techPowerUp! Forums

Go Back   techPowerUp! Forums > www.techpowerup.com > News

Reply
 
Thread Tools
Old Jul 16, 2012, 03:48 PM   #1
btarunr
Editor & Senior Moderator
 
btarunr's Avatar
 
Join Date: Oct 2007
Location: Hyderabad, India
Posts: 14,983 (7.29/day)
Thanks: 788
Thanked 12,907 Times in 5,654 Posts
Send a message via AIM to btarunr Send a message via MSN to btarunr

System Specs

NVIDIA Forums Hack: Passwords Not Salted

A group of hackers that claimed responsibility for hacking NVIDIA forums (forums.nvidia.com), which goes by the name "Team Apollo," posted the first piece of its exploits on Pastebin (find it here). The user data dump contains details of every fifth user of the forums. From what we can tell looking at the pasted data (which is now very much in the public domain), the passwords found in the user tables are not salted. NVIDIA was less than honest about that part.

The passwords are stored as raw MD5 hashes, which can be fairly-easily decrypted (when compared to hashes with salt values). To make matters worse, certain MD5 decryption websites have large databases of pre-decrypted MD5 phrases, potentially making decryption these hashes easy. Or you could just use a CUDA-accelerated MD5 decryption tool, which munches through unsalted MD5 hash values at the speed of a small supercomputer. If you have an NVIDIA Forums account, and your passwords on other websites (forums, email accounts, banks) even remotely resemble that of your NVIDIA forums account, it is strongly recommended that you change your passwords on each of those other websites.

btarunr is online now  
Reply With Quote
The Following 3 Users Say Thank You to btarunr For This Useful Post:
Old Jul 16, 2012, 03:55 PM   #2
Ikaruga
500 Posts
 
Ikaruga's Avatar
 
Join Date: Feb 2011
Posts: 642 (0.78/day)
Thanks: 391
Thanked 127 Times in 89 Posts

Ikaruga is offline  
Reply With Quote
Old Jul 16, 2012, 03:56 PM   #3
m1dg3t
1000 Posts
 
m1dg3t's Avatar
 
Join Date: May 2010
Location: Canada
Posts: 1,902 (1.73/day)
Thanks: 630
Thanked 429 Times in 353 Posts

System Specs

WOW! Good lookin' out bta
__________________

Why dazzle 'em with brilliance when you can baffle 'em with bullshit.
Alterius non sit, qui potest esse sui!
Und setzet ihr nicht das leben ein, Nie wird euch das leben gewonnen sein!

If knowledge is power, then ignorance is bliss!
If god didn't want them sheared, he wouldn't have made them sheep!
m1dg3t is offline  
Reply With Quote
Old Jul 16, 2012, 04:05 PM   #4
mayankleoboy1
5 Posts
 
Join Date: Apr 2011
Posts: 12 (0.02/day)
Thanks: 1
Thanked 6 Times in 2 Posts

using CUDA enabled crackers to crack NVIDIA passwords....
mayankleoboy1 is offline  
Reply With Quote
The Following 4 Users Say Thank You to mayankleoboy1 For This Useful Post:
Old Jul 16, 2012, 04:07 PM   #5
MaKCuMyC
25 Posts
 
MaKCuMyC's Avatar
 
Join Date: Mar 2011
Posts: 46 (0.06/day)
Thanks: 5
Thanked 4 Times in 4 Posts

System Specs

Again.
MaKCuMyC is offline  
Reply With Quote
Old Jul 16, 2012, 04:16 PM   #6
hhumas
500 Posts
 
Join Date: Jun 2011
Location: Islamabad
Posts: 529 (0.76/day)
Thanks: 170
Thanked 22 Times in 13 Posts
Send a message via MSN to hhumas Send a message via Yahoo to hhumas Send a message via Skype™ to hhumas

System Specs

hahahahhahahahah
hhumas is offline  
Reply With Quote
Old Jul 16, 2012, 04:26 PM   #7
Elmo
200 Posts
 
