-Whiteroom-
Pineapplewhat
+572|6660|BC, Canada
"youwantmyshityoucanthaveit" seems pretty secure. But like rdx-fx said, who here actually put their real password in there. I'm no ATG but I'm far to paranoid for that.
Finray
Hup! Dos, Tres, Cuatro
+2,629|5790|Catherine Black
It's JavaScript... Don't be so paranoid.
https://i.imgur.com/qwWEP9F.png
GC_PaNzerFIN
Work and study @ Technical Uni
+528|6416|Finland

Finray wrote:

It's JavaScript... Don't be so paranoid.
I have a friend highly skilled with JS. You'd be surprised what you can do with it.

But it is not my problem if you absolutely must give your passwords to total strangers. Besides, if you are unsure the password is good, then its not. Change it and never tell it to anyone.

Last edited by GC_PaNzerFIN (2010-10-17 13:31:18)

3930K | H100i | RIVF | 16GB DDR3 | GTX 480 | AX750 | 800D | 512GB SSD | 3TB HDD | Xonar DX | W8
mtb0minime
minimember
+2,418|6656

anywhere from 5 hours to 3 days
mtb0minime
minimember
+2,418|6656

Also, ban Finray and remove his Tech badge. We shouldn't be doing this
13urnzz
Banned
+5,830|6499

mtb0minime wrote:

Also, ban Finray and remove his Tech badge. We shouldn't be doing this
[HOF]Mercenary
o_O
+53|6180
It would take
About 7 septillion years
for a desktop PC to crack your password

wtf is a septillion. Also yay for college passwords.
Finray
Hup! Dos, Tres, Cuatro
+2,629|5790|Catherine Black
My college password would take 3 days to crack lol.
https://i.imgur.com/qwWEP9F.png
Zimmer
Un Moderador
+1,688|6758|Scotland

GC_PaNzerFIN wrote:

Finray wrote:

It's JavaScript... Don't be so paranoid.
I have a friend highly skilled with JS. You'd be surprised what you can do with it.

But it is not my problem if you absolutely must give your passwords to total strangers. Besides, if you are unsure the password is good, then its not. Change it and never tell it to anyone.
Then your friend ain't too smart either.

The script he's using can't submit anything or harvest it. There is no server-sided javascript in any of the code.

The site is perfectly safe to use with your actual passwords.

It's perfectly safe.
rdx-fx
...
+955|6593

GC_PaNzerFIN wrote:

Finray wrote:

It's JavaScript... Don't be so paranoid.
I have a friend highly skilled with JS. You'd be surprised what you can do with it.

But it is not my problem if you absolutely must give your passwords to total strangers. Besides, if you are unsure the password is good, then its not. Change it and never tell it to anyone.

Zimmer wrote:

Then your friend ain't too smart either.

The script he's using can't submit anything or harvest it. There is no server-sided javascript in any of the code.

The site is perfectly safe to use with your actual passwords.

It's perfectly safe.
And if the route to the "perfectly safe" javascripted site is compromised?

If there is only one route into the server, a bit of fairly mundane packet sniffing on the hop just before the "perfectly safe" server would net a bunch of passwords transmitted in the clear.  Easy enough to sniff the wire without even showing a hop in a traceroute, with a Receive-Only Cable or an old hub.

"It's perfectly safe" is right up there with "Hold my beer and watch this!" in the Famous Last Words Hall of Fame.

It may be a bit of harmless educational fun, it may be a scam.  Smells like Social Engineering to me, so I'll pass.
Your call what you do with your passwords.

Last edited by rdx-fx (2010-10-17 16:58:39)

rdx-fx
...
+955|6593
"SocialEngineeringForFunAndProfit" as a password would take "About 9,571,860 nonillion years"
mtb0minime
minimember
+2,418|6656

Funnily enough, my AIM password is the most secure and would take about 204,000 years to crack.

Guess I'll start changing everything to that one. Oh wait, I already input it.

Better test a different one.

Ok, got one that'll take 300 million years. Oh wait, I already input it.

Better test a different one...
Morpheus
This shit still going?
+508|6001|The Mitten
i like big butts and I cannot lie
takes about 9,571,860 brazillion years
EE (hats
Morpheus
This shit still going?
+508|6001|The Mitten
Fuck Yo Couch only takes 7 thousand years....
EE (hats
FEOS
Bellicose Yankee Air Pirate
+1,182|6412|'Murka

I've seen too much scary stuff done with "client-side only" (wink-wink) JS to say "sure, I'll go ahead and put in my password to this random site I found on the internet because their faq says it's safe and I can see their JS is client only".

That's fucking nuts, from a security perspective.
“Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid.”
― Albert Einstein

Doing the popular thing is not always right. Doing the right thing is not always popular
unnamednewbie13
Moderator
+2,053|6773|PNW

252 years for my simplest.

