<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Google as a password cracker</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Thu, 18 Mar 2010 03:53:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: david</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-51303</link>
		<dc:creator>david</dc:creator>
		<pubDate>Wed, 10 Mar 2010 19:59:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-51303</guid>
		<description>for some of you looking for a sha1 reverse lookup tool, check this &lt;a href="http://www.stringfunction.com/sha1-decrypter.html" rel="nofollow"&gt;sha1 decrypter&lt;/a&gt;
David</description>
		<content:encoded><![CDATA[<p>for some of you looking for a sha1 reverse lookup tool, check this <a href="http://www.stringfunction.com/sha1-decrypter.html" rel="nofollow">sha1 decrypter</a><br />
David</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-51302</link>
		<dc:creator>david</dc:creator>
		<pubDate>Wed, 10 Mar 2010 19:57:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-51302</guid>
		<description>hi guys,
just found another &lt;a href="http://www.stringfunction.com/md5-decrypter.html" rel="nofollow"&gt;md5 decrypter&lt;/a&gt;
David</description>
		<content:encoded><![CDATA[<p>hi guys,<br />
just found another <a href="http://www.stringfunction.com/md5-decrypter.html" rel="nofollow">md5 decrypter</a><br />
David</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FoundIt</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-31693</link>
		<dc:creator>FoundIt</dc:creator>
		<pubDate>Thu, 06 Aug 2009 19:02:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-31693</guid>
		<description>Google Hash: md5(jesus) = 110d46fcd978c24f306cd7fa23464d73

It worked for Jesus!</description>
		<content:encoded><![CDATA[<p>Google Hash: md5(jesus) = 110d46fcd978c24f306cd7fa23464d73</p>
<p>It worked for Jesus!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arya</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-31472</link>
		<dc:creator>Arya</dc:creator>
		<pubDate>Mon, 20 Jul 2009 10:49:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-31472</guid>
		<description>NIce-let us if you people can crack a pass with One capital letter+small letter+number+special character in it+upto 8 char long.
Though there is a way</description>
		<content:encoded><![CDATA[<p>NIce-let us if you people can crack a pass with One capital letter+small letter+number+special character in it+upto 8 char long.<br />
Though there is a way</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-31254</link>
		<dc:creator>John</dc:creator>
		<pubDate>Tue, 07 Jul 2009 15:48:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-31254</guid>
		<description>You got pretty lucky that the password was a common/proper dictionary word. I just did a few tests by adding numbers onto some simple random words, and google didn't have anything indexed. 

Another vote for John The Ripper though. The rules engine is very good and will find things like that quickly. 

An interesting project would be to develop a tool that would test your clear text password against all the common variation algorithms and help you to pick a password with a high probability of needing a pure brute force crack to discover. Much better than the simple "one letter, one number, one symbol" requirement that a lot of services are doing these days.</description>
		<content:encoded><![CDATA[<p>You got pretty lucky that the password was a common/proper dictionary word. I just did a few tests by adding numbers onto some simple random words, and google didn&#8217;t have anything indexed. </p>
<p>Another vote for John The Ripper though. The rules engine is very good and will find things like that quickly. </p>
<p>An interesting project would be to develop a tool that would test your clear text password against all the common variation algorithms and help you to pick a password with a high probability of needing a pure brute force crack to discover. Much better than the simple &#8220;one letter, one number, one symbol&#8221; requirement that a lot of services are doing these days.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leo Kelly</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-31046</link>
		<dc:creator>Leo Kelly</dc:creator>
		<pubDate>Tue, 19 May 2009 02:55:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-31046</guid>
		<description>I use http://www.md5crack.com for everything..sometimes it can be a little off, though</description>
		<content:encoded><![CDATA[<p>I use <a href="http://www.md5crack.com" rel="nofollow">http://www.md5crack.com</a> for everything..sometimes it can be a little off, though</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brayan</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-31035</link>
		<dc:creator>brayan</dc:creator>
		<pubDate>Mon, 11 May 2009 00:29:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-31035</guid>
		<description>mirar  contraseña</description>
		<content:encoded><![CDATA[<p>mirar  contraseña</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lynks</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-31022</link>
		<dc:creator>Lynks</dc:creator>
		<pubDate>Wed, 29 Apr 2009 23:09:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-31022</guid>
		<description>http://md5.rednoize.com/

has never failed me, and it's even google-themed</description>
		<content:encoded><![CDATA[<p><a href="http://md5.rednoize.com/" rel="nofollow">http://md5.rednoize.com/</a></p>
<p>has never failed me, and it&#8217;s even google-themed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: linux0wner</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-29765</link>
		<dc:creator>linux0wner</dc:creator>
		<pubDate>Thu, 28 Aug 2008 09:23:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-29765</guid>
		<description>This is a reverse search for sha-1: http://www.sha1-lookup.com</description>
		<content:encoded><![CDATA[<p>This is a reverse search for sha-1: <a href="http://www.sha1-lookup.com" rel="nofollow">http://www.sha1-lookup.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ana</title>
		<link>http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/comment-page-3/#comment-29742</link>
		<dc:creator>ana</dc:creator>
		<pubDate>Thu, 21 Aug 2008 13:37:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/#comment-29742</guid>
		<description>wordpress seem to have many security issues. 

And so does  this site ;)
For example when you go the the login page, you can 'test' if there is a username 'admin'  (or any other name). If so, then bruteforcing could be tried.
also, often wordpress folders like 
/wp-content/plugins/  or /wp-admin/  are readable.
It shows what  plugins you use, and often reveals the full path of your files by directly accessing the php files.</description>
		<content:encoded><![CDATA[<p>wordpress seem to have many security issues. </p>
<p>And so does  this site <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
For example when you go the the login page, you can &#8216;test&#8217; if there is a username &#8216;admin&#8217;  (or any other name). If so, then bruteforcing could be tried.<br />
also, often wordpress folders like<br />
/wp-content/plugins/  or /wp-admin/  are readable.<br />
It shows what  plugins you use, and often reveals the full path of your files by directly accessing the php files.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
