Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 24 guests and 1 member online
You are here:
EH-Net
May 25, 2013, 06:47:40 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Password Security (and my new blog)
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Password Security (and my new blog) (Read 7225 times)
0 Members and 1 Guest are viewing this topic.
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Password Security (and my new blog)
«
on:
June 25, 2012, 12:06:24 AM »
Recently, I've had several discussions (online and offline) about password security, password hashing algorithms, and what it is that we're trying to accomplish. I ended up starting a blog so I had a place to publish everything. The articles up so far are about password security, but I plan to publish more on other (mostly application) security issues. I hope that what I've written will be of interests to the folks here.
So far, I've posted about why rainbow tables aren't as powerful as people think, how long passwords actually need to be to withstand an online or offline attack, and an analysis of what we're actually trying to accomplish with salting, stretching, delay timers, expiration etc.
The blog is here:
http://bugcharmer.blogspot.com
Feedback is welcome.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
fred
Sr. Member
Offline
Posts: 351
The World is sick, Save your mind...
Re: Password Security (and my new blog)
«
Reply #1 on:
June 30, 2012, 03:25:42 AM »
ok buddy congrats but i have a question when u can have a website for free with all features that other sites has, why u still write weblog?
Logged
ICS Academy Network Security Certified
3xban
Hero Member
Offline
Posts: 608
Re: Password Security (and my new blog)
«
Reply #2 on:
June 30, 2012, 07:18:28 AM »
functionality and security would be a prime reason I would. I have a site and host that I pay yearly for. The cost is minimal based on all the unlimited features I have. I also can install a number of applications on the site ranging from Wordpress to Jabber chat. Problem is that I could either let them install and have little to manage but also little to customize or manually install and have to worry about keeping the code clean and updating it regularly. If you go with a blogspot or tumblr account, all you really have to worry about is the content. Plus both of these services are free.
I've been considering taking most of my site down until I can make some time to update everything but I have a game forum that a handful of people use. When I had more time, I enjoyed messing around with the website but now I just need something to work.
Logged
Certs: GCWN
(@)Dewser
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: Password Security (and my new blog)
«
Reply #3 on:
June 30, 2012, 12:33:04 PM »
Quote from: cyber.spirit on June 30, 2012, 03:25:42 AM
ok buddy congrats but i have a question when u can have a website for free with all features that other sites has, why u still write weblog?
I don't have to do any maintenance or setup. I can just write, check my stats once in a while, etc.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
fred
Sr. Member
Offline
Posts: 351
The World is sick, Save your mind...
Re: Password Security (and my new blog)
«
Reply #4 on:
June 30, 2012, 05:29:25 PM »
with
www.zymic.com
u can have a free web host with amazing features and u can register a .tk domain fo it (free) so creating a free and good website is not so hard man
Logged
ICS Academy Network Security Certified
3xban
Hero Member
Offline
Posts: 608
Re: Password Security (and my new blog)
«
Reply #5 on:
July 03, 2012, 12:25:48 PM »
missing the point Cyber.Spirit. Eventually we just want a site to work and do what we need it to do without having to worry. Hosting a full site when you just want to write a regular blog is overkill by today's standards. Even with free sites, you still need to worry about maintenance, whether you do it or the host does it. Most of my site is maintained by the host but there are pieces that fall to me to manage and can be exploited if I don't keep up on it. If I just want to post to a regular blog, it is much easier to sign up for the free Blogspot account. That way I can tweet my thoughts and concerns and reference the blog for more content that can't fit in the standard twitter post.
Also one thing I find great about maintaining a blog is the writing practice. As you go further in your Security career, you will find this becomes a must have skill. It can eventually lead to possibly doing talks at the local Bsides event, SchmooCon or DerbyCon.
Logged
Certs: GCWN
(@)Dewser
chrisj
Hero Member
Offline
Posts: 1163
Re: Password Security (and my new blog)
«
Reply #6 on:
July 03, 2012, 02:42:52 PM »
3xban,
running my own full sites is what lead me to speaking at Bsides Detroit, GrrCON and DerbyCon this year.
I'm also teaching a workshop to a local Security User group (MiSEC) in Aug.
You'd be surprised what doing something for personal learning, and brushing up on skills can lead to.
Logged
OSWP, Sec+
impelse
Hero Member
Offline
Posts: 565
Re: Password Security (and my new blog)
«
Reply #7 on:
July 03, 2012, 03:24:14 PM »
Quote from: chrisj on July 03, 2012, 02:42:52 PM
3xban,
running my own full sites is what lead me to speaking at Bsides Detroit, GrrCON and DerbyCon this year.
I'm also teaching a workshop to a local Security User group (MiSEC) in Aug.
You'd be surprised what doing something for personal learning, and brushing up on skills can lead to.
