Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

611–620 of 665 posts

Re: Ken Thompson's Unix Password

#611

Earlier quoted context omitted.

I was expelled from university for pulling off the exact same exploit with the "workstation only" feature in Novell. In my case, they put a computer in every dorm room, and every single one of them had a domain-wide administrator account cached in its SAM file. It was inevitable that a student would find it. It's been almost 15 years now but I believe the password was rac3c4r or something trivial like that. I ran Oph…

Sigh, I grow tired of pointing this out, but if they were able to figure out someone was doing this, and even who it was, then you weren't a l33t hacker. You used common tools and used a known exploit that people were watching. You broke rules for personal enjoyment and weren't even good enough to not get caught. You didn't beat them, they beat you. It doesn't matter if you went unnoticed for several months, the fact…

He points out below that he was caught because another student overheard him discussing it and ratted on him. I feel like a real hacker wouldn't make a bunch of untested assumptions about situations they have no context for.

Re: Ken Thompson's Unix Password

#613

Earlier quoted context omitted.

A lot of them will use an algorithm similar to this one https://www.jwz.org/doc/threading.html

Great read! Just noting that the website redirects you to an obscene (but funny) image if this site is the Referer. Disable Referer before clicking or copy the link into the toolbar manually.

Haha, I completely forgot about that, sorry.

Re: Ken Thompson's Unix Password

#614
post #470

Earlier quoted context omitted.

Are you gonna fire Troy?

Yes, of course. Actually, I don't understand your comment.

I'm just alluding to the people that got fired and expelled for involving themselves with "passwords" in the comments above.

Re: Ken Thompson's Unix Password

#615

Earlier quoted context omitted.

I was expelled from university for pulling off the exact same exploit with the "workstation only" feature in Novell. In my case, they put a computer in every dorm room, and every single one of them had a domain-wide administrator account cached in its SAM file. It was inevitable that a student would find it. It's been almost 15 years now but I believe the password was rac3c4r or something trivial like that. I ran Oph…

Sigh, I grow tired of pointing this out, but if they were able to figure out someone was doing this, and even who it was, then you weren't a l33t hacker. You used common tools and used a known exploit that people were watching. You broke rules for personal enjoyment and weren't even good enough to not get caught. You didn't beat them, they beat you. It doesn't matter if you went unnoticed for several months, the fact…

> You broke rules for personal enjoyment and weren't even good enough to not get caught.

Otherwise known as being young and in their formative years. Plenty of HN had similar experiences and luckily even 15 years ago this harsh view on teenage stupidity was in the minority.

He also doesn't seem claim to be a l33t whatever.

> Not being prevented from accessing the system is not the same thing as successfully hacking a system unless you aren't caught either.

> You didn't beat them, they beat you.

They beat themselves, which was understandable back in the day but that's a popular narrative to this day. If a school kid with random scripts or untargeted ransomware gets into a system I put far more blame on the process that prevented them from being patched than said kid.

Re: Ken Thompson's Unix Password

#616
post #578

Earlier quoted context omitted.

Wow - this is awful. For simply getting admin rights on your own laptop? How do school admins get away with treating the kids like inmates? Good on your dad, he handled it well.

You don't get to be headmaster of a school without wanting to feel power over the kids. And if that's the only power you have in your life, you'll protect it viciously. Teachers are usually in it for the warm fuzzy feeling of doing something good, but I've never met a headmaster who didn't behave like I described above.

At my small highschool it was well known that the teachers essentially rotated being principal. They all hated it but it had to be done. While I was there it was the history teacher. Before that it was the science teacher. After I left the english teacher took over the role. Yes it was <100 people so there really was only one teacher for each subject with some overlap.

Re: Ken Thompson's Unix Password

#617
post #53
post #8

Earlier quoted context omitted.

The part before : is the hash, the part after is the cracked 8 character password.

Honestly, that confused me too. I really thought the whole password was that long.

Ditto. I was like, I get the pawn moving from Queen 2 to Queen 4, but what’s that stuff before the colon?

Re: Ken Thompson's Unix Password

#618

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

My school hacking story: 7th grade, springtime, ~1998. The district used software that ran on login and populated your desktop/start menu and permissions. This was a mixed network of windows 98 and XP for all the newer computers. I found a bug where if you corrupted your own user profile folder, windows would load a temporary one after reboot and not apply all the restrictions, giving access to explorer. You could also get access to explorer by going through the f1 help menu in a couple of different programs.

Promptly used explorer to navigate to my english teachers computer via the hidden c$ share, and delete the executable from the program files folder. Next time she logged in, BOOM nothing. no start menu, no desktop, no permissions. The admins had an incredibly consistent and predictable naming scheme, and my idiot "friends" I shared the vulnerability with promptly used this to nuke like 3 labs and a bunch of teachers computers.

Fast forward 1 month, we all got pulled out of PE by a cop and sentenced to 1-3 weeks of community service.

* I abused that profile bug to work exclusively out of portable firefox on a usb drive instead of being tied to internet explorer 6 and 7, which allowed me to bypass proxy settings and get access to gmail and read slashdot/ign/halo.bungie.org during school hours! Those were the days.

Re: Ken Thompson's Unix Password

#619

Earlier quoted context omitted.

It's probably actually easier to learn vulgar passwords. Well vulgar anything really, it's a memorization trick we were taught in school to find a way to relate boring things to sex. Probably anything that has strong emotional valence works.

Yup, Moonwalking with Einstein explains this phenomenon well. I know I'll never forget 'Sex On Hard Concrete Always Hurts The Orgasmic Areas', which my Maths teacher passed on ~30 years ago.

we always preferred the "Some Old Hippy Caught At Home Tripping On Acid"

I won't repeat the one we were told to remember Resistor color codes.

Re: Ken Thompson's Unix Password

#620

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

In high school a teacher in the computer lab tossed a piece of note paper in the garbage, a fellow student saw it, fished it out and brought it to me because I would be interested in having an admin password I guess. It was indeed the admin password for the QNX machines we used.

Life was so simple in the 80's.

Post reply on HN