hashing algorithm. Most new Linux installs use strong password-hashing algorithms such as MD5, which can take an infinite length password. Older installs used the traditional DES algorithm, which only allows 8 character passwords. It's best for you to ask your administrator which kind of hashing algorithm is used on the system before you choose a password.

If you are the administrator, it's not too hard to see which kind of hashing algorithm is the default. For example, change the password for jdoe and then do the following:

old_des_style# grep jdoe /etc/shadow
jdoe:m1kbsnKnULUKs:12133:0:99999:7:::
^^^^^^^^^^^^^
md5_style# grep jdoe /etc/shadow
jdoe:$1$e0/v1t9O$y/SxZxbiHsesW5HbeZRHq0:12133:0:99999:7:::
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

(I've underlined each password hash above with caret symbols to make it easier to see them.)

On the first host, the passwd program is configured to use the older DES-style password hashes. The password hash is the 13 character long string "m1kbsnKnULUKs". The second host uses MD5 hashing instead, as can be seen by much longer hash "$1$e0/v1t9O$y/SxZxbiHsesW5HbeZRHq0". There are other possible password hashing routines[3] but these are the two you're most likely to have available.

Continued @ Hacking Linux Exposed
Posted on Tuesday, 25 March 2003 @ 07:28:18 UTC by Paul (1048 reads)
[ Trackback ]
image

"Passwords: Everyone needs a good reminder about when it's time to change their passwords" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Linux.com
· HotScripts
· W3 Consortium
· More about Privacy
· News by Paul


Most read story about Privacy:
Ad-aware 6 Release from Lavasoft

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer