Quantcast

Jump to content


Photo

warning about neoboards


  • Please log in to reply
54 replies to this topic

#26 silversun

silversun
  • 29 posts

Posted 20 October 2010 - 08:13 AM

Well, I guess on the bright side, if you find yourself on one, you know you're doing something right :p

#27 gemificus

gemificus
  • 149 posts

Posted 20 October 2010 - 08:22 AM

:o my password is password12....O_o


yes guys is was my poor excuse for a joke

#28 Boggart

Boggart
  • Professional Napper

  • 7981 posts


Users Awards

Posted 20 October 2010 - 08:33 AM

so poor it needs welfare LOL

:whistling:

#29 Gee

Gee
  • 498 posts

Posted 20 October 2010 - 09:07 AM

Luckily I have a complex password so no idiot can try to guess what my password is. >_>
I have a question, if you get cookie grabbed wouldn't they be able to access your personal PIN as well? Just a thought...

#30 sc4fps3

sc4fps3
  • 299 posts

Posted 20 October 2010 - 09:08 AM

Luckily I have a complex password so no idiot can try to guess what my password is. >_>
I have a question, if you get cookie grabbed wouldn't they be able to access your personal PIN as well? Just a thought...


That's not stored in your cookies, just on Neopets' servers.

#31 Lineage

Lineage
  • 498 posts

Posted 20 October 2010 - 09:36 AM

Good thing my email goes to my university and my password is seriously just random numbers and+ random capitalized and uncapitalized letters.

I used to have quite a problem with people trying to fuck with my account so I'm sure my account has been on these lists before.

#32 Boggart

Boggart
  • Professional Napper

  • 7981 posts


Users Awards

Posted 20 October 2010 - 09:47 AM

CG'ers don't get access to your info, just to your cookies. THus they can browse your account until your cookies expire.

#33 Noitidart

Noitidart
  • Neocodex Co-Founder

  • 23214 posts


Users Awards

Posted 20 October 2010 - 11:27 AM

This stuff is horrible. We don't allow this on our boards.

#34 Mishelle

Mishelle
  • Bitch Of The Boards

  • 2245 posts


Users Awards

Posted 21 October 2010 - 10:16 PM

I feel like my account is too crappy for them to even attempt to break in to mine but I'm going to change my password to something a little more secure just in case.

#35 luvsmyncis

luvsmyncis
  • I have no friends.

  • 6724 posts


Users Awards

Posted 22 October 2010 - 05:30 AM

A few people here know my account. It's not that impressive :p


That's what she said.

#36 Elindoril

Elindoril
  • Weeaboo Trash

  • 9254 posts


Users Awards

Posted 22 October 2010 - 06:30 AM

That's what she said.

About his account, or his Asian penis?

#37 Faval

Faval
  • 637 posts

Posted 22 October 2010 - 06:32 AM

JN and TDN are pretty safe :p IT's the people hacking them into hash lists that can't be trusted


Makes me wonder about the security of those sites if people can get into the database and get the hashed list of username and passwords.

#38 Boggart

Boggart
  • Professional Napper

  • 7981 posts


Users Awards

Posted 22 October 2010 - 07:07 AM

yes, lots of people here know about my Asian penis. It's not that impressive

#39 Philly

Philly
  • 402 posts

Posted 22 October 2010 - 07:36 AM

Makes me wonder about the security of those sites if people can get into the database and get the hashed list of username and passwords.


I thinkthey are pretty secure. havent heard of someone losing their account thanks to those sites yet.

#40 Waser Lave

Waser Lave

  • 25516 posts


Users Awards

Posted 22 October 2010 - 07:39 AM

I thinkthey are pretty secure. havent heard of someone losing their account thanks to those sites yet.


Actually I'd say people have lost hundreds, if not thousands, of accounts due to hash lists from those kind of sites...

#41 Boggart

Boggart
  • Professional Napper

  • 7981 posts


Users Awards

Posted 22 October 2010 - 07:48 AM

I thinkthey are pretty secure. havent heard of someone losing their account thanks to those sites yet.


I agree with laser. Someone told me that per every hash list of about 1000 names, about 100 would work. Sometimes more, sometimes less of course.

#42 Coilvect

Coilvect
  • 300 posts

Posted 22 October 2010 - 11:50 AM

IMO Passwords should contain %&$# if they're allowed.

#43 Elindoril

Elindoril
  • Weeaboo Trash

  • 9254 posts


Users Awards

Posted 22 October 2010 - 11:58 AM

IMO Passwords should contain %&$# if they're allowed.

Why so? A randomly generated password of both lower and upper case letters as well as numbers should be secure enough, depending on its length and complexity.

Really, no one is going to try and crack your account if they can just jump right into some idiots account with "justinbeiber" as their password or something.

#44 Waser Lave

Waser Lave

  • 25516 posts


Users Awards

Posted 22 October 2010 - 12:03 PM

Why so? A randomly generated password of both lower and upper case letters as well as numbers should be secure enough, depending on its length and complexity.

Really, no one is going to try and crack your account if they can just jump right into some idiots account with "justinbeiber" as their password or something.


20+ character length and you should be fine. :p

#45 Philly

Philly
  • 402 posts

Posted 22 October 2010 - 12:08 PM

Actually I'd say people have lost hundreds, if not thousands, of accounts due to hash lists from those kind of sites...

Sorry to be so ignorant but what's a hash list?

#46 Faval

Faval
  • 637 posts

Posted 22 October 2010 - 12:10 PM

Sorry to be so ignorant but what's a hash list?


It's basically like a encrypted version of the password if you will. Databases usually store the password in an encrypted forum using whatever keys they have setup in their configuration.

I'm not sure how long it would take to crack what the key is and decrypt the data but some people have a lot of time on their hands.

So let's say the database here stores my password as 7C4A8D09CA3762AF61E59520943DC26494F8941B or something arbitrary like that. Once you know the algorithm for decrypting it, they have my password.

Edited by Faval, 22 October 2010 - 12:13 PM.


#47 Coilvect

Coilvect
  • 300 posts

Posted 22 October 2010 - 12:13 PM

In a nut shell hash lists are a list of data blocks in a file or a set. Its usually encrypted with SHA-1 encryption.

#48 Waser Lave

Waser Lave

  • 25516 posts


Users Awards

Posted 22 October 2010 - 12:16 PM

In a nut shell hash lists are a list of data blocks in a file or a set. Its usually encrypted with SHA-1 encryption.


They're usually MD5.

#49 Faval

Faval
  • 637 posts

Posted 22 October 2010 - 12:40 PM

They're usually MD5.


Yeah since that seems to be the default for php settings. SHA1 is probably the default setting if you're using a .Net build.

#50 iargue

iargue
  • 10048 posts


Users Awards

Posted 22 October 2010 - 01:10 PM

20+ character length and you should be fine. :p



Using 1 letter is probably the best. Most crackers just start at 4 letters and continue from there. :).


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users