Protect your sites with real Passwords

Learn about Security for code and servers. Learn how to secure your site and your code. Learn about hacking prevention, finding and identifying exploits, and recognising vulnerabilities. Plus, Weekly Security tips and Tutorials.
Forum rules
Post questions related to security, analyse and learn about vulnerabilities and exploits within code to protect yourself against hackers.

Protect your sites with real Passwords

Postby topdown » 08 Feb 2009, 12:26

Do to the nature of hackers/crackers we have to do better to secure our sites.
Especially Admin and C-Panel accounts.
I actually use to use a memorable password letter number mix, but it simply isn't good enough anymore.
BAD : my3good4pass This can get Bruteforced
GOOD : IxKUozu9EZiA0iWJ3TnQ Good luck hacking that ;)
For a good break down on passwords, check out this post
So here are some great little programs to fix that, so you can have long highly mixed passwords and different for every site.

Pointed out to me by Brainy in the phpBB Weekly Podcast
[11:44:53 AM] <Brainy> Check out KeePass


Well here it is
http://keepass.info/
Excellent little program that can give you all kinds of generated passwords, long, mixed, and store them in a secure database on a locked USB stick.

Works good on my Vista (32) and has 64 bit drivers so it should work there also.
For Mac read the next post :grin:
Image
Valid Webs Web Development My Mods SVN phpBB Development Wiki
Do not PM me for Support unless I give permission in a post......PM's only help one, posts help everyone !
User avatar
topdown    
STG Styles Leader
STG Styles Leader
 
Posts: 2559
Joined: 01 Oct 2007, 22:56
Location: Handyman's harddrive
Favorite Team: STG Teams
Gender: Male
phpBB Knowledge: 8


Re: Protect your sites with real Passwords

Postby mtotheikle » 08 Feb 2009, 12:36

If you are running a Mac I would urge you to buy 1Password. Yes it is expensive, but it is a great program and you can make sure your passwords are strong.
"You have a lifetime to learn technique. But I can teach you what is more important than technique: How to see. Learn that and all you have to do afterwards is press the shutter." - Garry Winogrand

I have turned into a Military Sergeant and Highway of Life and Handyman are my newest privates under my command. Don't be scared anyone, this is all for your good!

Image
User avatar
mtotheikle    
STG Development Leader
STG Development Leader
 
Posts: 1054
Joined: 10 Oct 2007, 22:43
Location: Washington
Favorite Team: Seahawks
Gender: Male
phpBB Knowledge: 10

Re: Protect your sites with real Passwords

Postby brodo » 08 Feb 2009, 15:51

If you only used Safari would that suffice and be "strong" enough to save passwords?
brodo    
Crewman
Crewman
 
Posts: 9
Joined: 07 Feb 2009, 15:05
Location: UK
Gender: Male
phpBB Knowledge: 1

Re: Protect your sites with real Passwords

Postby 3Di » 08 Feb 2009, 16:02

got this: http://keepass.info/ I'll give it a shot.
Give Peace A Chance.. Pass ON It!
Image
The door that leads to the Glory is very narrow but it is mandatory to be Great to be able to cross it.
------------------------- phpBB wiki in Italiano - partecipa con il tuo contributo -----------------------
User avatar
3Di    
MOD Author
MOD Author
 
Posts: 247
Joined: 22 Apr 2008, 14:09
Location: Italy
Favorite Team: Milan
Gender: Male
phpBB Knowledge: 8

Re: Protect your sites with real Passwords

Postby cherokee red » 08 Feb 2009, 16:10

topdown wrote:GOOD : IxKUozu9EZiA0iWJ3TnQ Good luck hacking that ;) .

Good, but adding a symbol or 2 in there would make it even better ;)

IxKU$zu9&ZiA0iWJ%TnQ
// 6 String Romance Music // 6 String Romance // Myspace // MODs Development //
Are you a musician in the Glasgow area interested in acoustic events? The ArtBox
User avatar
cherokee red    
Supporter
Supporter
 
Posts: 99
Joined: 04 Apr 2008, 12:02
Location: Airdrie, UK
Favorite Team: Airdrie United
Gender: Male
phpBB Knowledge: 8

