Upgrade to Pro — share decks privately, control downloads, hide ads and more …

80,000 Plaintext Passwords: An Open Source Love Story in Three Acts

80,000 Plaintext Passwords: An Open Source Love Story in Three Acts

T.J. Schuck

June 26, 2014
Tweet

Other Decks in Programming

Transcript

  1. mallory@local$ perl haxor.pl ! +------+-----------------------+------------+ | id | email |

    password | +------+-----------------------+------------+ | 6125 | [email protected] | honeyd | | 6126 | [email protected] | blowfish | | 6127 | [email protected] | peppercorn | | 6128 | [email protected] | md1947 | +------+-----------------------+------------+
  2. mallory@local$ perl haxor.pl ! +------+-----------------------+------------+ | id | email |

    password | +------+-----------------------+------------+ | 6125 | [email protected] | honeyd | | 6126 | [email protected] | blowfish | | 6127 | [email protected] | peppercorn | | 6128 | [email protected] | md1947 | +------+-----------------------+------------+
  3. mallory@local$ perl haxor.pl ! +------+-----------------------+------------+ | id | email |

    password | +------+-----------------------+------------+ | 6125 | [email protected] | ubarlq | | 6126 | [email protected] | oybjsvfu | | 6127 | [email protected] | crccrepbea | | 6128 | [email protected] | zq1947 | +------+-----------------------+------------+
  4. mallory@local$ perl haxor.pl ! +------+-----------------------+----------------------------------+ | id | email |

    password | +------+-----------------------+----------------------------------+ | 6125 | [email protected] | 6ee717a4bc91d99170ce0d0922ab6c43 | | 6126 | [email protected] | b258a419ddbc13d92b8e7fc25c2b9d6c | | 6127 | [email protected] | 6a58d0ad2619df7d7fabc2603b79063f | | 6128 | [email protected] | 0304432f4c8080781f1b210c6b92b12f | +------+-----------------------+----------------------------------+
  5. mallory@local$ perl haxor.pl ! +------+-----------------------+----------------------------------+ | id | email |

    password | +------+-----------------------+----------------------------------+ | 6125 | [email protected] | 6ee717a4bc91d99170ce0d0922ab6c43 | | 6126 | [email protected] | b258a419ddbc13d92b8e7fc25c2b9d6c | | 6127 | [email protected] | 6a58d0ad2619df7d7fabc2603b79063f | | 6128 | [email protected] | 0304432f4c8080781f1b210c6b92b12f | +------+-----------------------+----------------------------------+
  6. pepper8 pepper83 pepper88 pepper99 ! pepperdog pepperi1 peppermint peppermint1 pepperoni

    pepperpepper peppers peppers4 peppi123 peppone pepsi pepsi1 pepsi123 pepsi2006 pepsi5 pepsi78bottle pepsicat pepsico pepsii pepsimax pepsione pepsis12 pequot per12fect peralta1 peppercorn
  7. mallory@local$ perl haxor.pl ! +------+----------------------------------+------------------------+ | id | password |

    salt | +------+----------------------------------+------------------------+ | 6125 | 5b5f47a49cdd4386611ee0a63577eccd | CeVDwwrT7saa_cY2rV_qng | | 6126 | a50f4854739e10773c99d5576dbb2f73 | rRWjkN4ioELXIPpQ6aDY4w | | 6127 | 94c91484c8bb05113b28f9da2b7ea624 | XvALmgae9uUGmpikd8sohg | | 6128 | 5d2ee837249e9340624b12e653c5e4a3 | D-ZUYoaSadkCze1fPibbgg | +------+----------------------------------+------------------------+
  8. mallory@local$ perl haxor.pl ! +-----------------------+--------------------------------------------------------------+ | email | password |

    +-----------------------+--------------------------------------------------------------+ | [email protected] | $2a$10$1ObnU/cPb3AjVU5iu8ntfe77xO83roRhoJMyBqYhlq5ZMMbHCcELK | | [email protected] | $2a$10$CelbCnmBjJez5ego4w.mbusfnZGOn/lRhLjrr37R0iUCr1UIC6ZyC | | [email protected] | | | [email protected] | $2a$10$9WLufYmucbh.yaTHKKUuUeihbcA3hBUiI.XiW7ygmaYcYXtl4MBKy | +-----------------------+--------------------------------------------------------------+ $ 2a 10 LrfFlMh6Yc7JWKlpRwVjUuPCOPU5574fXAVrvLZRFT87cT55oLBEe $ $
  9. Cost Seconds 9 0.0344 10 0.0656 11 0.1333 12 0.2646

    13 0.5236 14 1.0481 15 2.1645 16 4.2801