|
airdata
|
|
June 26, 2011, 06:02:57 AM |
|
some of my favorites.... tupacshakur fuckyoumike tupac_shakur niggernigger n1gger! assrape looking at alot of the password makes me question the demographic of the bitcoin community.
|
|
|
|
Maged
Legendary
Offline
Activity: 1204
Merit: 1015
|
|
June 26, 2011, 06:05:17 AM |
|
Moral of the story: length means nothing if your password is still easy to type
My password isn't on there, and it isn't long at all. But it's hard to type. That said, I expect it to be found in the next few days.
|
|
|
|
haydent
|
|
June 26, 2011, 06:11:58 AM |
|
cheers op
|
2x Gigabyte 6950 OC @ 920/450 w/ ati tray tools (1 shader modded) - 760Mhs on ozco.in 0% fee aus pool btc: 1HS5Brzcsh7XkJn566XYbvfpa2JuBRBdss
|
|
|
datafish
Donator
Full Member
Offline
Activity: 129
Merit: 100
Swimming in a sea of data
|
|
June 26, 2011, 06:20:13 AM |
|
Moral of the story: length means nothing if your password is still easy to type
My password isn't on there, and it isn't long at all. But it's hard to type. That said, I expect it to be found in the next few days.
Same here. Relatively short password but not susceptible to a dictionary attack and containing special characters.
|
|
|
|
Slowpok3
|
|
June 26, 2011, 06:22:30 AM |
|
Moral of the story: length means nothing if your password is still easy to type
My password isn't on there, and it isn't long at all. But it's hard to type. That said, I expect it to be found in the next few days.
can passwords contain characters like.... ¿ ¼ © mine was 13 characters long, so it looks like they only got to 12 characters in length and were almost up to mine
|
|
|
|
SgtSpike
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
June 26, 2011, 06:24:59 AM |
|
some of my favorites.... tupacshakur fuckyoumike tupac_shakur niggernigger n1gger! assrape looking at alot of the password makes me question the demographic of the bitcoin community. LOL, so true... also saw "pooppoop123". Moral of the story: length means nothing if your password is still easy to type
My password isn't on there, and it isn't long at all. But it's hard to type. That said, I expect it to be found in the next few days.
can passwords contain characters like.... ¿ ¼ © mine was 13 characters long, so it looks like they only got to 12 characters in length and were almost up to mine Mine was only 9 chars, and wasn't on that list. Is this only the unsalted pw's?
|
|
|
|
Maged
Legendary
Offline
Activity: 1204
Merit: 1015
|
|
June 26, 2011, 06:35:12 AM |
|
Mine was only 9 chars, and wasn't on that list. Is this only the unsalted pw's? This is including salted passwords. Also, it wasn't a full bruteforce: they looked for common patterns.
|
|
|
|
Findeton
|
|
June 26, 2011, 06:49:33 AM |
|
They got hacked again?
I'm happy now that I withdrew all my remaining bitcoins from Mt Gox.
|
|
|
|
BtcNmcMiner
|
|
June 26, 2011, 06:55:46 AM |
|
Mine was 9 characters long a number and a dictionary word, no capitals or special characters It should have been salted, based on my join date. It is not on that list. Still a good thing I didn't have anything in Mt. Gox though. And the only reason I didn't was, IIRC, they wouldn't let me transfer in less than 1 Btc at a time.
|
|
|
|
SpaceLord
Member
Offline
Activity: 70
Merit: 10
|
|
June 26, 2011, 07:03:45 AM |
|
Mike really is a fucker. God, I hate that guy.
|
|
|
|
Valhalla1
Newbie
Offline
Activity: 51
Merit: 0
|
|
June 26, 2011, 07:04:58 AM |
|
1q2w3e!Q@W#E qwe123QWE!@# interesting that these got cracked, was it salted? looks like it would be more difficult to crack than a lot of the ones on that list
|
|
|
|
julz
Legendary
Offline
Activity: 1092
Merit: 1001
|
|
June 26, 2011, 07:05:58 AM |
|
They got hacked again?
No. *some* of the passwords have been extracted from the *previously* released list of (lightly) encrypted passwords. Everyone should have changed their mtgox passwords by now, and also on other services if they were silly enough to use the same password elsewhere. This is just an interesting exercise in seeing what insecure passwords people tend to use. The shorter, dictionary based passwords are easily cracked. The more complex ones will take time - if anyone can even be bothered. I'm happy now that I withdrew all my remaining bitcoins from Mt Gox.
Fine - be happy. But take a little time to understand what you are being happy about. then again.. maybe too much understanding is not a recipe for happiness... As you were!
|
@electricwings BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
|
|
|
Tasty Champa
Member
Offline
Activity: 84
Merit: 10
|
|
June 26, 2011, 07:10:21 AM |
|
that looks to only go up to 9000, I wouldn't expect it to be complete for a couple months. You also have to assume most of them are throwaway accounts.
|
|
|
|
julz
Legendary
Offline
Activity: 1092
Merit: 1001
|
|
June 26, 2011, 07:11:55 AM |
|
1q2w3e!Q@W#E qwe123QWE!@# interesting that these got cracked, was it salted? looks like it would be more difficult to crack than a lot of the ones on that list It is interesting.. but note that on a standard qwerty keyboard - it's a pattern of 6 keys at the top left.. first unshifted then shifted. Perhaps some wannabe security guru recommended it to a bunch of suckers as an easy way to remember your complicated password?!
|
@electricwings BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
|
|
|
|
d.james
Sr. Member
Offline
Activity: 280
Merit: 250
Firstbits: 12pqwk
|
|
June 26, 2011, 07:31:00 AM |
|
|
You can not roll a BitCoin, but you can rollback some. Roll me back: 1NxMkvbYn8o7kKCWPsnWR4FDvH7L9TJqGG
|
|
|
fcmatt
Legendary
Offline
Activity: 2072
Merit: 1001
|
|
June 26, 2011, 07:46:48 AM |
|
1q2w3e!Q@W#E qwe123QWE!@# interesting that these got cracked, was it salted? looks like it would be more difficult to crack than a lot of the ones on that list It is interesting.. but note that on a standard qwerty keyboard - it's a pattern of 6 keys at the top left.. first unshifted then shifted. Perhaps some wannabe security guru recommended it to a bunch of suckers as an easy way to remember your complicated password?! since the days of john the ripper, the config file for it allows you to put patterns that are commonly used. i assume other password cracking tools are also configurable for such patterns. checking simple patterns on the keyboard are often the first to fall since they are checked for that and dictionary way before the brute force takes place using a-z A-Z 1-0 shift1-0 etc....
|
|
|
|
Paperweight
Jr. Member
Offline
Activity: 41
Merit: 41
|
|
June 26, 2011, 08:30:02 AM |
|
My favorite username and passwords were UserID Username Email Password 12558 hehehe\' 0 0 0)waitfor delay\'0: $1$ldybUNj/$jZ5XJRWM8DsOTM3FU9TyN0 14250 & 39 union select 1 2 3 4 5 6
|
|
|
|
julz
Legendary
Offline
Activity: 1092
Merit: 1001
|
|
June 26, 2011, 08:49:45 AM |
|
My favorite username and passwords were UserID Username Email Password 12558 hehehe\' 0 0 0)waitfor delay\'0: $1$ldybUNj/$jZ5XJRWM8DsOTM3FU9TyN0 14250 & 39 union select 1 2 3 4 5 6
ouch. That's potentially damning for the 'no sql injection attack occurred' line. There are also some script tags in there that I didn't notice before.
|
@electricwings BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
|
|
|
|