Re: Protect your sites with real Passwords

Postby topdown » 08 Feb 2009, 16:22

Which is better, but some sites don't allow symbols only abc/123's :grin:
That app has the potential of creating passwords in just about any possible variation.
Image
Valid Webs Web Development My Mods SVN phpBB Development Wiki
Do not PM me for Support unless I give permission in a post......PM's only help one, posts help everyone !
User avatar
topdown    
STG Styles Leader
STG Styles Leader
 
Posts: 2559
Joined: 01 Oct 2007, 22:56
Location: Handyman's harddrive
Favorite Team: STG Teams
Gender: Male
phpBB Knowledge: 8

Re: Protect your sites with real Passwords

Postby Erik Frèrejean » 08 Feb 2009, 16:24

topdown wrote:Which is better, but some sites don't allow symbols only abc/123's :grin:

Those sites are nub++ and you shouldn't use them, same as for silly maximum character limitations on passwords :blackeye:
Image Proud member of the phpBB support team
Image STG Support team member | Image STG Moderator team member
Image
User avatar
Erik Frèrejean    
phpBB Team Member
phpBB Team Member
 
Posts: 1021
Joined: 03 Dec 2007, 00:49
Location: USERS_TABLE
Favorite Team: phpBB teams
Gender: Male
phpBB Knowledge: 9

Re: Protect your sites with real Passwords

Postby brodo » 08 Feb 2009, 16:55

The 1Password for Mac demo is good... an excellent password generator included along with several other features... I can see this is going to cost me money... :cry:

Just tried the generator up full to create a password for here but it was deemed to long. :D
brodo    
Crewman
Crewman
 
Posts: 9
Joined: 07 Feb 2009, 15:05
Location: UK
Gender: Male
phpBB Knowledge: 1

Re: Protect your sites with real Passwords

Postby Highway of Life » 08 Feb 2009, 17:06

Erik Frèrejean wrote:
topdown wrote:Which is better, but some sites don't allow symbols only abc/123's :grin:

Those sites are nub++ and you shouldn't use them, same as for silly maximum character limitations on passwords :blackeye:
You are correct on both counts, but I did want to point out that phpBB3 has a character limitation as well... which the administrator can set, but is usually 25-30 or more chars.
The safest passwords to use contain the following:
  1. MiXeD CasE letters.
  2. Non-dictionary words, nonsense, or gobbledegook.
  3. Numbers interspersed and in no particular pattern.
  4. At least 2 symbols, but the more the better. (i.e. #%(*!^@$)
  5. Between 20 and 30 chars, the longer, the safer.

Really tough passwords are especially important for accounts such as:
  1. Your Server access, root access passwords.
  2. Your Database access passwords.
  3. Your cPanel access passwords.
  4. Your password for your administrator account on any software running on your server, including but not limited to phpBB.
  5. eBay, PayPal, your online bank, credit card accounts or other accounts that could contain bank accounts, credit card numbers, social security numbers, or even your physical mailing address.
All of the above type of accounts you should never access on public or shared computers, but should always be accessed by your computer and have a password management program manage your passwords for these accounts so that you do not need to memorise them. As a general rule of thumb, if you can remember your password, it is not safe.
Watch out! I might do a code wheelie!

User avatar
Highway of Life    
STG Jedi Master
STG Jedi Master
 
Posts: 10423
Joined: 08 May 2006, 05:23
Location: Beware of Programmers carrying screwdrivers
Gender: Male
phpBB Knowledge: 10

Re: Protect your sites with real Passwords

Postby Erik Frèrejean » 09 Feb 2009, 02:10

Highway of Life wrote:
Erik Frèrejean wrote:
topdown wrote:Which is better, but some sites don't allow symbols only abc/123's :grin:

Those sites are nub++ and you shouldn't use them, same as for silly maximum character limitations on passwords :blackeye:
You are correct on both counts, but I did want to point out that phpBB3 has a character limitation as well... which the administrator can set, but is usually 25-30 or more chars.

I'm aware of that and 30 is a reasonable limit. I know however of enough sites that have limits way lower 10/12 chars and that where the ones I'm pointing at :).
Image Proud member of the phpBB support team
Image STG Support team member | Image STG Moderator team member
Image
User avatar
Erik Frèrejean    
phpBB Team Member
phpBB Team Member
 
Posts: 1021
Joined: 03 Dec 2007, 00:49
Location: USERS_TABLE
Favorite Team: phpBB teams
Gender: Male
phpBB Knowledge: 9

Next

Return to Security Class

Who is online

Users browsing this forum: ccBot [Bot] and 1 guest