Passwords

Live forum: http://forum.freeipodguide.com/viewtopic.php?t=16885

Admin

17-06-2005 14:21:46

I was bored just now so I decided to run a quick check on the forum database


Showing rows 30 - 58 (59 total, Query took 0.0439 sec)
SQL-query [Edit] [Explain SQL] [Create PHP Code]
SELECT li
FROM `phpbb_users`
WHERE 1 AND `user_password`
LIKE '5f4dcc3b5aa765d61d8327deb882cf99' LIMIT 30 , 30


"5f4dcc3b5aa765d61d8327deb882cf99" is the md5sum for 'password'.

What this means is, 59 users on here use 'password' as their password.

For christ's sake, people, PLEASE CHANGE YOUR PASSWORD TO SOMETHING SECURE.

I'm just going to ban people who use 'password' and 'secret' and 'sex' as their passwords from now on, for the sake of forum security.

cartrenroy

17-06-2005 14:23:06

So you can check the password that people uses


[quote80ef112cda="Admin"]I was bored just now so I decided to run a quick check on the forum database


Showing rows 30 - 58 (59 total, Query took 0.0439 sec)
SQL-query [Edit] [Explain SQL] [Create PHP Code]
SELECT li
FROM `phpbb_users`
WHERE 1 AND `user_password`
LIKE '5f4dcc3b5aa765d61d8327deb882cf99' LIMIT 30 , 30


"5f4dcc3b5aa765d61d8327deb882cf99" is the md5sum for 'password'.

What this means is, 59 users on here use 'password' as their password.

For christ's sake, people, PLEASE CHANGE YOUR PASSWORD TO SOMETHING SECURE.

I'm just going to ban people who use 'password' and 'secret' and 'sex' as their passwords from now on, for the sake of forum security.[/quote80ef112cda]

Admin

17-06-2005 14:28:25

No, I can't. If I already know a password, I can generate an md5sum for it, and then check if that's in the database. I can't go backwards from an md5 in the database to a cleartext password (at least not without a crazy amount of time and computing power).

theysayjump

17-06-2005 14:39:17

[quote20539bf9e2="Admin"]I was bored just now so I decided to run a quick check on the forum database


Showing rows 30 - 58 (59 total, Query took 0.0439 sec)
SQL-query [Edit] [Explain SQL] [Create PHP Code]
SELECT li
FROM `phpbb_users`
WHERE 1 AND `user_password`
LIKE '5f4dcc3b5aa765d61d8327deb882cf99' LIMIT 30 , 30


"5f4dcc3b5aa765d61d8327deb882cf99" is the md5sum for 'password'.

What this means is, 59 users on here use 'password' as their password.

For christ's sake, people, PLEASE CHANGE YOUR PASSWORD TO SOMETHING SECURE.

I'm just going to ban people who use 'password' and 'secret' and 'sex' as their passwords from now on, for the sake of forum security.[/quote20539bf9e2]

lmao.....thats funny yet sad at the same time (

now that youve posted this, do you think that people will probably try logging into other peoples accounts with those passwords now?

slease

17-06-2005 14:47:34

my pass isn't that one of course, but i'm going to change my password for good measure. everyone should do the same, at least if you have a high TR.

Admin

17-06-2005 16:23:41

Excellent advice.

Collateral

17-06-2005 16:25:51

Password!! HAHAHAHAHAHAHAHAH!!!!!!!

Peksim

17-06-2005 16:27:10

lichanges password from 1-2-3-4-5-6-7-8-9"

LOL...

EatChex89

17-06-2005 17:59:25

my password is one i know. but can probably be guessed

FreeOffersNow

17-06-2005 18:44:58

[quote67daa3f174="EatChex89"]my password is one i know. but can probably be guessed[/quote67daa3f174]

Really? You know your password? Interesting... http//www.freeipodguide.com/phpBB2/smilies_mod/upload/c791773df4d421ae16ec15be17048000.gif[" alt=""/img67daa3f174]

bballp6699

17-06-2005 18:56:58

My password is monkey.
















Just kidding fuckers.

Yeah, I definatley wouldn't keep the same password on this site as any other boards. Some board types don't have encrypted passes.

FreeOffersNow

17-06-2005 19:54:08

[quote3942129b20="bballp6699"]Some board types don't have encrypted passes.[/quote3942129b20]


licoughliinvisionlicough

theysayjump

17-06-2005 20:26:28

since im a foriegner i have to give all my passwords to the INS

when i applied for my I-485 and I-130, i had to give them my e-mail address, they sent me an e-maila nd now theres a secure site with logon info for me...i go in and have to put my passwords in to any new sites ive signed up at.

its shit being constantly monitored but i dont really have a choice. (

slease

17-06-2005 20:29:26

[quote6c5dab18fa="theysayjump"]since im a foriegner i have to give all my passwords to the INS

when i applied for my I-485 and I-130, i had to give them my e-mail address, they sent me an e-maila nd now theres a secure site with logon info for me...i go in and have to put my passwords in to any new sites ive signed up at.

its shit being constantly monitored but i dont really have a choice. ([/quote6c5dab18fa]

is this a new thing or part of the patriot act? that is bullshit, i'm sorry our country is retarded like that.

theysayjump

17-06-2005 21:08:22

i should probably stop before it gets out of control.

i just made it up (

but they did ask for my e-mail addy thats about as far as it went though.

sorry, my bad lol.

FreeOffersNow

17-06-2005 21:11:48

[quotea8363bf0ed="slease"]is this a new thing or part of the patriot act? that is bullshit, i'm sorry our country is retarded like that.[/quotea8363bf0ed]


You moron. lol

theysayjump

17-06-2005 21:13:11

lol

slease

17-06-2005 21:26:35

lol, well it sounds like something that would be part of the Patriot Act doesn't it?

theysayjump

17-06-2005 21:28:00

lol yeah it does actually.

Retro

17-06-2005 21:52:23

[quote4452426840="theysayjump"]
now that youve posted this, do you think that people will probably try logging into other peoples accounts with those passwords now?[/quote4452426840]

That means they would have to try to log in as all of fig's 4812 members

theysayjump

17-06-2005 21:54:16

i just meant people trying it randomly.