Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow Spot the problem.....
EH-Net
May 21, 2013, 07:44:03 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Spot the problem.....  (Read 1990 times)
0 Members and 1 Guest are viewing this topic.
SecurityMonkey
Jr. Member
**
Offline Offline

Posts: 89



View Profile WWW
« on: August 28, 2012, 08:05:43 PM »

Can anyone see the problem with the tech guys reply?

https://gist.github.com/3497955

 Undecided
Logged

jjwinter
Jr. Member
**
Offline Offline

Posts: 76


View Profile
« Reply #1 on: August 28, 2012, 08:25:51 PM »

**raises hand**

1) They will snail mail your password to you....

2) To an ADDRESS YOU CAN CHANGE!!!



Logged
SecurityMonkey
Jr. Member
**
Offline Offline

Posts: 89



View Profile WWW
« Reply #2 on: August 28, 2012, 08:47:27 PM »

.....AND.....
Logged

jjwinter
Jr. Member
**
Offline Offline

Posts: 76


View Profile
« Reply #3 on: August 28, 2012, 08:50:36 PM »

Well, the whole hint giving thing is just weird.

"Your password rhymes with 'nassword'"

and starts with a P and ends with a D.

 Huh

Why even have passwords. Just use the honor system Wink
Logged
SecurityMonkey
Jr. Member
**
Offline Offline

Posts: 89



View Profile WWW
« Reply #4 on: August 28, 2012, 08:57:45 PM »

So do you  think they store the password in clear text... and the tech support people have access to view your password!

"A hint to your password is that it begins with s and ends with j"

Bit of a fail I think!
Logged

jjwinter
Jr. Member
**
Offline Offline

Posts: 76


View Profile
« Reply #5 on: August 28, 2012, 09:02:44 PM »

Didn't even think of that. Wow.

The more I learn about security, the less evidence I see of it being used.
Logged
shadowzero
Full Member
***
Offline Offline

Posts: 120


It's a UNIX system, I know this!


View Profile
« Reply #6 on: August 28, 2012, 10:11:26 PM »

So do you  think they store the password in clear text... and the tech support people have access to view your password!

"A hint to your password is that it begins with s and ends with j"

Bit of a fail I think!

I assumed that was more like a hint the user provides to himself, like "My mother's maiden name" sort of thing.
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #7 on: August 28, 2012, 11:27:26 PM »

So do you  think they store the password in clear text... and the tech support people have access to view your password!

"A hint to your password is that it begins with s and ends with j"

Bit of a fail I think!

I assumed that was more like a hint the user provides to himself, like "My mother's maiden name" sort of thing.

Hah, that's where I went too. I can envision the scenario where he forgot he set his own password hint that way and proceeds to get all uppity because he thought they were storing the password in plain text and giving out random hints.

Bonus points if the only reason he used that password hint was because they wouldn't let the hint contain the password itself Cheesy
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #8 on: August 29, 2012, 02:15:14 AM »

its a good sing they using the plaintext protocol or an encryption that can b reserved but both are really bad.
Logged

OSWP | Hackingdojo Nidan | eCPPT
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.114 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.