Hacking Passwords; Most Common Passwords&How long it takes to hack a Password
MOST COMMON PASSWORDS1. 1 More..23456, 123, 123123, 01234, 2468, 987654, etc COMMON EXTENSIONSSome sites force you to have passwords with both numbers and letters. For example bob's password is football, and the site asks him to add some numbers to it to make it valid. Here's what people usually add. The 10 most common passwordsNews broke that hackers had accessed the private Yahoo e-mail account of GOP vice presidential candidate Sarah Palin. They exposed a few innocuous e-mails, but the incident surely left many wondering whether the same thing could happen to them.
HOW LONG IT TAKES TO HACK A PASSWORDIf they have hacked and downloaded the entire database it's 10000 times faster than if they send requests guessing your passwords on certain websites. Most decent comps can check easily thousands possibilities per second. HOW HACKERS OBTAIN YOUR PASSWORDMost malicious hackers just wait for security update news. Whenever some forum or cms software like drupal, vbulletin, phpbb or invision board releases a security update, they try and find what the discovered exploit was. They google search for forums that may have the affected system and use the exploit. Forums can give tons of emails / passwords.
HOW ARE PASSWORDS STORED IN A WEBSITEMost are stored as md5 hashes. If your password is stored without encryption you are screwed if they get screwed. It doesn't matter how long your password is. Sites like thepiratebay and stage6 have gotten their passwords stolen, don't think it can't happen to big sites. You can tell if a site encrypts your password by using their password recovery form. If it gives you your password your password is not encrypted. If it asks you to enter a new one or it generates a password for you, it has your password encrypted. DANGERS OF MD5Sites like milw0rm and plain-text have millions, maybe billions of precomputed hash values in what are called rainbow tables. People can enter hashes in limited quantities to put on queue for cracking. md5 is a one-way hash, meaning it can't be decrypted. Instead, they try every possible combination in a limited range. Other sites are just searchable databases of hashes. You still should be ok if your pass is over 8 characters long. Some sites do double md5s or concatenate md5 encrypted passwords with an encrypted "salted" value, then encrypt the whole thing again. This prevents rainbow tables, but does not prevent brute force attacks. Brute force attacks use word lists separated by line breaks which are widely available around the net and can be easily created. WHAT IS HACKINGContrary to popular belief and the Hollywood culture, hackers are just people that can manipulate things on a bits and bytes level. They're excellent programmers and the majority do not engage in illegal activity. Making something do what it wasn't intended to is exploiting, not hacking.
|
| Similary articles: |
|---|
|





















Most people are clueless as to how accounts are hacked and their passwords reflect that. If you find anything in common with the most common passwords below you have a weak password. This is to help people choose a strong password and possibly help site admins understand the risks.
























![[8/5/2012] UN HQ: Bashar Al Jaafari kicks asses an View Video](http://img.youtube.com/vi/zWATzH3-XHU/default.jpg)

