<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Advanced Password Cracking - Insight &#187; General</title>
	<atom:link href="http://blog.crackpassword.com/category/general/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.crackpassword.com</link>
	<description>&#171;...This blog is about &#60;a href=&#34;/?s=password+recovery&#34;&#62;cracking passwords&#60;/a&#62;, &#60;a href=&#34;/?s=forensic&#34;&#62;forensics solutions&#60;/a&#62;,&#60;br&#62;&#60;a href=&#34;/?s=security&#34;&#62;computer and network security&#60;/a&#62;, &#60;a href=&#34;/?s=system+recovery&#34;&#62;system recovery&#60;/a&#62; and other things...&#187;</description>
	<lastBuildDate>Thu, 15 Jul 2010 09:37:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Something new….</title>
		<link>http://blog.crackpassword.com/2010/07/something-new%e2%80%a6/</link>
		<comments>http://blog.crackpassword.com/2010/07/something-new%e2%80%a6/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 09:37:00 +0000</pubDate>
		<dc:creator>Alexandra Tsybulskaya</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Customer Reference Program Questionnaire]]></category>
		<category><![CDATA[Internet Password Breaker]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1341</guid>
		<description><![CDATA[According to the preliminary results of our latest questionnaire (ElcomSoft Customer Reference program Questionnaire) the majority of people forget their passwords when returned from holidays, thus being blocked out from the precious information they have on the PC. I bet that lots of people found themselves or those around in a similar situation at least [...]]]></description>
			<content:encoded><![CDATA[<p>According to the preliminary results of our latest questionnaire (ElcomSoft Customer Reference program Questionnaire) the majority of people forget their passwords when returned from holidays, thus being blocked out from the precious information they have on the PC. <br />
I bet that lots of people found themselves or those around in a similar situation at least once. Let me share my personal experience with you. One of my friends, having returned from the vacation in a tropical paradise, was pleased to see a new computer at her desk (while she was away the company renewed some of the machines) and at the same time very much discouraged and upset to find out that many of her passwords remained in her old pc and she didn&#39;t bother herself to save them anywhere else. So the access to the mail account from her new modern PC was forbidden, as well as access to several password-protected websites (from social networks to online banking).&nbsp; Nothing to be happy with, isn&rsquo;t it?!! But such a story no longer has a sad ending due to the release of Elcom&rsquo;s new recovery tool, namely ElcomSoft Internet Password Breaker. In the above described situation EINPB revealed necessary passwords stored in the old computer, thus letting a person replace the password-protected data from one machine to another.&nbsp; One more important remark in this respect is that my friend didn&rsquo;t have to seek help of the &ldquo;user-unfriendly sysadmin&rdquo; <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>What&rsquo;s special about EINPB? Let&rsquo;s have a quick jog through some of its features. Our new tool instantly reveals cached passwords to Web sites in Microsoft Internet Explorer, mailbox &amp; identity passwords in lots of Microsoft versions. It as well supports the new security model employed by Microsoft Internet Explorer 7 and 8.</p>
<p>Think it can be of any interest for you, please visit our site <a href="http://www.elcomsoft.com">http://www.elcomsoft.com</a> &amp; learn more about EINPB at <a href="http://einpb.elcomsoft.com">http://einpb.elcomsoft.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/07/something-new%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CCFC 2010</title>
		<link>http://blog.crackpassword.com/2010/07/ccfc-2010/</link>
		<comments>http://blog.crackpassword.com/2010/07/ccfc-2010/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 05:28:59 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[CCFC]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1333</guid>
		<description><![CDATA[For the third time we&#39;ve been invited to Beijing, China to participate in CCFC (China Computer Forensic Conference), to talk about password recovery and to conduct workshop on password recovery tools. Like two previous times, this time CCFC also was great. Lots of visitors, very nice audience and lots of smart questions. On the first [...]]]></description>
