Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-24-2004, 01:31 PM   #1
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
How to create strong password for your admin areas and such

Obviously, you want your admin areas and other important stuff to be secure. So, you need a strong password. Preferably something long, and at the very least containing numbers as well as letters. The only problem with this is that you'll never be able to remember it... and keeping it on your pc can be rather insecure, as well as extremely annoying if your hd dies or you lose the file it's in.

So, just take something that is easy to remember (for you), and hash it using md5, sha-1 or something similar. You'll get a password that will be hella-hard to break for crackers, but you'll easily be able to get it any time you want. Just remember to keep your encryption app/page somewhere handy
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 01:42 PM   #2
Freakster
Confirmed User
 
Join Date: Jul 2002
Location: Montreal
Posts: 833
that's pretty smart
__________________
174-38-56
Freakster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 01:47 PM   #3
pamphage
Confirmed User
 
Join Date: Jan 2003
Location: Hollywood, CA
Posts: 3,569
Quote:
Originally posted by punkworld
Obviously, you want your admin areas and other important stuff to be secure. So, you need a strong password. Preferably something long, and at the very least containing numbers as well as letters. The only problem with this is that you'll never be able to remember it... and keeping it on your pc can be rather insecure, as well as extremely annoying if your hd dies or you lose the file it's in.

So, just take something that is easy to remember (for you), and hash it using md5, sha-1 or something similar. You'll get a password that will be hella-hard to break for crackers, but you'll easily be able to get it any time you want. Just remember to keep your encryption app/page somewhere handy
good idea. i've been meaning to stop using 123abc anyway
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR.
Unless your sig is for a GFY top banner sponsor, you may use a 624x80 instead of a 120x60.
Let me repeat... A 120 x 60 button and no more that 3 lines of DEFAULT SIZE AND COLOR text.
pamphage is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 01:51 PM   #4
beemk
CLICK HERE
 
Industry Role:
Join Date: Jan 2002
Posts: 20,829
sending this page to the password boards....
__________________
I host with Vacares
beemk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 02:05 PM   #5
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
Quote:
Originally posted by beemk
sending this page to the password boards....
Go ahead. It won't make it much easier to brute force a 32 character string (like md5), and there are quite a few different encoding algos out there, so to get them all they'd have to create even huger password lists... up to the point where using a list takes almost as much time as brute forcing


Another tip, for very inexperienced programmers: if you store passwords in a database, don't store passwords in plain text form. Instead, use a one way hash like md5. If people lose their password, resend them a reset random password, which they can change again in their accounts.
This way, if your database ever gets compromised, the stupid ones among your customers (i.e. the ones that use a single password for all their stuff) have less chance of getting screwed - and blaming you, because you were the one that leaked their password.
(ofcourse crackers can still run wordlists against the hashes and have a fairly good chance of finding weak passes that way, but it's better than nothing)
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 02:07 PM   #6
JOKER
Facit Omnia Voluntas
 
JOKER's Avatar
 
Industry Role:
Join Date: Apr 2003
Location: Offshore
Posts: 2,105
Good Idea,thanx 4 sharing


Take care,
JOKER
__________________
Facilitation - BizDev - Traffic - Consulting - Marketing
Skype: jokerempire | Silent Circle: joker

JOKER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 02:09 PM   #7
Paul Waters
Confirmed User
 
Paul Waters's Avatar
 
Join Date: Mar 2003
Location: Toronto, Ontario
Posts: 4,402
I use cock10in

Very secure, and easy to remember.
__________________


Paul
Paul Waters is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 02:12 PM   #8
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
Quote:
Originally posted by punkworld
(ofcourse crackers can still run wordlists against the hashes and have a fairly good chance of finding weak passes that way, but it's better than nothing)
Which brings me to the next tip...
If you have any type of protected area for which people can choose their own passes, you should keep a wordlist. Just rip a big one from one of the password forums, and try to keep it up to date.

Make your script check every new username password against the wordlist, and if it's in there, give the person signing up a "username (or password) already exists"-error.

That way, most wordlists will be useless against your sites, and crackers have way less of a chance of getting in
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 02:13 PM   #9
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
Quote:
Originally posted by Paul Waters
I use cock10in

Very secure, and easy to remember.
But since you probably wouldn't post your password on this board, I suppose the real one is slightly different? Something like cock4in maybe?
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 02:20 PM   #10
Calvinguy
Confirmed User
 
Join Date: Oct 2002
Location: European Union
Posts: 1,752
I feel like adding....


As a common rule you never make a username casesensitive but passwords should always be casesensitive.
Calvinguy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2004, 02:46 PM   #11
Paul Waters
Confirmed User
 
Paul Waters's Avatar
 
Join Date: Mar 2003
Location: Toronto, Ontario
Posts: 4,402
Quote:
Originally posted by punkworld


But since you probably wouldn't post your password on this board, I suppose the real one is slightly different? Something like cock4in maybe?
It is really cock14in, but if I posted that, I would get shit for braggin'
__________________


Paul
Paul Waters is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.