About 1,341,374 nonillion years for my wireless network key.

(e: I used similar password format, not the actual passwords.)
killer21
Because f*ck you that's why.
+400|6592|Reisterstown, MD

It would take

About 564 billion years

for a desktop PC to crack your password
.:ronin:.|Patton
Respekct dad i love u always
+946|6811|Marathon, Florida Keys
whatwhatinthebutt takes 138 million lolz
https://i54.photobucket.com/albums/g117/patton1337/stats.jpg
Camm
Feeding the Cats.
+761|4970|Dundee, Scotland.

Code:

[quote=ig]wat[/quote]
takes about a quadrillion years

Last edited by Camm (2010-10-18 08:17:22)

for a fatty you're a serious intellectual lightweight.
Zimmer
Un Moderador
+1,688|6758|Scotland

rdx-fx wrote:

GC_PaNzerFIN wrote:

Finray wrote:

It's JavaScript... Don't be so paranoid.
I have a friend highly skilled with JS. You'd be surprised what you can do with it.

But it is not my problem if you absolutely must give your passwords to total strangers. Besides, if you are unsure the password is good, then its not. Change it and never tell it to anyone.

Zimmer wrote:

Then your friend ain't too smart either.

The script he's using can't submit anything or harvest it. There is no server-sided javascript in any of the code.

The site is perfectly safe to use with your actual passwords.

It's perfectly safe.
And if the route to the "perfectly safe" javascripted site is compromised?

If there is only one route into the server, a bit of fairly mundane packet sniffing on the hop just before the "perfectly safe" server would net a bunch of passwords transmitted in the clear.  Easy enough to sniff the wire without even showing a hop in a traceroute, with a Receive-Only Cable or an old hub.

"It's perfectly safe" is right up there with "Hold my beer and watch this!" in the Famous Last Words Hall of Fame.

It may be a bit of harmless educational fun, it may be a scam.  Smells like Social Engineering to me, so I'll pass.
Your call what you do with your passwords.
You don't seem to understand that there is no "route". That page is static and all that you see there is being rendered by your browser. Absolutely nothing on that page is server side. So however much you like your lovely little theory, it's totally and utterly pointless for this. You aren't submitting anything, nothing is getting parsed by the server, the server isn't taking note of your keystrokes. And no, you cannot "hide" a file into the JS or HTML and hope that nobody sees it whilst it sends data to the server. The fact is that that page could be rendered on your computer, my computer, a server and it wouldn't be able to do anything. There is no server side ANYTHING.

Lovely little theory though, too bad it's total bollocks for the site at hand.
GC_PaNzerFIN
Work and study @ Technical Uni
+528|6416|Finland

It doesn't just magically appear in your browser, claiming there is nothing on server side implicates that would be the case.

As much as you don't want to believe it, but JS is far from 100% vulnerability free magic land, client side included.

First you willingly type your password on totally stranger site, then you claim you cannot exploit client side JS.... That is ridicule, in which world you lived again?
3930K | H100i | RIVF | 16GB DDR3 | GTX 480 | AX750 | 800D | 512GB SSD | 3TB HDD | Xonar DX | W8
Zimmer
Un Moderador
+1,688|6758|Scotland

GC_PaNzerFIN wrote:

It doesn't just magically appear in your browser, claiming there is nothing on server side implicates that would be the case.

As much as you don't want to believe it, but JS is far from 100% vulnerability free magic land, client side included.

First you willingly type your password on totally stranger site, then you claim you cannot exploit client side JS.... That is ridicule, in which world you lived again?
One that knows more about JS than you do.

Sorry, but it's not about believing. JS doesn't suddenly spring legs and start communicating with the server. However much your paranoid world thinks it can.
13urnzz
Banned
+5,830|6499

i'm with Panzer on this one.

by all means, you type your passwords where you will, just don't be disappointed if i don't.
13urnzz
Banned
+5,830|6499

Zimmer wrote:

JS doesn't suddenly spring legs and start communicating with the server. However much your paranoid world thinks it can.
ok mr. java-can-do-no-wrong, if you trust this site so much, what is your password?
Zimmer
Un Moderador
+1,688|6758|Scotland

burnzz wrote:

Zimmer wrote:

JS doesn't suddenly spring legs and start communicating with the server. However much your paranoid world thinks it can.
ok mr. java-can-do-no-wrong, if you trust this site so much, what is your password?
Javascript*

I never said it can do no wrong, but I checked it and there's no linking to an external file that can read your parse what is being typed or a text file they're getting put into. Of course you can set up Javascript to do just that, but in this case it's harmless.

My password on that site?
"About 42 trillion years".

I'll come back to you when they hack all my gmail accounts and Paypal accounts.

Board footer

Privacy Policy - © 2024 Jeff Minard