			<content:encoded><![CDATA[<p>For the third time we&#39;ve been invited to Beijing, China to participate in CCFC (<a href="http://www.china-forensic.com/en/2010/index.htm" target="_blank">China Computer Forensic Conference</a>), to talk about password recovery and to conduct workshop on password recovery tools. Like two previous times, this time CCFC also was great. Lots of visitors, very nice audience and lots of smart questions. On the first day of conference I gave a talk on password recovery (mostly very generic and not very in-depth) and I&#39;d like to share slides of that talk.</p>
<div id="__ss_4651632" style="width: 598px;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" height="481" id="__sse4651632" width="598"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/player.swf?doc=2010-06-28ccfcelcomsoft-100630101322-phpapp01&amp;rel=0&amp;stripped_title=password-recovery-tools" /><param name="name" value="__sse4651632" /><param name="allowfullscreen" value="true" /><embed allowfullscreen="true" allowscriptaccess="always" height="481" id="__sse4651632" name="__sse4651632" src="http://static.slidesharecdn.com/swf/player.swf?doc=2010-06-28ccfcelcomsoft-100630101322-phpapp01&amp;rel=0&amp;stripped_title=password-recovery-tools" type="application/x-shockwave-flash" width="598"></embed></object></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/07/ccfc-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>0-day</title>
		<link>http://blog.crackpassword.com/2010/06/0-day/</link>
		<comments>http://blog.crackpassword.com/2010/06/0-day/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 10:50:43 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[EPPB]]></category>
		<category><![CDATA[iOS 4]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1330</guid>
		<description><![CDATA[It’s been two weeks since Steve Jobs has announced release of new iPhone 4 and iOS 4 operating system during his keynote on WWDC’2010. New iPhone will begin shipping on Thursday, 24th of June, and new iOS will become available for download today, just few hours are left. iOS 4 comes packed with a lot [...]]]></description>
			<content:encoded><![CDATA[<p>It’s been two weeks since Steve Jobs has announced release of new iPhone 4 and iOS 4 operating system during his keynote on WWDC’2010. New iPhone will begin shipping on Thursday, 24th of June, and new iOS will become available for download today, just few hours are left.</p>
<p>iOS 4 comes packed with a lot of nice features (long-awaited multitasking, background location services, iBooks and much improved Mail app&#160; just to name a few) and we are very pleased to announce today the release of the new version of Elcomsoft iPhone Password Breaker with support for iTunes 9.2 and iOS 4.</p>
<p>Elcomsoft iPhone Password Breaker (or EPPB for short) is a utility to recover passwords for encrypted and password-protected iPhone/iPod/iPad backups created with iTunes (please note that it’s not meant to recover or remove passcode lock on the device).</p>
<p>With iOS 4 Apple has completely changed the way backups are encrypted and stored. Backup and restore processes are way much faster now. Apple have also improved protection against password recovery attacks, thus making our job harder (password recovery is about 5x slower for new backups than for older ones).</p>
<p>We at Elcomsoft try our best to keep up with the times, so most of our tools &amp; programs are adjusted to the latest technologically advanced features. The EPPB is not an exception, new version of EPPB fully supports both old and new backup formats. It also supports hardware acceleration using NVIDIA and ATI GPUs and Tableau TACC1441.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/06/0-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Usage Behavior Survey, Take 2</title>
		<link>http://blog.crackpassword.com/2010/06/password-usage-behavior-survey-take-2/</link>
		<comments>http://blog.crackpassword.com/2010/06/password-usage-behavior-survey-take-2/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 09:36:45 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Human Factor]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Password Usage Behavior Survey]]></category>
		<category><![CDATA[questionnaire]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1310</guid>
		<description><![CDATA[Hello! Yet again, we have launched a survey on password usage behavior. As our previous survey went like a breeze (you will find the report in our archives), it is a logical next step that we decide to try one more time. From the very first survey we gained curious info, which was also interesting [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="" src="http://blog.crackpassword.com/wp-content/uploads/2010/06/survey06101.jpg" style="margin-bottom: 10px; margin-left: 10px" />Hello! Yet again, we have launched a <a href="http://www.elcomsoft.com/questionnaire0610.html">survey</a> on password usage behavior.</p>