This is the second time I heard about that. Maybe something to consider
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: Password Security (and my new blog)
«
Reply #8 on:
July 03, 2012, 05:17:17 PM »
Quote from: chrisj on July 03, 2012, 02:42:52 PM
3xban,
running my own full sites is what lead me to speaking at Bsides Detroit, GrrCON and DerbyCon this year.
I'm also teaching a workshop to a local Security User group (MiSEC) in Aug.
You'd be surprised what doing something for personal learning, and brushing up on skills can lead to.
I'm working full-time and going back to school. Even a small amount of extra time to maintain a full site would be a deal breaker for me. Once I'm out of school, I might do that; especially if I need to release code, exploits, etc.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
chrisj
Hero Member
Offline
Posts: 1163
Re: Password Security (and my new blog)
«
Reply #9 on:
July 03, 2012, 06:54:35 PM »
Quote from: unicityd on July 03, 2012, 05:17:17 PM
I'm working full-time and going back to school. Even a small amount of extra time to maintain a full site would be a deal breaker for me. Once I'm out of school, I might do that; especially if I need to release code, exploits, etc.
I work full time, I go to college (university) part time, I run a local lock sport group and involved in a few others. I have 2 sites (one server), a podcast, and an active member in 2 security groups. the time is there, you just have to learn to manage it.
Logged
OSWP, Sec+
3xban
Hero Member
Offline
Posts: 608
Re: Password Security (and my new blog)
«
Reply #10 on:
July 03, 2012, 08:37:49 PM »
Show off
Understandable though and I agree. But again if time is limited then you pick your filler for the little spare time you have. Mine is reverse engineering malware. Once I have a bit more I may circle back to building out my site.
Logged
Certs: GCWN
(@)Dewser
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: Password Security (and my new blog)
«
Reply #11 on:
July 04, 2012, 03:32:27 AM »
Quote from: 3xban on July 03, 2012, 08:37:49 PM
But again if time is limited then you pick your filler for the little spare time you have. Mine is reverse engineering malware.
Mine is crypto. I heart teh maths.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
fred
Sr. Member
Offline
Posts: 351
The World is sick, Save your mind...
Re: Password Security (and my new blog)
«
Reply #12 on:
July 04, 2012, 03:55:30 AM »
Quote from: 3xban on July 03, 2012, 12:25:48 PM
missing the point Cyber.Spirit. Eventually we just want a site to work and do what we need it to do without having to worry. Hosting a full site when you just want to write a regular blog is overkill by today's standards. Even with free sites, you still need to worry about maintenance, whether you do it or the host does it. Most of my site is maintained by the host but there are pieces that fall to me to manage and can be exploited if I don't keep up on it. If I just want to post to a regular blog, it is much easier to sign up for the free Blogspot account. That way I can tweet my thoughts and concerns and reference the blog for more content that can't fit in the standard twitter post.
Also one thing I find great about maintaining a blog is the writing practice. As you go further in your Security career, you will find this becomes a must have skill. It can eventually lead to possibly doing talks at the local Bsides event, SchmooCon or DerbyCon.
3xban im working on my new website with free host and domain man its not overkill blogs services has many disadvantages you just get a subdomain (example.blogspot.com) you cant design your blog freely you cant upload your files and create direct download links. users cant log in to your website and so on...
But with a free host and domain you can have all of above features and some another features too. if your problem is security you can run a pentest on your web application (you cant run pentest on the web server because its not legal.)
Then when you can have your own domain your own host your own web design and many of amazing features i think blog services are sucks..... im sure they have vulnerabilities also
CyberSpirit......
Logged
ICS Academy Network Security Certified
fred
Sr. Member
Offline
Posts: 351
The World is sick, Save your mind...
Re: Password Security (and my new blog)
«
Reply #13 on:
July 04, 2012, 09:59:21 AM »
and i missed something blog services must be so thankful of us because people made blogspot famous (example) without those people blog services are useless im wondering even if they understand it they wont give people some good features
Logged
ICS Academy Network Security Certified
3xban
Hero Member
Offline
Posts: 608
Re: Password Security (and my new blog)
«
Reply #14 on:
July 05, 2012, 10:59:43 PM »
Quote from: unicityd on July 04, 2012, 03:32:27 AM
Quote from: 3xban on July 03, 2012, 08:37:49 PM
But again if time is limited then you pick your filler for the little spare time you have. Mine is reverse engineering malware.
Mine is crypto. I heart teh maths.
Nerd
I don't mind math. I was hanging at a Ruby meetup a few weeks back and they started doing situational calculus in the "Math Room" of my friend's office. I am watching these guys go to town with an explanation of the math and then I realize, holy crap, I sort of understand this. Then it dawned on me, oh that wonderful Intro to Logic class I took way back in college. I felt briefly smart. I think they were just doing it for kicks.
Logged
Certs: GCWN
(@)Dewser
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.