Elmo's Avatar
 
Join Date: May 2012
Location: Malaysia
Posts: 254 (0.70/day)
Thanks: 16
Thanked 35 Times in 31 Posts

System Specs

already decrypted one
__________________
⎝⏠⏝⏠⎠
Elmo is offline  
Reply With Quote
Old Jul 16, 2012, 04:33 PM   #8
Ikaruga
500 Posts
 
Ikaruga's Avatar
 
Join Date: Feb 2011
Posts: 642 (0.78/day)
Thanks: 391
Thanked 127 Times in 89 Posts

how do you know it's not salted? seriously please
Ikaruga is offline  
Reply With Quote
Old Jul 16, 2012, 04:38 PM   #9
newtekie1
Semi-Retired Folder
 
newtekie1's Avatar
 
Join Date: Nov 2005
Location: Indiana
Posts: 17,754 (6.48/day)
Thanks: 780
Thanked 5,116 Times in 3,707 Posts

System Specs

A good policy, and one I use, it to not use any similar passwords for important things. Each email address has a totally different password, my bank passwords are also totally different. I vary rarely use the same password for two things, though I do have one password that I use for sites that I'll probably only ever visit once and don't care about.
__________________

Rig1: System Specs.
Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5
Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD
Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate
newtekie1 is offline  
Crunching for Team TPU More than 25k PPD
Reply With Quote
Old Jul 16, 2012, 04:38 PM   #10
W1zzard
Benevolent Dictator
 
W1zzard's Avatar
 
Join Date: May 2004
Location: Stuttgart, Germany
Posts: 13,789 (4.18/day)
Thanks: 184
Thanked 10,270 Times in 3,173 Posts
Send a message via ICQ to W1zzard Send a message via AIM to W1zzard Send a message via MSN to W1zzard

System Specs

Quote:
Originally Posted by Ikaruga View Post
how do you know it's not salted? seriously please
if you md5 12345678 you get 25d55ad283aa400af464c76d713c07ad

search for that text in the posted data and you will find it three times
W1zzard is offline  
Reply With Quote
The Following 2 Users Say Thank You to W1zzard For This Useful Post:
Old Jul 16, 2012, 04:40 PM   #11
newtekie1
Semi-Retired Folder
 
newtekie1's Avatar
 
Join Date: Nov 2005
Location: Indiana
Posts: 17,754 (6.48/day)
Thanks: 780
Thanked 5,116 Times in 3,707 Posts

System Specs

Quote:
Originally Posted by W1zzard View Post
if you md5 12345678 you get 25d55ad283aa400af464c76d713c07ad

search for that text in the posted data and you will find it three times
OMG! That is the combination to my luggage!
__________________

Rig1: System Specs.
Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5
Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD
Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate
newtekie1 is offline  
Crunching for Team TPU More than 25k PPD
Reply With Quote
The Following 4 Users Say Thank You to newtekie1 For This Useful Post:
Old Jul 16, 2012, 04:40 PM   #12
Kreij
Hardcore Monkey Moderator
 
Kreij's Avatar
 
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,117 (5.27/day)
Thanks: 591
Thanked 5,493 Times in 2,937 Posts

System Specs

Hash "qwerty" and I'm sure you will get some matches too.
__________________

Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other.


Get more tech news on a wide variety of topics at NextPowerUp
Kreij is offline  
Reply With Quote
Old Jul 16, 2012, 04:41 PM   #13
Ikaruga
500 Posts
 
Ikaruga's Avatar
 
Join Date: Feb 2011
Posts: 642 (0.78/day)
Thanks: 391
Thanked 127 Times in 89 Posts

Quote:
Originally Posted by W1zzard View Post
if you md5 12345678 you get 25d55ad283aa400af464c76d713c07ad

search for that text in the posted data and you will find it three times
thank you dear good sir
Ikaruga is offline  
Reply With Quote
Old Jul 16, 2012, 04:42 PM   #14
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,111 (6.92/day)
Thanks: 1,337
Thanked 6,834 Times in 3,741 Posts