<p>As our previous survey went like a breeze (you will find the <a href="http://www.elcomsoft.com/surveys.html">report</a> in our archives), it is a logical next step that we decide to try one more time. From the very first survey we gained curious info, which was also interesting to publicity. Naturally questions about password protection are numerous and some of them remain dark, possibly a little too much so, that is why we are tempted to undertake one more &ldquo;investigation&rdquo;.</p>
<p>This time we expanded on questions and made some of them hypothetical, where you are put into a situation to find a way out. It is interesting to trace your way of thinking on both hypothetical and actual matters, so other questions are suggested to understand your attitude to real everyday situations you have to deal with.</p>
<p>As usually, survey completion will be finalized by a report.</p>
<p>We tried not to inundate our <a href="http://www.elcomsoft.com/questionnaire0610.html">questionnaire</a> with baffling questions, but if you still consider it time-consuming, you are welcome to answer one absurdly simple question on home page of <a href="http://www.elcomsoft.com/#survey">ElcomSoft website</a>.</p>
<p>C&rsquo;mon you are within an ace of getting 10% discount for all our software; just find a little will-power to put a couple of ticks. Again, thank you for taking time from your busy day and completing our <a href="http://www.elcomsoft.com/questionnaire0610.html">questionnaire</a>.&nbsp; And feel free to channel this survey to your friends and colleagues.</p>
<p>Best of luck!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/06/password-usage-behavior-survey-take-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ElcomSoft at EuroForensics 2010 in Turkey</title>
		<link>http://blog.crackpassword.com/2010/04/elcomsoft-at-euroforensics-2010-in-turkey/</link>
		<comments>http://blog.crackpassword.com/2010/04/elcomsoft-at-euroforensics-2010-in-turkey/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 08:43:10 +0000</pubDate>
		<dc:creator>Alexandra Tsybulskaya</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[EuroForensics 2010]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1267</guid>
		<description><![CDATA[Hurrying to inform you about our adventures in one of the most beautiful cities of Euro-Asian region, Istanbul. This March we were lucky to have a chance of participating in a big forensics and security focused international event in Turkey, namely EuroForensics 2010, thanks to our Turkish partners Forensic People, organizers &#38; hosts of the [...]]]></description>
			<content:encoded><![CDATA[<p>Hurrying to inform you about our adventures in one of the most beautiful cities of Euro-Asian region, Istanbul. This March we were lucky to have a chance of participating in a big forensics and security focused international event in Turkey, namely <a href="http://euroforensics.com" target="_blank">EuroForensics 2010</a>, thanks to our Turkish partners <a href="http://forensicpeople.com" target="_blank">Forensic People</a>, organizers &amp; hosts of the event.</p>
<p>The city gave us a warm and sunny welcome, regarding its weather, so since the arrival we were filled with positive energy &amp; cheerful mood. We were not only exhibiting, but delivering a presentation as well (however it had been cut in time because of the previous speaker). The exhibition/conference took part in the Military Museum of Istanbul, highly-protected military zone, so that to enter the exhibition area one should have all his belongings scanned. But it wasn&rsquo;t that annoying, we respected local rules &amp; policies (obedient guys).</p>
<p>Now, a few words about the conference itself. We arrived in Istanbul the day before the event in order to have time to see the city a bit and to organize our booth, want to notice that we were one of the first exhibitors to have our stand constructed in time, can&rsquo;t resist praising ourselves in this respect <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  .</p>
<p>The first day of the exhibition was busy: hundreds of visitors, most of them were really interested and were in the topic of the show, which was actually a surprising fact for us. The rest two days were not that lively, to say the least of it, only the most forensics-obsessed people sacrificed their weekend to visit the exhibition, hope, it came up to their expectations <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  .</p>
<p>On the whole, it was worthwhile experiments for us, next year we think of having another go at it. Want to thank everybody who visited our booth &amp; took interest in our software.</p>
<p><span id="more-1267"></span></p>
<p>Below there are some photo materials from the show&hellip;</p>
<p><strong>Me at the booth&#8230;</strong></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us"><a href="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_0230.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank"><img alt="Click to enlarge photo" class="alignnone size-full wp-image-1271" height="413" src="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_02302.jpg" width="550" /></a></span></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt">&nbsp;</p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><strong><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us"><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us">Guys saying &quot;cheese &quot; at the camera <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></span></strong></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt">&nbsp;</p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us"><a href="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_02910.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank"><img alt="Click to enlarge photo" class="size-full wp-image-1272" height="413" src="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_0291.jpg" width="550" /></a></span></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt">&nbsp;</p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us"><a href="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_0293.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank"><img alt="Click to enlarge photo" class="alignnone size-full wp-image-1273" height="413" src="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_02931.jpg" width="550" /></a></span></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt">&nbsp;</p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><strong><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us">Have add this pic at multiple requests&#8230;</span></strong></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt">&nbsp;</p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us"><a href="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_05380.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank"><img alt="Click to enlarge photo" class="size-full wp-image-1274" height="413" src="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_0538.jpg" width="550" /></a></span></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt">&nbsp;</p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><strong><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us">Just a beautiful view of the city</span></strong></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt">&nbsp;</p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us"><a href="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_05650.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank"><img alt="Click to enlarge photo" class="size-full wp-image-1275" height="413" src="http://blog.crackpassword.com/wp-content/uploads/2010/04/IMG_0565.jpg" width="550" /></a></span></p>
<p class="MsoNormal" style="line-height: 150%; margin: 0cm 0cm 0pt"><span lang="EN-US" style="color: #444444; mso-ansi-language: en-us"><o:p></o:p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/04/elcomsoft-at-euroforensics-2010-in-turkey/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why you should crack your passwords</title>
		<link>http://blog.crackpassword.com/2010/02/why-you-should-crack-your-passwords/</link>
		<comments>http://blog.crackpassword.com/2010/02/why-you-should-crack-your-passwords/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 10:01:13 +0000</pubDate>
		<dc:creator>Per Thorsheim</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Human Factor]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[password audit]]></category>
		<category><![CDATA[password cracking]]></category>
		<category><![CDATA[Password policy]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1207</guid>
		<description><![CDATA[Your organization probably has a written password policy. Accordingly you also have different technical implementations of that policy across your various systems. Most of the implementations does not match the exact requirements or guidelines given in the written policy, because they cannot be technically implemented. Requirements that cannot be implemented can be anything from minimum/maximum [...]]]></description>
			<content:encoded><![CDATA[<p><center>
<p><img alt="Computer security audit" src="http://blog.crackpassword.com/wp-content/uploads/2010/02/security-audit.jpg" style="border-bottom: #000000 3px solid; border-left: #000000 3px solid; border-top: #000000 3px solid; border-right: #000000 3px solid" title="security audit" /></p>
<p></center>
<p>Your organization probably has a written password policy. Accordingly you also have different technical implementations of that policy across your various systems. Most of the implementations does not match the exact requirements or guidelines given in the written policy, because they cannot be technically implemented.</p>
<p><span id="more-1207"></span>Requirements that cannot be implemented can be anything from minimum/maximum length and complexity settings to non-measurable requirements such as &quot;never use the same password at work as you use at home&quot; or &quot;do not use any word from any existing language today as whole or part of your password&quot;.</p>
<p>In almost any case, there will be differences between the written policy, and the technical implementation of the policy, in any system. Obviously, this really doesn&#39;t aid end users in choosing and maintaining good passwords, as there will be various settings forcing them to have different passwords and different change frequencies from system to system.</p>
<p>Most auditors will conduct random samples to verify if the technical implementation equals the written policy. Unfortunately they will usually accept most deviations based on technical issues, as explained by system maintainers. Some auditors may check random accounts for &quot;password last set&quot; and &quot;last logon&quot; information, in order to get a quick impression of the overall account maintenance status, eventually mixing that with at list of ex-employees to verify if their accounts has been disabled and/or removed.</p>
<p>What they won&#39;t do is any type of password cracking to sample the compliance of passwords against the technical or the written password policy. From my point of view the results from the audit performed will be pretty close to worthless. You really will have no idea about the real risk level you are facing.</p>
<p>Consider this: If the written and/or technical implementation of a password policy gets changed, it may take months, years and even decades before all accounts has their passwords changed in accordance to the new policy. This is especially true for environments where software for complete account management are not in use. (This is true for most environments i have ever audited through 13+ years).</p>
<p>This is a major reason for why you should do proactive password audits. Doing password audits on your own systems will effectively help you with verifying password compliance against the written password policy. This is the best way of finding the weak spots, such as accounts where the password equals the username (a very common finding everywhere actually). You are simply blind to the risk of bad passwords as long as you don&#39;t audit them properly.</p>
<p>In fact, i would say that any auditor that is not capable of performing such an audit upon request is simply not good enough. Their audit will not provide the necessary input needed for you to make real-life risk assessments and perform the necessary steps to reduce the risk accordingly.</p>
<p>Good luck with your next password audit!</p>
<hr />
<p><em>Per Thorsheim is a security professional living and working in Bergen, Norway. He is currently certified CISA and CISM from <a href="http://www.isaca.org" rel="nofollow" target="_blank">isaca.org</a>, and CISSP-ISSAP from <a href="http://www.isc2.org" rel="nofollow" target="_blank">isc2.org</a>. You can follow him on <a href="http://Twitter.com/thorsheim" rel="nofollow" target="_blank">http://Twitter.com/thorsheim</a> and read his personal blog at <a href="http://securitynirvana.blogspot.com" rel="nofollow" target="_blank">http://securitynirvana.blogspot.com</a>. Comments and questions are of course welcome!</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/02/why-you-should-crack-your-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Contributor</title>
		<link>http://blog.crackpassword.com/2010/02/new-contributor/</link>
		<comments>http://blog.crackpassword.com/2010/02/new-contributor/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 09:12:16 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1215</guid>
		<description><![CDATA[We are glad to announce that we have a new contributor to our blog and we would like to introduce him to you. Per Thorsheim is a security professional living and working in Bergen, Norway. He is currently certified CISA and CISM from isaca.org, and CISSP-ISSAP from isc2.org. You can follow him on http://twitter.com/thorsheim and [...]]]></description>
			<content:encoded><![CDATA[<p><img align="left" alt="Per Thorsheim" height="220" src="http://blog.crackpassword.com/wp-content/uploads/2010/02/Per_Thorsheim.jpg" style="padding-right: 10px" title="Per Thorsheim" width="147" />We are glad to announce that we have a new contributor to our blog and we would like to introduce him to you.</p>
<p>Per Thorsheim is a security professional living and working in Bergen, Norway. He is currently certified CISA and CISM from <a href="http://www.isaca.org" rel="nofollow" target="_blank">isaca.org</a>, and CISSP-ISSAP from <a href="http://www.isc2.org" rel="nofollow" target="_blank">isc2.org</a>. You can follow him on <a href="http://twitter.com/thorsheim" rel="nofollow" target="_blank">http://twitter.com/thorsheim</a> and read his personal blog at <a href="http://securitynirvana.blogspot.com" rel="nofollow" target="_blank">http://securitynirvana.blogspot.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/02/new-contributor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It was Data Privacy Day&#8230; our warmest congratulations!</title>
		<link>http://blog.crackpassword.com/2010/01/it-was-data-privacy-day-our-warmest-congratulations/</link>
		<comments>http://blog.crackpassword.com/2010/01/it-was-data-privacy-day-our-warmest-congratulations/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 12:55:40 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Did you know that...?]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Data Privacy Day]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1105</guid>
		<description><![CDATA[ElcomSoft always have yet another pair of eyes for your privacy&#8230;]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.elcomsoft.com">ElcomSoft </a>always have yet another pair of eyes for your privacy&#8230; <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><img align="bottom" alt="" height="500" src="http://blog.crackpassword.com/wp-content/uploads/29012010121.jpg" width="375" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/01/it-was-data-privacy-day-our-warmest-congratulations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>123 Out Goes&#8230; Your Password</title>
		<link>http://blog.crackpassword.com/2010/01/123-out-goes-your-password/</link>
		<comments>http://blog.crackpassword.com/2010/01/123-out-goes-your-password/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 10:22:08 +0000</pubDate>
		<dc:creator>Katerina Korolkova, PR Director</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Human Factor]]></category>
		<category><![CDATA[Industry News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1099</guid>
		<description><![CDATA[About a month ago, a SQL Injection flaw was found in the database of RockYou.com, a website dealing with social networking applications. The Tech Herald reports that 32.6 million passwords were exposed and posted online due to the flaw. The complete examination of the passwords from the list showed that the passwords in question are [...]]]></description>
			<content:encoded><![CDATA[<p>About a month ago, a SQL Injection flaw was found in the database of RockYou.com, a website dealing with social networking applications. <a href="http://www.thetechherald.com/">The Tech Herald</a> reports that 32.6 million passwords were exposed and posted online due to the flaw. The complete examination of the passwords from the list showed that the passwords in question are not only short as RockYou.com allows creating 5-character-passwords but also alphanumeric only.</p>
<p>A half of the passwords from the list contained names, slang and dictionary words, or word combinations. The Tech Herald enumerates the most common passwords: &#8220;123456&#8243;, followed by &#8220;12345&#8243;, &#8220;123456789&#8243;, &#8220;Password&#8221;, &#8220;iloveyou&#8221;, &#8220;princess&#8221;, &#8220;rockyou&#8221;, &#8220;1234567&#8243;, &#8220;12345678&#8243;, and &#8220;abc123&#8243; to round out the top 10. Other passwords included common names such as &#8220;Jessica&#8221;, &#8220;Ashley&#8221;, or patterns like &#8220;Qwerty&#8221;.</p>
<p>Although the findings of the survey are deplorable, most sites do nothing to improve password security. At the same time some websites block special characters and do not allow users to choose them for passwords making user accounts vulnerable to malicious attacks.</p>
<p>As a part of problem solution, the Tech Herald sees sites enforcing users a hard rule of character length. We at <a href="http://www.elcomsoft.com/">ElcomSoft</a> share the opinion that a password must be at least 9 characters long, consisting of upper and lowercase letters, numbers, and &#8211; preferably &#8211; special characters.</p>
<p>The article also highlights greater risks for the companies as attackers are using more advanced brute force attacks. According to the Tech Herald, &#8220;if an attacker would&#8217;ve used the list of the top 5000 passwords as a dictionary for brute force attack on Rockyou.com users, it would take only one attempt (per account) to guess 0.9-percent of the user&#8217;s passwords, or a rate of one success per 111 attempts&#8221;.</p>
<p>Related articles and publications:</p>
<p><a href="http://www.klein.com/dvk/publications/passwd.pdf">A list of passwords used by the Conficker Worm Daniel V. Klein, &#8221;Foiling the Cracker&#8221;: A Survey of, and Improvements to, Password Security,&#8221; 1990.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/01/123-out-goes-your-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The 5th China Computer Forensics Conference</title>
		<link>http://blog.crackpassword.com/2009/12/the-5th-china-computer-forensics-conference/</link>
		<comments>http://blog.crackpassword.com/2009/12/the-5th-china-computer-forensics-conference/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 13:19:19 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Beijing]]></category>
		<category><![CDATA[CCFC]]></category>
		<category><![CDATA[Sprite Guo]]></category>
		<category><![CDATA[The 5th China Computer Forensics Conference]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1087</guid>
		<description><![CDATA[So, they are back from CCFC&#160; (Beijing) where Vladimir, Andrew, and Dmitry made their speeches and listened to those given by other reps.&#160; Here is a follow-up of the conference with nice shots kindly taken by a keen &#8220;shooter&#8221; Dmitry Sklyarov&#160;;) But first of all, we&#8217;d like to thank Sprite Guo for taking care of [...]]]></description>
			<content:encoded><![CDATA[<p>So, they are back from <a href="http://www.china-forensic.com/en/2009/index.htm">CCFC</a>&nbsp; (Beijing) where Vladimir, Andrew, and Dmitry made their <a href="http://www.china-forensic.com/en/2009/speaker.htm">speeches</a> and listened to those given by other reps.&nbsp; Here is a follow-up of the conference with nice shots kindly taken by a keen &ldquo;shooter&rdquo; Dmitry Sklyarov&nbsp;;) But first of all, we&rsquo;d like to thank Sprite Guo for taking care of all preparations and perfect managing throughout the whole conference &ndash; our BIG thank you!</p>
<p>Remarkably, on guys&rsquo; returning there was no need to ask them about their trip, it was clearly seen on their fresh faces they are full of new ideas&nbsp;which is the most intrinsic value of all.</p>
<p>So, here is a photo-reportage&#8230;</p>
<p>&nbsp;<span id="more-1087"></span></p>
<p><strong>Andrew Belenko is making his speech on the opening day</strong><br />
<a href="/wp-content/uploads/1.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/1_small.jpg" /></a></p>
<p><b>Vladimir, Dmitry, Andrew and Yurii at Tian&rsquo;anmen</b><br />
<a href="/wp-content/uploads/2.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/2_small.jpg" /></a></p>
<p><b>Dmitry Sklyarov is lecturing&#8230; as always <img alt=";)" height="20" src="http://blog.crackpassword.com/wp-content/plugins/fckeditor-for-wordpress-plugin/ckeditor/plugins/smiley/images/wink_smile.gif" title=";)" width="20" /></b><br />
<a href="/wp-content/uploads/3.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/3_small.jpg" /></a></p>
<p><b>Andrew, Vladimir and Sprite, cigarette-break</b><br />
<a href="/wp-content/uploads/4.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/4_small.jpg" /></a></p>
<p><b>Guess what?</b><br />
<a href="/wp-content/uploads/6.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/6_small.jpg" /></a></p>
<p><b>CCFC photo session <img alt=":)" height="20" src="http://blog.crackpassword.com/wp-content/plugins/fckeditor-for-wordpress-plugin/ckeditor/plugins/smiley/images/regular_smile.gif" title=":)" width="20" /></b><br />
<a href="/wp-content/uploads/7.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/7_small.jpg" /></a></p>
<p><b>Sometimes it is like in a fairy tale</b><br />
<a href="/wp-content/uploads/8.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/8_small.jpg" /></a></p>
<p><b>Dmitry, Vladimir and Andrew and the Great Wall of China</b><br />
<a href="/wp-content/uploads/9.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/9_small.jpg" /></a></p>
<p><b>Would you like centipede?&#8230; <img alt=":P" height="20" src="http://blog.crackpassword.com/wp-content/plugins/fckeditor-for-wordpress-plugin/ckeditor/plugins/smiley/images/tounge_smile.gif" title=":P" width="20" /></b><br />
<a href="/wp-content/uploads/10.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/10_small.jpg" /></a></p>
<p><b>Wires again&#8230;</b><br />
<a href="/wp-content/uploads/11.jpg" style="border-bottom: medium none; border-left: medium none; border-top: medium none; border-right: medium none" target="_blank" title="Click to enlarge photo"><img alt="" border="0" src="http://blog.crackpassword.com/wp-content/uploads/11_small.jpg" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/12/the-5th-china-computer-forensics-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
