Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

531–540 of 665 posts

Re: Ken Thompson's Unix Password

#531

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

In our engineering school the password hash used to be publicly accessible. Someone had devised a johntheripper binary to look like seti@home and made it run on several machines with the admins' benediction.

We had a meagre limited amount of quota on these shared systems (between 1 and 10 MB) but teachers had 1 GB. We stored the Quake binary on one teacher's account, Starcraft 1 on another and start kicking.

Good times...

Re: Ken Thompson's Unix Password

#532
post #483

Earlier quoted context omitted.

Our high school network ran on Novell NetWare, but I wasn't anywhere near smart enough to crack anything so I just wrote a little program in QBASIC that looked like the NetWare login prompt which rejected all login attempts but dumped what was entered into a text file, and left it running on one of the PCs in the computer room. It wasn't even a compiled program, it was just running inside QBASIC's IDE. Yet it was run…

This is exactly why some versions of Windows required you to press ctrl-alt-delete to open the login form. Programs aren't allowed to block Windows from receiving ctrl-alt-delete, so a fake login program would not be able to stay on the screen after the user pressed ctrl-alt-delete. (Of course this only works if the user knows to always hit ctrl-alt-delete when they go to login. If the user sees an already-open (fake…

I think ctrl-alt-delete generates a hardware interrupt.

Re: Ken Thompson's Unix Password

#533

Earlier quoted context omitted.

I said "being creepy" because I was being vague. He was doing much worse than that.

Like what? I have an ex-girlfriend whom I dumped when she (among other things) called my family and lied about me getting into a horrible accident because we were arguing about her [several hard street drugs] addiction. I cared about her enough to stick around until after the drug problems started. She tells people I'm a "creep" when she explains why we didn't work out, because we had been together for a while and I…

Sorry to hear about an unpleasant situation. However, I think it's safe to assume this is unrelated to the story about the dude's password and HR issues.

Re: Ken Thompson's Unix Password

#534

Earlier quoted context omitted.

>I never once used it for evil: never read anyone's email, never viewed anyone's private files, never poked around the academic file shares for test solutions, never tried to steal credit card numbers or social security numbers from the finance office's file share. I don't understand this justification. The system owners can't know that to be true and have to proceed as if the systems are compromised. Would you still…

Isn't this more like duplicating everyones house key? He never actually went into the houses.

Only if you can know he didn't actually go in. Even now, do you believe he never liked at a single private file?

Re: Ken Thompson's Unix Password

#535

Earlier quoted context omitted.

Like what? I have an ex-girlfriend whom I dumped when she (among other things) called my family and lied about me getting into a horrible accident because we were arguing about her [several hard street drugs] addiction. I cared about her enough to stick around until after the drug problems started. She tells people I'm a "creep" when she explains why we didn't work out, because we had been together for a while and I…

Sorry to hear about an unpleasant situation. However, I think it's safe to assume this is unrelated to the story about the dude's password and HR issues.

My password says "FUCK [a woman whom I no longer have an intimate relationship with]". This doesn't concern you? Does it concern 'jedberg?

Re: Ken Thompson's Unix Password

#536

Earlier quoted context omitted.

Sorry to hear about an unpleasant situation. However, I think it's safe to assume this is unrelated to the story about the dude's password and HR issues.

My password says "FUCK [a woman whom I no longer have an intimate relationship with]". This doesn't concern you? Does it concern 'jedberg?

Well it's none of my business and after the story you've shared I can't say I am very concerned. But in the story about HR, they looked into it and there was "other stuff", I guess they concluded something else about that situation.

We don't know what that "other stuff" is and if it's right or wrong, but it's also likely not the exact same situation as your very detailed and specific story, is my point.

Re: Ken Thompson's Unix Password

#537

Earlier quoted context omitted.

Do you know how they ended up finding out about it and catching you?

Yeah. My technical tracks were covered. It was the roommate of one of my friends. He overheard me talking about it and ratted me out.

wow, that's very scummy. That must feel worse than them finding you because you slipped up technically.

Re: Ken Thompson's Unix Password

#538
post #407

Earlier quoted context omitted.

I've never done anything malicious with the knowledge, but I've totally learned people's passwords just by watching their fingers type. I make an effort to have passwords that would be difficult for a human to nail down while watching them typed quickly in real time. The ubiquity of cameras has me reconsidering input and/or authentication mechanisms, though.

One good thing about using dvorak I guess

At one point I considered learning Dvorak and then having a password that was using the Dvorak key layout but on a Qwerty keyboard.

But I only made it maybe a month into my Dvorak-learning efforts. Just not enough benefit for the added hassle.

Re: Ken Thompson's Unix Password

#539

Earlier quoted context omitted.

>I never once used it for evil: never read anyone's email, never viewed anyone's private files, never poked around the academic file shares for test solutions, never tried to steal credit card numbers or social security numbers from the finance office's file share. I don't understand this justification. The system owners can't know that to be true and have to proceed as if the systems are compromised. Would you still…

Isn't this more like duplicating everyones house key? He never actually went into the houses.

Except he went in the Admin's house:

> I'd just log in with the admin account and run pwdump

Re: Ken Thompson's Unix Password

#540

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

I wish my story was as cool and involved some technical expertise. In year 10, a friend of mine saw our school network admin type the admin password in (he used his index fingers and typed in each character one at a time like someone with very little typing experience - this was 1998) Anyway, I used this info to log in as the admin and I promptly deleted all of the student accounts in the school. Students around me i…

Oh, did something similar to change a friend's grades in college. Pretended to be on my smartphone while the professor signed in, and filmed their fingers on the keyboard. Took some trial and error watching the low-res video (this was before phones had nice cameras) frame by frame to figure out which keys he was hitting.
Post reply on HN