View Single Post
Old 04-10-2007, 12:59 PM  
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Quote:
Originally Posted by rotowa85 View Post
blocking ip addresses is pointless, any good hacker will be using proxies.
Indeed, which is why you block those proxies using something like Strongbox.

Quote:
Originally Posted by rotowa85 View Post
i also think its a bad idea to pick peoples passwords for them,
Any reason for that? If you DON'T choose their passwords for them, a suprisingly
large number will choose the word "password" as their password. Another large
percentage will make their password the same as their user name and their user name
is easy to get.

Quote:
correct me if im wrong but i think ccbill uses computer generated usernames and passwords.
It can be set to generate user names and passwords, random ones that suck.
It can also be set to use GOOD user names and passwords generated by our tool.

Quote:
and the fact is that if you can get hold of and a ccbill log file (which isnt very difficult from
some sites) and decrypt it (which isnt very difficult) you get access not only to all the passwords for that site but to the format that the usernames and passes are in which makes creating a username:password list alot easier.
Kind of close, but no. The CCBill log doesn't include the password and it's not encrypted.
Also this has nothing at all to do with choosing the user's password for them, BTW.
The CCBill log and other files are IDENTICAL whether the user chooses the password,
the password is random characters assigned by CCBill, or it's a good password genertaed
by our tool.
What you're thinking of is the password file, .htpasswd, which every password protected
site has. A very few sites store the list in a database rather than a file, but that makes
no difference becuse they are both just about equally readable. Way back in the day
the passwords in the password file used to be encrypted using a type of encryption called DES,
which can now be cracked in seconds. CCBill and the other processors all still use DES
as the default and make it easy for a cracker to get most of your passwords. We routinely
update the scripts that the processor's give you to use a much stronger type of encryption
called "salted MD5".
More info about all of this can be found on this page:
http://bettercgi.com/strongbox/passgen/
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote