| | |
Passwords
![]() |
recently i have been researching social engineering and have chosen to write a bit on how companie policies on passwords, the up keep of them and sharing of them.
i have already written on the do's and dont's for keeping your password e.g.. Don't reveal a password in an email message. But want to look more into how users remember there passwords eg memory techniques and how companies view these techniques etc..
i have already written on the do's and dont's for keeping your password e.g.. Don't reveal a password in an email message. But want to look more into how users remember there passwords eg memory techniques and how companies view these techniques etc..
I wrote some info here: http://www.daniweb.com/blogs/blog270061.html
Michael
Forensic IT Consultant / Designer | My DaniWeb Blog
Quis custodiet ipsos custodes?
Forensic IT Consultant / Designer | My DaniWeb Blog
Quis custodiet ipsos custodes?
•
•
Join Date: Nov 2003
Posts: 4
Reputation:
Solved Threads: 0
Funny you talk about this. I recent attended a week long course sponsored by the EC-Council on Certified Ethical Hacking, one of the big points was just this. Basically we learned that you can weasel information that is very sensitive from almost anyone in a company, including people who should know better. To give an example, our teacher had me call the office we were attending class to try and get the network admins name gateway ips or anything that would be useful to hack in. Mind you the person I talked to was one of his best friends. By simply calling and saying:
"I'm Daniel from microsoft, Chad and I were working on a problem with your firewall and I want to check if the problem is solve. Can you run tracert microsoft.com for me and read off the output until i say stop."
Of course since I said I was from microsoft he did it and gave me their internal ip structure as well as their gateway and service provider ips. Basically everything I needed to get started.
Another technique is to find Ex-employees. If they were fired or even some who quit can be very open about the companies technologies such as passwords or more. If they were a network admin, maybe their account wasn't even disabled or removed?
Other methods are simple. Our college gives all students an initial password of their student id number. Which can be found on any students ID. So that's not very secure. My passwords are all common words or names that mean something to me, but with changes. Maybe I use LEET speak on one password like this: r@g0u7 = ragout
Another good method is appending and prepending. Say my password is mydog i could make it more secure by doing this:
843myd0g911
Two things i can remember, areacode, and 911. Then leet speak the password and it's harder.
most people pick either passwords that mean something to them, not just random ones like I prefer to do. childs names, their name, a picture on their desk, a phone number. Things like that. The best password should be about 14 characters long, leet speak and completely random. I have use things that just happened to be in the room. I've done Procell cause a Procell battery was there or DeadEyes cause a book named that was there.
Hope that helped. If you want any more, I could do more on social engineering overall and not just based to passwords
"I'm Daniel from microsoft, Chad and I were working on a problem with your firewall and I want to check if the problem is solve. Can you run tracert microsoft.com for me and read off the output until i say stop."
Of course since I said I was from microsoft he did it and gave me their internal ip structure as well as their gateway and service provider ips. Basically everything I needed to get started.
Another technique is to find Ex-employees. If they were fired or even some who quit can be very open about the companies technologies such as passwords or more. If they were a network admin, maybe their account wasn't even disabled or removed?
Other methods are simple. Our college gives all students an initial password of their student id number. Which can be found on any students ID. So that's not very secure. My passwords are all common words or names that mean something to me, but with changes. Maybe I use LEET speak on one password like this: r@g0u7 = ragout
Another good method is appending and prepending. Say my password is mydog i could make it more secure by doing this:
843myd0g911
Two things i can remember, areacode, and 911. Then leet speak the password and it's harder.
most people pick either passwords that mean something to them, not just random ones like I prefer to do. childs names, their name, a picture on their desk, a phone number. Things like that. The best password should be about 14 characters long, leet speak and completely random. I have use things that just happened to be in the room. I've done Procell cause a Procell battery was there or DeadEyes cause a book named that was there.
Hope that helped. If you want any more, I could do more on social engineering overall and not just based to passwords
![]() |
Similar Threads
- Hard Drive Passwords (Storage)
- passwords (Web Browsers)
- What software prevent sending my passwords to the Internet? (Viruses, Spyware and other Nasties)
- Passwords (OS X)
- Transfer Linux passwords (*nix Software)
- AutoComplete does not promt to save passwords for IE (Web Browsers)
- Forgot passwords, can data be copied ?? (Windows NT / 2000 / XP)
Other Threads in the IT Professionals' Lounge Forum
- Previous Thread: VLAN communication troubles
- Next Thread: Keylogger help
| Thread Tools | Search this Thread |
1gbit advertising advice amazon answers archive british broadband business businessprocesses career carrier censorship cern china cio collectiveintelligence connectivity consumer consumers corporateearnings datatransfer debtcollectors dictionary digg digital ebay ecommerce email employment environment facebook food government grid high-definition hottub infodelivery infotech intel internet interview ipod isp japan kindle lhc library malware marketing mit moonfruit news onlineshopping piracy piratebay pope porn program questions r&d religion remoteworking research retail security sex shopping simple skype smallbusiness smb sms socialmedia socialnetworking software softwareengineer spam speed spending startrek statistics stocks study stumbleupon survey tabletpc technology touch-screen touchscreen twitter uk videoinprint voips web webdeveloper windows words






