Silkroad Online Forums

A community forum for the free online game Silkroad Online. Discuss Silkroad Online, read up on guides, and build your character and skills.

Faq Search Members Chat  Register Profile Login

All times are UTC




Post new topic Reply to topic  [ 57 posts ]  Go to page Previous  1, 2
Author Message
 Post subject:
PostPosted: Sat Sep 22, 2007 9:02 pm 
Valued Member
Offline

Joined: Aug 2007
Posts: 457
Cruor wrote:
Cracking passwords:
Code:
Pass Length.....All Characters..............Only Lowercase

3 characters....0.86 seconds................0.02 seconds
4 characters....1.36 minutes................0.046 seconds
5 characters....2.15 hours..................11.9 seconds
6 characters....8.51 days...................5.15 minutes
7 characters....2.21 years..................2.23 hours
8 characters....2.10 centuries..............2.42 days
9 characters....20 millennia................2.07 months
10 characters...1,899 millennia.............4.48 years
11 characters...180,365 millennia...........1.16 centuries
12 characters...17,184,705 millennia........3.03 millennia
13 characters...1,627,797,068 millennia.....78.7 millennia
14 characters...154,640,721,434 millennia...2,046 millennia

These times are for an average computer, attempting to brute force your password, meaning it assumes you have a completely random password; passwords with any form of words in them are far easier to crack, and using 1337-speak in attempt to hide it won't help you any.

The first column is what you could expect if Joymax let you use all ASCII characters, including uppercase and symbols.

We are all in the second column, because only a-z, 0-9 are allowed. It's best to at least change your password at least once within the time period it could be cracked in, however it's even better to change it on a daily or weekly basis.

it is shorter than that if the hacker is experienced and the victim is an dumbass.

_________________
<<banned from SRF for bot admission and rules violations. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 9:13 pm 
Ex-Staff
User avatar
Offline

Joined: Jan 2006
Posts: 2639
Location: 4 hour jack sessions with stallowned
3.03 millennia woot woot

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 9:14 pm 
Casual Member
User avatar
Offline

Joined: Jan 2007
Posts: 77
Location:
Babel
ZiNC wrote:
it is shorter than that if the hacker is experienced and the victim is an dumbass.


And significantly longer than that if the victim is reasonable clever and Joymax has not exposed their encrypted password list.

A reasonable advanced password, given 200 milliseconds latency and 10 minutes for extra for each 3 attempts, quickly becomes unwieldy to brute force fast enough.

I was however very annoyed when they reduced the characters you could use for your password. Suddenly I could not login to the web-site any longer since my password contained quite a few special characters. Logging in to the game still worked - so I did not notice until I planned to buy silk.


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 9:16 pm 
Chronicle Writer
User avatar
Offline

Joined: Jan 2007
Posts: 9841
Location: US - Illidan
Cruor wrote:
Cracking passwords:
Code:
Pass Length.....All Characters..............Only Lowercase

3 characters....0.86 seconds................0.02 seconds
4 characters....1.36 minutes................0.046 seconds
5 characters....2.15 hours..................11.9 seconds
6 characters....8.51 days...................5.15 minutes
7 characters....2.21 years..................2.23 hours
8 characters....2.10 centuries..............2.42 days
9 characters....20 millennia................2.07 months
10 characters...1,899 millennia.............4.48 years
11 characters...180,365 millennia...........1.16 centuries
12 characters...17,184,705 millennia........3.03 millennia
13 characters...1,627,797,068 millennia.....78.7 millennia
14 characters...154,640,721,434 millennia...2,046 millennia

These times are for an average computer, attempting to brute force your password, meaning it assumes you have a completely random password; passwords with any form of words in them are far easier to crack, and using 1337-speak in attempt to hide it won't help you any.

The first column is what you could expect if Joymax let you use all ASCII characters, including uppercase and symbols.

We are all in the second column, because only a-z, 0-9 are allowed. It's best to at least change your password at least once within the time period it could be cracked in, however it's even better to change it on a daily or weekly basis.


:shock: im so f*cked if someone wants to brute my pass....where do you find this stuff cruor, never cease to amaze me.

_________________
Image Image
signatures by Hostage Co. <3
~PoP is DEAD! My sTyLe is Supa-Flat!!~


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 9:30 pm 
Loyal Member
User avatar
Offline

Joined: Apr 2006
Posts: 1999
Location:
Off Topic
yoko wrote:
And significantly longer than that if the victim is reasonable clever and Joymax has not exposed their encrypted password list.

A reasonable advanced password, given 200 milliseconds latency and 10 minutes for extra for each 3 attempts, quickly becomes unwieldy to brute force fast enough.

I was however very annoyed when they reduced the characters you could use for your password. Suddenly I could not login to the web-site any longer since my password contained quite a few special characters. Logging in to the game still worked - so I did not notice until I planned to buy silk.
Yes, such speeds likely aren't attainable should the hacker merely try to brute force it through SRO, however if the user reused his password elsewhere and the hacker has access to that database, it could potentially be brute forced. Regardless, it does show you how much we are screwed over with our limited passwords and how much extra characters can help you out.

The weak point in the current system seems to be the secret question page, because all a hacker needs to change your password is your email and some research about you for the secret answer. A long, random password will probably keep you safe but if you aren't willing to remember one or type it in every time you want to log in, at least lock up your secret question. Because the secret question requires the hacker to have your email, you can basically make your email into a second password. Just go to Gmail or something and register an email account with a nice random name then change your SRO account's email to that and never use it for anything else. That will effectively protect your account from being outright stolen.

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 9:37 pm 
Casual Member
User avatar
Offline

Joined: Jan 2007
Posts: 77
Location:
Babel
Cruor wrote:
Yes, such speeds likely aren't attainable should the hacker merely try to brute force it through SRO, however if the user reused his password elsewhere and the hacker has access to that database, it could potentially be brute forced. Regardless, it does show you how much we are screwed over with our limited passwords and how much extra characters can help you out.


Re-using passwords are not a good idea. It is easy to fall into the trap of doing so. I would personally recommend Password Safe for storing and generating your passwords. Most websites you can easily paste your very complex password in - for Silkroad, just practice it until your hands know how to type it and you be fine. I type my password very very quickly.

Cruor wrote:
The weak point in the current system seems to be the secret question page, because all a hacker needs to change your password is your email and some research about you for the secret answer. A long, random password will probably keep you safe but if you aren't willing to remember one or type it in every time you want to log in, at least lock up your secret question. Because the secret question requires the hacker to have your email, you can basically make your email into a second password. Just go to Gmail or something and register an email account with a nice random name then change your SRO account's email to that and never use it for anything else. That will effectively protect your account from being outright stolen.


The secret question (and the e-mail) is by far the most exposed details for Silkroad. Become friendly, ask for MSN (most people will have same MSN address as their Silkroad e-mail), then just ask innocent questions of favourite colour, where they are born, what film they like the most etc. etc. etc. Bingo - you got their account.

So, do as Cruor says, make an e-mail address just for the purpose of the game. Have a long password and learn it well. Do not use the password for any other place.


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 9:48 pm 
Chronicle Writer
User avatar
Offline

Joined: Jan 2007
Posts: 9841
Location: US - Illidan
i was going to make a new character anyway....this time i'll start it on a new account

_________________
Image Image
signatures by Hostage Co. <3
~PoP is DEAD! My sTyLe is Supa-Flat!!~


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 10:30 pm 
Loyal Member
User avatar
Offline

Joined: Jun 2006
Posts: 1550
Location:
Xian
I'd have liked the ability of at least using lower and uppercase letters in your PWs ... and the fact that your first 3 characters have to be letters also limits the extra-protection it might give.

Nice footage btw Cruor ... you smartass :P :love:

_________________
Chaby wrote:
I'm famous, but that's because I'm the biggest attention whore.

Crumpets wrote:
If you had sexual intercourse with an 0x33 member who has 'paid' clockwork .. would that be an offense?


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 10:33 pm 
Ex-Staff
User avatar
Offline

Joined: Jul 2007
Posts: 9250
Location: Sand
MonstaH wrote:
I'd have liked the ability of at least using lower and uppercase letters in your PWs ... and the fact that your first 3 characters have to be letters also limits the extra-protection it might give.

Nice footage btw Cruor ... you smartass :P :love:


the first 3 letter dont have 2 b numbers
>.>
<.<

_________________
Maddening
Image


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 11:14 pm 
Common Member
User avatar
Offline

Joined: Jun 2007
Posts: 163
Location: look behind you..........
Belgarath wrote:
My password is "This thread should be locked."


LMAO yea be afraid BE VERY AFRAID of me wanting to h4xur3d all of you. i think by the time i h4xur some one i'll be 17,184,705 millennia +9 yrs old :P


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 22, 2007 11:16 pm 
Ex-Staff
User avatar
Offline

Joined: Jun 2006
Posts: 1197
Location: Artist's Corner
Was using 12 when I was playing.

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 12:16 am 
Frequent Member
User avatar
Offline

Joined: Dec 2006
Posts: 1284
Location:
Xian
Matrixman__ wrote:
i dont even know, havent typed it in such a long time, i use my G15 keyboard macro to enter username, password and hit enter for me all with only 1 button

I've heard ppl wrote their info in town by accident with that method.

_________________
Image
Image


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 1:46 am 
Valued Member
User avatar
Offline

Joined: Nov 2006
Posts: 361
Location:
Sparta
lol my secret question was where i was born....the good thing on my part, is that the answer is a 15 digit # and letter string that i dont use anywhere else, good luck xD, cuz my pass is even harder than that, and i use a gmail address just like cruor said......security ftw!

_________________
Image
IGN: EvilDiablo
lvl: 55
[SD]draquish wrote:
Ju goat dhat en ju goat er een da sakk ma boi.


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 1:50 am 
Banned User
Offline

Joined: Mar 2007
Posts: 3467
Location:
Babel
Long enough for it to be secure, short enough for me to remember :)

With practice, you could type any password quick enough.

_________________
<<banned from SRF for bot support. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 1:59 am 
Valued Member
User avatar
Offline

Joined: Jun 2007
Posts: 488
Location:
Venus
My secret answer has nothing to do with the question :P

_________________
Retired noob.


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 2:00 am 
Active Member
Offline

Joined: Jun 2007
Posts: 666
Location:
Off Topic
lol @ millennia.. haven't heard that word for quite some time

_________________
<<banned from SRF for bot admission. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 5:09 am 
Common Member
User avatar
Offline

Joined: Jun 2007
Posts: 163
Location: look behind you..........
G-mail? :? whats that?


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 5:14 am 
Banned User
Offline

Joined: Mar 2007
Posts: 3467
Location:
Babel
TemJiN wrote:
G-mail? :? whats that?


mail.google.com

_________________
<<banned from SRF for bot support. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 5:27 am 
Chronicle Writer
User avatar
Offline

Joined: Jan 2007
Posts: 9841
Location: US - Illidan
Sylhana wrote:
TemJiN wrote:
G-mail? :? whats that?


mail.google.com


do you have to be invited or can you just make one when you want

_________________
Image Image
signatures by Hostage Co. <3
~PoP is DEAD! My sTyLe is Supa-Flat!!~


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 5:38 am 
Banned User
Offline

Joined: Mar 2007
Posts: 3182
Location:
Babel
I change mine every inspection so it varies.

_________________
<<banned from SRF for proof of botting. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 6:01 am 
Banned User
Offline

Joined: Mar 2007
Posts: 3467
Location:
Babel
XemnasXD wrote:
Sylhana wrote:
TemJiN wrote:
G-mail? :? whats that?


mail.google.com


do you have to be invited or can you just make one when you want


EDIT: Before they require you to have an invite. I think you can just sign up now w/o one.

_________________
<<banned from SRF for bot support. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 7:45 am 
Valued Member
Offline

Joined: Aug 2007
Posts: 457
Sylhana wrote:
XemnasXD wrote:
Sylhana wrote:
TemJiN wrote:
G-mail? :? whats that?


mail.google.com


do you have to be invited or can you just make one when you want


EDIT: Before they require you to have an invite. I think you can just sign up now w/o one.

ya now its like hotmail you just go and sigh up.

_________________
<<banned from SRF for bot admission and rules violations. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 8:43 am 
Banned User
User avatar
Offline

Joined: Sep 2006
Posts: 1574
Location:
Greece
12 here, brute forcing takes time if its MD5 (lol @MD5 i still use that in my PHP >.>)

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 2:59 pm 
Active Member
User avatar
Offline

Joined: Sep 2007
Posts: 720
Location:
Venus
Twist wrote:
Belgarath wrote:
My password is "This thread should be locked."


Wow,mine too :P



shit thats mine! im gonna be hacked again! :o


:P

_________________
Image

Thanks MasterKojito for the sig <3


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 3:14 pm 
Banned User
Offline

Joined: Sep 2006
Posts: 3895
Location: Artists Corner & Aege
lol at "17,184,705 millennia"

good luck? :P

_________________
<<banned from SRF for proof of botting. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 3:15 pm 
Banned User
User avatar
Offline

Joined: Sep 2007
Posts: 1496
Location: BEEN DERPIN ALL DAY DERP DERP
Lol,thats just bruteforce dont forget u can be keylogged,so 150 char pass will be taken in 3 seconds lol.

_________________
<<Account shut down to prevent sockpuppeting. New user accountname "hey">>


Top
 Profile  
 
 Post subject:
PostPosted: Sun Sep 23, 2007 4:58 pm 
Addicted Member
User avatar
Offline

Joined: Jun 2007
Posts: 2583
Location: :|
Cruor wrote:
Cracking passwords:
Code:
Pass Length.....All Characters..............Only Lowercase

3 characters....0.86 seconds................0.02 seconds
4 characters....1.36 minutes................0.046 seconds
5 characters....2.15 hours..................11.9 seconds
6 characters....8.51 days...................5.15 minutes
7 characters....2.21 years..................2.23 hours
8 characters....2.10 centuries..............2.42 days
9 characters....20 millennia................2.07 months
10 characters...1,899 millennia.............4.48 years
11 characters...180,365 millennia...........1.16 centuries
12 characters...17,184,705 millennia........3.03 millennia
13 characters...1,627,797,068 millennia.....78.7 millennia
14 characters...154,640,721,434 millennia...2,046 millennia

These times are for an average computer, attempting to brute force your password, meaning it assumes you have a completely random password; passwords with any form of words in them are far easier to crack, and using 1337-speak in attempt to hide it won't help you any.

The first column is what you could expect if Joymax let you use all ASCII characters, including uppercase and symbols.

We are all in the second column, because only a-z, 0-9 are allowed. It's best to at least change your password at least once within the time period it could be cracked in, however it's even better to change it on a daily or weekly basis.

FCK
they hack mine in 11 seconds ><

_________________
Spoiler!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 57 posts ]  Go to page Previous  1, 2

All times are UTC


Who is online

Users browsing this forum: No registered users and 19 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group