System Specs

Quote:
Originally Posted by newtekie1 View Post
A good policy, and one I use, it to not use any similar passwords for important things. Each email address has a totally different password, my bank passwords are also totally different. I vary rarely use the same password for two things, though I do have one password that I use for sites that I'll probably only ever visit once and don't care about.
Indeed. NONE of my passwords are the same.
TheMailMan78 is offline  
Reply With Quote
Old Jul 16, 2012, 04:44 PM   #15
newtekie1
Semi-Retired Folder
 
newtekie1's Avatar
 
Join Date: Nov 2005
Location: Indiana
Posts: 17,754 (6.48/day)
Thanks: 780
Thanked 5,116 Times in 3,707 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
Indeed. NONE of my passwords are the same.
Yeah, in a perfect world no one should have to worry about this. Then again, apparently some of the users used 12345678 as their passwords, so we obviously aren't in a perfect world.
__________________

Rig1: System Specs.
Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5
Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD
Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate
newtekie1 is offline  
Crunching for Team TPU More than 25k PPD
Reply With Quote
Old Jul 16, 2012, 04:57 PM   #16
Kreij
Hardcore Monkey Moderator
 
Kreij's Avatar
 
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,117 (5.27/day)
Thanks: 591
Thanked 5,493 Times in 2,937 Posts

System Specs

This is from a local WI news site.
Gives you an idea what people regularly use as passwords.
__________________

Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other.


Get more tech news on a wide variety of topics at NextPowerUp
Kreij is offline  
Reply With Quote
The Following User Says Thank You to Kreij For This Useful Post:
Old Jul 16, 2012, 05:04 PM   #17
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,111 (6.92/day)
Thanks: 1,337
Thanked 6,834 Times in 3,741 Posts

System Specs

Quote:
Originally Posted by newtekie1 View Post
Yeah, in a perfect world no one should have to worry about this. Then again, apparently some of the users used 12345678 as their passwords, so we obviously aren't in a perfect world.
Well as dumb as I am compared to a few users on TPU about tech stuff I ain't THAT dumb. I think a lot of the older TPU crowd is far more tech savvy then the average user.

I once "fixed" a computer for someone who acted as if they pioneered software engineering yet couldn't figure out why he was getting BSOD's. I sat down on his OEM rig and discovered 32 viruses and his not so well hid porn stash. He said the viruses downloaded the porn. His wife kept asking me if that was true and I just said "Its possible"

After she left I said to him "Dude come on. You hid your porn on the desktop in a folder called "(His name) Work Files" This virus knew your first name?"

Last edited by TheMailMan78; Jul 16, 2012 at 05:10 PM.
TheMailMan78 is offline  
Reply With Quote
The Following 2 Users Say Thank You to TheMailMan78 For This Useful Post:
Old Jul 16, 2012, 05:07 PM   #18
DarkOCean
1000 Posts
 
DarkOCean's Avatar
 
Join Date: Jan 2009
Location: on top of that big mountain on mars(e Eu)
Posts: 1,420 (0.90/day)
Thanks: 39
Thanked 272 Times in 234 Posts

System Specs

Quote:
Originally Posted by newtekie1 View Post
Yeah, in a perfect world no one should have to worry about this. Then again, apparently some of the users used 12345678 as their passwords, so we obviously aren't in a perfect world.
They obviously did not consider their accounts as being important.
DarkOCean is offline  
Reply With Quote
Old Jul 16, 2012, 05:10 PM   #19
W1zzard
Benevolent Dictator
 
W1zzard's Avatar
 
Join Date: May 2004
Location: Stuttgart, Germany
Posts: 13,789 (4.18/day)
Thanks: 184
Thanked 10,270 Times in 3,173 Posts
Send a message via ICQ to W1zzard Send a message via AIM to W1zzard Send a message via MSN to W1zzard

System Specs

I use asdfgh and variations on many sites that want me to register for some lame reason and I don't want to give them any hints of my real passwords
W1zzard is offline  
Reply With Quote
The Following 2 Users Say Thank You to W1zzard For This Useful Post:
Old Jul 16, 2012, 05:12 PM   #20
Elmo
200 Posts
 
Elmo's Avatar
 
Join Date: May 2012
Location: Malaysia
Posts: 254 (0.70/day)
Thanks: 16
Thanked 35 Times in 31 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
Well as dumb as I am compared to a few users on TPU about tech stuff I ain't THAT dumb. I think a lot of the older TPU crowd is far more tech savvy then the average user.

I once "fixed" a computer for someone who acted as if they pioneered software engineering yet couldn't figure out why he was getting BSOD's. I sat down on his OEM rig and discovered 32 viruses and his not so well hid porn stash. He said the viruses downloaded the porn. His wife kept asking me if that was true and I just said "Its possible"

After she left I said to him "Dude come on. You hid your porn on the desktop in a folder called "(His name) Work Files" This virus knew your first name?"
Now this deserves a gold award as it made me laugh.
__________________
⎝⏠⏝⏠⎠
Elmo is offline  
Reply With Quote
Old Jul 16, 2012, 05:23 PM   #21
Major_A
75 Posts
 
Major_A's Avatar
 
Join Date: Jun 2009
Location: Houston, TX
Posts: 128 (0.09/day)
Thanks: 13
Thanked 25 Times in 24 Posts

System Specs

After having a few friends get their email accounts hacked I started using 16-32 character passwords. I know that they are still vulnerable but the hope is they are harder to crack than lazier people. Kind of like the expression about 2 people and a bear, "I don't have to run faster than the bear, just faster than you".

If you want a totally random password then I'd suggest using PCTools Secure Password Generator.
http://www.pctools.com/guides/password/
Major_A is offline  
Reply With Quote
Old Jul 16, 2012, 05:37 PM   #22
johnnyfiive
2000 Posts
 
johnnyfiive's Avatar
 
Join Date: Apr 2008
Location: Tucson, AZ
Posts: 2,975 (1.60/day)
Thanks: 740
Thanked 856 Times in 537 Posts

System Specs

Pfft. I use 'passw0rd' and never have been hacked. [0_o]/
__________________
[o_0] - GO BUCKEYES!
------------------------------------------------------
HEATWARE /MY KEYBOARD / VIDEO OF MY LGA 2011 RIG

------------------------------------------------------
Steam: johnnyfiive
ORIGIN: johnny5iive
League of Legends: 5iive
johnnyfiive is offline  
Reply With Quote
Old Jul 16, 2012, 05:52 PM   #23
Aleksander
2000 Posts
 
Aleksander's Avatar
 
Join Date: Dec 2009
Posts: 3,028 (2.39/day)
Thanks: 648
Thanked 280 Times in 228 Posts

System Specs

Why did they publish the passwords???
Aleksander is offline  
Reply With Quote
Old Jul 16, 2012, 05:55 PM   #24
1c3d0g
500 Posts
 
1c3d0g's Avatar
 
Join Date: Dec 2007
Posts: 615 (0.31/day)
Thanks: 2,255
Thanked 47 Times in 38 Posts

On a more serious note: are TPU's forum passwords salted? You just never know what these script kiddie fuckers will target next...
1c3d0g is offline  
Reply With Quote
Old Jul 16, 2012, 05:56 PM   #25
pantherx12
Eligible for custom title
 
pantherx12's Avatar
 
Join Date: Jan 2009
Location: ENGLAND-LAND-LAND
Posts: 8,443 (5.27/day)
Thanks: 1,188
Thanked 1,705 Times in 1,375 Posts

System Specs

Quote:
Originally Posted by Aleksander Dishnica View Post
Why did they publish the passwords???
To prove that they had them.

Is anyone elses Techpowerup password techpowerup.....
pantherx12 is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
NVIDIA Forums Hacked btarunr News 27 Jul 16, 2012 06:13 AM
Email clients not remembering passwords 7.62 General Software 12 Jul 13, 2011 04:49 AM
sli hack not working Corduroy_Jr General Hardware 0 Apr 10, 2011 07:07 AM
Sli Hack Tried Everything Not Working..... Black Screen Fallen Angel -X NVIDIA 7 Jan 29, 2011 04:30 PM


All times are GMT. The time now is 05:43 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts