Jonathan (jon3) wrote,

Idle hands ARE the Devil's Plaything.

So I wrote a perl program to crack the password file at a certain school I won't name. They use a really moronic scheme for password generation. Basically, your username is first letter of first name, then the first x letters of your last name followed by some number. (not sure how they end up deriving the last part).

Anyway, the password scheme is: [first letter of first name][first letter of last name] then the last 4 digits of your SSN. Since you know the first and last name's letters, all you have to do is dictionary-attack 10,000 times and you're done.

20 lines of perl and a half hour later (I'm a sucky coder) 84% of the [non-disabled] passwords cracked. A simple Crack 5.0 dictionary run gave me another 11 %. Yup, 95% of the passwords total, including somebody in Wheel, and 2 professors. That doesn't even count the weakness in my program: I couldn't figure out how to munge my counter to display 0000-9999 so it starts at 1000. There's probably another few % that I could have cracked. I didn't even use a fast unix box to do the work, it was a doorstop SS5/170 (obsd 3.1) that did it all in 10 seconds.

No, I didn't abuse it! I'd mail the admins at the College, but I have heard too many horror stories of people doing the Right Thing and then being snooped on, mail read, various invasions of privacy, or worse, getting tossed out. So, I'll just keep my work offsite and wait for some bozo to destroy them and they learn the hard way.

  • For those not yet in the know....

    Last night, Missy and I got engaged! I took her out to Bricco in the North End, for our 3rd Valentine's day in a row. Our first date was there. 2…

  • Heartbeat post...

    Yeah, I've still got one, and I know that I don't update for shit these days, so here goes. Things are generally good. I'm feeling positive. Things…

  • I went permanent

    So I've got 273 paid days. Who wants em?

  • Post a new comment


    default userpic

    Your IP address will be recorded 

    When you submit the form an invisible reCAPTCHA check will be performed.
    You must follow the Privacy Policy and Google Terms of use.