Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Making an account on something today when I came across a novel to me password restriction

Making an account on something today when I came across a novel to me password restriction

Scheduled Pinned Locked Moved Uncategorized
6 Posts 6 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • benjojo@benjojo.co.ukB This user is from outside of this forum
    benjojo@benjojo.co.ukB This user is from outside of this forum
    benjojo@benjojo.co.uk
    wrote last edited by
    #1

    Making an account on something today when I came across a novel to me password restriction

    Link Preview Image
    1 Reply Last reply
    2
    0
    • R relay@relay.infosec.exchange shared this topic
    • flesh@transfem.socialF This user is from outside of this forum
      flesh@transfem.socialF This user is from outside of this forum
      flesh@transfem.social
      wrote last edited by
      #2

      @benjojo@benjojo.co.uk Please explain to the Python developer (me).

      gladtherescake@todon.nlG 1 Reply Last reply
      0
      • flesh@transfem.socialF flesh@transfem.social

        @benjojo@benjojo.co.uk Please explain to the Python developer (me).

        gladtherescake@todon.nlG This user is from outside of this forum
        gladtherescake@todon.nlG This user is from outside of this forum
        gladtherescake@todon.nl
        wrote last edited by
        #3

        @flesh @benjojo The $ is a unix crypt hash symbol, which indicates the string that follows is an encrypted password string. If the password were to be stored in say plain text, the program to check the password might infer some things about the password that are untrue if it starts with a $ and always error out since it's comparing what it thinks is a hash to a plaintext of the password, and they don't match. One might reasonably assume from this that this restriction is in place because they do indeed save the passwords as plain text...

        leeloo@c.imL 1 Reply Last reply
        0
        • gladtherescake@todon.nlG gladtherescake@todon.nl

          @flesh @benjojo The $ is a unix crypt hash symbol, which indicates the string that follows is an encrypted password string. If the password were to be stored in say plain text, the program to check the password might infer some things about the password that are untrue if it starts with a $ and always error out since it's comparing what it thinks is a hash to a plaintext of the password, and they don't match. One might reasonably assume from this that this restriction is in place because they do indeed save the passwords as plain text...

          leeloo@c.imL This user is from outside of this forum
          leeloo@c.imL This user is from outside of this forum
          leeloo@c.im
          wrote last edited by
          #4

          @GLaDTheresCake @flesh @benjojo
          Ooh, interesting.

          My thoughts were PHP injection.

          Either way, there is no reasonable explanation that doesn't include the words "horribly insecure".

          vileox@infosec.exchangeV 1 Reply Last reply
          0
          • lennybacon@infosec.exchangeL This user is from outside of this forum
            lennybacon@infosec.exchangeL This user is from outside of this forum
            lennybacon@infosec.exchange
            wrote last edited by
            #5

            @benjojo
            @dumbpasswordrules

            1 Reply Last reply
            1
            0
            • R relay@relay.an.exchange shared this topic
            • leeloo@c.imL leeloo@c.im

              @GLaDTheresCake @flesh @benjojo
              Ooh, interesting.

              My thoughts were PHP injection.

              Either way, there is no reasonable explanation that doesn't include the words "horribly insecure".

              vileox@infosec.exchangeV This user is from outside of this forum
              vileox@infosec.exchangeV This user is from outside of this forum
              vileox@infosec.exchange
              wrote last edited by
              #6

              @leeloo @GLaDTheresCake @flesh @benjojo

              "Either way, there is no reasonable explanation that doesn't include the words "horribly insecure"."

              There is one, alluded by someone up the thread: trolling. It is possible that the system is secure, but an admin with a (twisted) sense of humor decided to do some mild nerd-sniping.

              Not very likely, just reasonable.

              1 Reply Last reply
              1
              0
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups