As you are undoubtedly aware of by now, two weeks ago the
professional networking site LinkedIn became the victim of a rather unfortunate
mishap: they sprung a little leak, and 6.4 million password hashes trickled out
onto the internet. And in those two short weeks, hundreds of security experts
the world over, all of various backgrounds whose hats range from white to
black, have been feverishly clawing their way through that list in an attempt
to crack all 6.4 million passwords. However, few have made more progress in
their pursuit than my associate d3ad0ne and me.
Saturday, June 30, 2012
Thursday, June 28, 2012
Linkedin Password Infographic
| [ Oh yeah, you can click it for *full* size! Free to use, please show credits. ] |
Jeremi Gosney (@jmgosney) have done a terrific job on cracking the Linkedin hashes. In fact, he has cracked some 90% of them now. So I asked Jeremi if I could ask one of my UX colleagues to try to make an infographic, he happily agreed. The result can be seeen in all its glory from the above supersize infographic (Print it if you like!)
Wednesday, May 30, 2012
Analyzing PIN codes
![]() |
| [ A load of PIN codes visualized ] |
According to Norwegian privacy laws, we didn't request and didn't get any ownership information on each PIN, so they cannot be traced back to individual users.
Now you may ask why did we do this?
Monday, May 21, 2012
Live Memory Password Aquisition
![]() |
| [ Screenshot of Passware Kit Forensic ] |
Lets take a look at these new features from a threat/risk perspective:
Saturday, May 19, 2012
Note to self: Inception + Ubuntu 12.04LTS
If you want to get inception up and running on (default config) Ubuntu 12.04LTS, you should expand your dependencies installation like this (adding juju, doxygen and g++):
sudo apt-get install git cmake python3 doxygen g++ juju
Now go ahead with the rest of the installation. :-)
sudo apt-get install git cmake python3 doxygen g++ juju
Now go ahead with the rest of the installation. :-)
Thursday, May 10, 2012
Forbud mot skimmingutstyr
![]() |
| [Klikk på bildet for full størrelse] |
Monday, May 07, 2012
Challenge received
![]() |
| [Picture from lego.com - I'm a Star Wars fan!] |
"Accept the challenge I do, your Highness". (Yoda, Star Wars)
Kirsi Helkala gave presentations at both Passwords^10 and Passwords^11. Her work on passwords is fascinating, now working as a associate professor at Gjøvik University College in Norway. See her list of publications to understand what I'm talking about. She has given me a challenge - nine in fact - all being unsalted MD5s. I need help! :-)
FY til Adecco!
I forrige uke var jeg muligens litt småtøff i kjeften da jeg la ut en melding på Twitter angående Adecco (Norge), med link til testresultater fra SSLLabs. La meg bare si med en gang at @AdeccoNorge har svart, så jeg går ut i fra at de tar dette seriøst.
Saturday, May 05, 2012
Countermail - protecting your privacy?
Due to some media coverage lately, I got curious and had to take a look at the Swedish service Countermail. It seems to go far and beyond services like hushmail in order to protect your privacy, at least that's my impression from their service description. Not that I have a habit of trusting marketing talk of course, but they do have some pretty tough claims at their site.
Now I do like to look for logical errors, mistakes etc., but I am not a pentester anymore. I'll leave Backtrack and that sort of stuff to the younger generation. :-) So here are just a few simple comments on their service offerings, after playing around for an hour or so:
Monday, April 23, 2012
Note to self: Google Authenticator + oneiric
install Google-Authenticator app on whatever device you prefer
Then you do this on Ubuntu 11.10 (oneric):
git clone https://code.google.com/p/google-authenticator/
install libqrencode library
install libpam0g-dev
cd google-authenticator
sudo make install
run google-authenticator
Time-based tokens: Y
Scan the QR code you get up on screen with your authenticator app
Update .google-authenticator file: Y
Disallow use of same authentication token: Y
Increase window for time-skew: N
Rate-limiting: Y
insert auth required pam_google_authenticator-so into your /etc/pam.d/sshd file
sudo restart ssh
go.
Then you do this on Ubuntu 11.10 (oneric):
git clone https://code.google.com/p/google-authenticator/
install libqrencode library
install libpam0g-dev
cd google-authenticator
sudo make install
run google-authenticator
Time-based tokens: Y
Scan the QR code you get up on screen with your authenticator app
Update .google-authenticator file: Y
Disallow use of same authentication token: Y
Increase window for time-skew: N
Rate-limiting: Y
insert auth required pam_google_authenticator-so into your /etc/pam.d/sshd file
sudo restart ssh
go.
Subscribe to:
Posts (Atom)








