![]() |
|
|
#1 |
|
Editor & Senior Moderator
Join Date: Oct 2007
Location: Hyderabad, India
Posts: 14,983 (7.29/day)
Thanks: 788
Thanked 12,907 Times in 5,654 Posts
|
NVIDIA Forums Hack: Passwords Not Salted
A group of hackers that claimed responsibility for hacking NVIDIA forums (forums.nvidia.com), which goes by the name "Team Apollo," posted the first piece of its exploits on Pastebin (find it here). The user data dump contains details of every fifth user of the forums. From what we can tell looking at the pasted data (which is now very much in the public domain), the passwords found in the user tables are not salted. NVIDIA was less than honest about that part.
The passwords are stored as raw MD5 hashes, which can be fairly-easily decrypted (when compared to hashes with salt values). To make matters worse, certain MD5 decryption websites have large databases of pre-decrypted MD5 phrases, potentially making decryption these hashes easy. Or you could just use a CUDA-accelerated MD5 decryption tool, which munches through unsalted MD5 hash values at the speed of a small supercomputer. If you have an NVIDIA Forums account, and your passwords on other websites (forums, email accounts, banks) even remotely resemble that of your NVIDIA forums account, it is strongly recommended that you change your passwords on each of those other websites.
|
|
|
|
|
|
#2 |
![]() Join Date: Feb 2011
Posts: 642 (0.78/day)
Thanks: 391
Thanked 127 Times in 89 Posts
|
|
|
|
|
|
|
#3 |
![]() Join Date: May 2010
Location: Canada
Posts: 1,902 (1.73/day)
Thanks: 630
Thanked 429 Times in 353 Posts
|
WOW! Good lookin' out bta
__________________
Why dazzle 'em with brilliance when you can baffle 'em with bullshit. Alterius non sit, qui potest esse sui! Und setzet ihr nicht das leben ein, Nie wird euch das leben gewonnen sein! If knowledge is power, then ignorance is bliss! If god didn't want them sheared, he wouldn't have made them sheep! |
|
|
|
|
|
#4 |
![]() Join Date: Apr 2011
Posts: 12 (0.02/day)
Thanks: 1
Thanked 6 Times in 2 Posts
|
using CUDA enabled crackers to crack NVIDIA passwords....
![]()
|
|
|
|
| The Following 4 Users Say Thank You to mayankleoboy1 For This Useful Post: |
|
|
#5 |
![]() |
|
|
|
|
|
|
#6 |
![]() Join Date: Jun 2011
Location: Islamabad
Posts: 529 (0.76/day)
Thanks: 170
Thanked 22 Times in 13 Posts
|
hahahahhahahahah
__________________
|
|
|
|
|
|
#7 |
![]() Join Date: May 2012
Location: Malaysia
Posts: 254 (0.70/day)
Thanks: 16
Thanked 35 Times in 31 Posts
|
already decrypted one
__________________
⎝⏠⏝⏠⎠
|
|
|
|
|
|
#8 |
![]() Join Date: Feb 2011
Posts: 642 (0.78/day)
Thanks: 391
Thanked 127 Times in 89 Posts
|
how do you know it's not salted? seriously please
|
|
|
|
|
|
#9 |
|
Semi-Retired Folder
Join Date: Nov 2005
Location: Indiana
Posts: 17,754 (6.48/day)
Thanks: 780
Thanked 5,116 Times in 3,707 Posts
|
A good policy, and one I use, it to not use any similar passwords for important things. Each email address has a totally different password, my bank passwords are also totally different. I vary rarely use the same password for two things, though I do have one password that I use for sites that I'll probably only ever visit once and don't care about.
__________________
Rig1: System Specs. Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5 Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate |
|
|
|
|
|
#10 |
|
Benevolent Dictator
Join Date: May 2004
Location: Stuttgart, Germany
Posts: 13,789 (4.18/day)
Thanks: 184
Thanked 10,270 Times in 3,173 Posts
|
|
|
|
|
|
|
#11 |
|
Semi-Retired Folder
Join Date: Nov 2005
Location: Indiana
Posts: 17,754 (6.48/day)
Thanks: 780
Thanked 5,116 Times in 3,707 Posts
|
OMG! That is the combination to my luggage!
__________________
Rig1: System Specs. Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5 Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate |
|
|
|
| The Following 4 Users Say Thank You to newtekie1 For This Useful Post: |
|
|
#12 |
|
Hardcore Monkey Moderator
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,117 (5.27/day)
Thanks: 591
Thanked 5,493 Times in 2,937 Posts
|
Hash "qwerty" and I'm sure you will get some matches too.
__________________
Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other. Get more tech news on a wide variety of topics at NextPowerUp
|
|
|
|
|
|
#13 |
![]() Join Date: Feb 2011
Posts: 642 (0.78/day)
Thanks: 391
Thanked 127 Times in 89 Posts
|
|
|
|
|
|
|
#14 | |
|
Banstick Dummy
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,111 (6.92/day)
Thanks: 1,337
Thanked 6,834 Times in 3,741 Posts
|
Quote:
|
|
|
|
|
|
|
#15 |
|
Semi-Retired Folder
Join Date: Nov 2005
Location: Indiana
Posts: 17,754 (6.48/day)
Thanks: 780
Thanked 5,116 Times in 3,707 Posts
|
Yeah, in a perfect world no one should have to worry about this. Then again, apparently some of the users used 12345678 as their passwords, so we obviously aren't in a perfect world.
__________________
Rig1: System Specs. Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5 Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate |
|
|
|
|
|
#16 |
|
Hardcore Monkey Moderator
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,117 (5.27/day)
Thanks: 591
Thanked 5,493 Times in 2,937 Posts
|
This is from a local WI news site.
Gives you an idea what people regularly use as passwords.
__________________
Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other. Get more tech news on a wide variety of topics at NextPowerUp
|
|
|
|
| The Following User Says Thank You to Kreij For This Useful Post: |
|
|
#17 | |
|
Banstick Dummy
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,111 (6.92/day)
Thanks: 1,337
Thanked 6,834 Times in 3,741 Posts
|
Quote:
I once "fixed" a computer for someone who acted as if they pioneered software engineering yet couldn't figure out why he was getting BSOD's. I sat down on his OEM rig and discovered 32 viruses and his not so well hid porn stash. He said the viruses downloaded the porn. His wife kept asking me if that was true and I just said "Its possible" ![]() After she left I said to him "Dude come on. You hid your porn on the desktop in a folder called "(His name) Work Files" This virus knew your first name?"
Last edited by TheMailMan78; Jul 16, 2012 at 05:10 PM. |
|
|
|
|
|
|
#18 |
![]() Join Date: Jan 2009
Location: on top of that big mountain on mars(e Eu)
Posts: 1,420 (0.90/day)
Thanks: 39
Thanked 272 Times in 234 Posts
|
|
|
|
|
|
|
#19 |
|
Benevolent Dictator
Join Date: May 2004
Location: Stuttgart, Germany
Posts: 13,789 (4.18/day)
Thanks: 184
Thanked 10,270 Times in 3,173 Posts
|
I use asdfgh and variations on many sites that want me to register for some lame reason and I don't want to give them any hints of my real passwords
|
|
|
|
|
|
#20 | |
![]() Join Date: May 2012
Location: Malaysia
Posts: 254 (0.70/day)
Thanks: 16
Thanked 35 Times in 31 Posts
|
Quote:
__________________
⎝⏠⏝⏠⎠
|
|
|
|
|
|
|
#21 |
![]() Join Date: Jun 2009
Location: Houston, TX
Posts: 128 (0.09/day)
Thanks: 13
Thanked 25 Times in 24 Posts
|
After having a few friends get their email accounts hacked I started using 16-32 character passwords. I know that they are still vulnerable but the hope is they are harder to crack than lazier people. Kind of like the expression about 2 people and a bear, "I don't have to run faster than the bear, just faster than you".
If you want a totally random password then I'd suggest using PCTools Secure Password Generator. http://www.pctools.com/guides/password/ |
|
|
|
|
|
#22 |
![]() Join Date: Apr 2008
Location: Tucson, AZ
Posts: 2,975 (1.60/day)
Thanks: 740
Thanked 856 Times in 537 Posts
|
Pfft. I use 'passw0rd' and never have been hacked. [0_o]/
__________________
[o_0] - GO BUCKEYES! ------------------------------------------------------ HEATWARE /MY KEYBOARD / VIDEO OF MY LGA 2011 RIG ------------------------------------------------------ Steam: johnnyfiive ORIGIN: johnny5iive League of Legends: 5iive |
|
|
|
|
|
#23 |
![]() |
Why did they publish the passwords???
|
|
|
|
|
|
#24 |
![]() Join Date: Dec 2007
Posts: 615 (0.31/day)
Thanks: 2,255
Thanked 47 Times in 38 Posts
|
On a more serious note: are TPU's forum passwords salted? You just never know what these script kiddie fuckers will target next...
|
|
|
|
|
|
#25 |
|
Eligible for custom title
Join Date: Jan 2009
Location: ENGLAND-LAND-LAND
Posts: 8,443 (5.27/day)
Thanks: 1,188
Thanked 1,705 Times in 1,375 Posts
|
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| NVIDIA Forums Hacked | btarunr | News | 27 | Jul 16, 2012 06:13 AM |
| Email clients not remembering passwords | 7.62 | General Software | 12 | Jul 13, 2011 04:49 AM |
| sli hack not working | Corduroy_Jr | General Hardware | 0 | Apr 10, 2011 07:07 AM |
| Sli Hack Tried Everything Not Working..... Black Screen | Fallen Angel -X | NVIDIA | 7 | Jan 29, 2011 04:30 PM |