<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-7021629415348487315</id><updated>2009-10-13T10:07:09.351+02:00</updated><title type='text'>Ibrium's Blog</title><subtitle type='html'>Hacking in Israel... and other ramblings.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-2032483604786283670</id><published>2009-08-16T12:57:00.004+03:00</published><updated>2009-08-27T22:10:04.581+03:00</updated><title type='text'>War dialing time!</title><content type='html'>Here is a small time-occupier for you readers. Take a look at the 1-800-6x0-x0x free toll range. Among other things, a juicy unpassworded Cisco 3640 router is hiding in there. Somewhere.&lt;br /&gt;And if you do do something fun with the router or the "other things" drop a note here. It will be interesting to hear the story.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-2032483604786283670?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/2032483604786283670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=2032483604786283670' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/2032483604786283670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/2032483604786283670'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2009/08/war-dialing-time.html' title='War dialing time!'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-3663566917680665005</id><published>2009-05-02T21:04:00.011+03:00</published><updated>2009-08-27T22:28:28.104+03:00</updated><title type='text'>Y****n Information Station</title><content type='html'>Some software is secure, some is free, some excels in usability, other provides an unique functionality. And then there is the y****n (Oh, in case you didn't know, y****n is an information station software used by numerous higher education institutions). Whoever was responsible for usability tests on this thing should be kicked in the head $#@%#&amp;amp;! &lt;br /&gt;No seriously, this thing should be a practical example on how not to do software development. I dare the developer to try to use y****n forum system! &lt;br /&gt;But I digress. Let's discuss the interesting stuff...&lt;br /&gt;&lt;br /&gt;Here is a nice example on why securing communications with SSL over a crappy infrastructure == waste of effort (and money, those certificates are not cheap).&lt;br /&gt;&lt;br /&gt;In y****n user logs-in over HTTPS, gets assigned a cookie and then can navigate through the site using URL parameters, something like this:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 102);"&gt;https://y****n.****.ac.il/y****n/fireflyweb.aspx?appname=BSHITA&amp;amp;prgname=Menu&amp;amp;arguments=-N123456789,-A,-N012983489321984,-N0018,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;What's interesting is that the very first argument -N123456789 which is used to identify the user when querying the database is actually the student &lt;span style="font-style: italic;"&gt;teudat zehut&lt;/span&gt; number. Upon receiving a query the server only verifies that the user 123456789 is currently logged-in, but not that the id matches actual user who made the query. In fact one does not even need to be authenticated on the server to send a query. This essentially means that we could perform queries for any logged-in user within his privilege level.&lt;br /&gt;&lt;br /&gt;For example, we could extract someone else`s exam sheet:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 102);"&gt;https://y****n.****.ac.il/y****n/fireflyweb.aspx?APPNAME=BSHITA&amp;amp;PRGNAME=NoteBooks_Open_Do&amp;amp;ARGUMENTS=-N[ID]-AH,-N[YYYY],-N1,-N[COURSEID][YY][MM],-N00,-N00[COURSEID],-N0001,-N1,-A&amp;amp;LineNo=1&amp;amp;Stat=U&amp;amp;LastPark=&amp;amp;IndexNo=&amp;amp;TaskDefinition=&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;where:&lt;br /&gt;&lt;span style="color: rgb(0, 0, 102);"&gt;[ID]&lt;/span&gt; - student id&lt;br /&gt;&lt;span style="color: rgb(0, 0, 102);"&gt;[YYYY]&lt;/span&gt; - current year&lt;br /&gt;&lt;span style="color: rgb(0, 0, 102);"&gt;[COURSEID]&lt;/span&gt; - course id&lt;br /&gt;&lt;span style="color: rgb(0, 0, 102);"&gt;[YYMM]&lt;/span&gt; - semester's starting date (two digit year/month format)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;UPDATE: since this has a potential for abuse and me dislikes lawsuits the software name has been removed. sorry folks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-3663566917680665005?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/3663566917680665005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=3663566917680665005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/3663566917680665005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/3663566917680665005'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2009/05/hacking-information-station.html' title='Y****n Information Station'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-6936155536164209332</id><published>2009-04-03T01:47:00.007+03:00</published><updated>2009-04-09T23:55:12.273+03:00</updated><title type='text'>ilhack.org - israeli hacking conference. 04.05.09 24.05.09</title><content type='html'>TOP 4 reasons why you should come:&lt;br /&gt;&lt;br /&gt;* It's the first hacking con in four years (not counting OWASPs and such)&lt;br /&gt;* It's probably the last hacking con for the next four years&lt;br /&gt;* Did I mention that it's a hacking con?&lt;br /&gt;oh and there just might be free pizzas&lt;br /&gt;&lt;br /&gt;...and why it's bound to suck:&lt;br /&gt;&lt;br /&gt;* Will last only 8 hours&lt;br /&gt;* Most lectures look boring&lt;br /&gt;* Taking place on &lt;s&gt;MONDAY&lt;/s&gt; SUNDAY. This alone will cost you minus fifty points ilhack organizers!&lt;br /&gt;* There is no mention of booze. Will there be any booze? What kind of con is it without any booze???&lt;br /&gt;That reminds me. No mention of Hacker Jeopardy in the schedule either :(&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-6936155536164209332?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/6936155536164209332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=6936155536164209332' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/6936155536164209332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/6936155536164209332'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2009/04/ilhackorg-israeli-hacking-conference.html' title='ilhack.org - israeli hacking conference. &lt;s&gt;04.05.09&lt;/s&gt; 24.05.09'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-5294453785460083081</id><published>2009-03-10T21:44:00.007+02:00</published><updated>2009-08-27T22:31:04.391+03:00</updated><title type='text'>Scamming on Purim. That's just low!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_7ySd6iEmEgw/SbbDRhplnNI/AAAAAAAAACs/OTRVpQVTZRI/s1600-h/duck-cash-scam.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 258px;" src="http://4.bp.blogspot.com/_7ySd6iEmEgw/SbbDRhplnNI/AAAAAAAAACs/OTRVpQVTZRI/s320/duck-cash-scam.jpg" alt="" id="BLOGGER_PHOTO_ID_5311647516388072658" border="0" /&gt;&lt;/a&gt;While writing the previous post I received an intriguing call.&lt;br /&gt;A female voice, calling me by my full name, asked if I have ever purchased from their store, pronouncing store`s name so fast I could barely understand it.&lt;br /&gt;She then continued telling me that I have been marked in their lists as a VIP customer and eligible for a prize of my choice: silver necklace,  exclusive leather purse, or juice squeezer. Yes that's right - a juice squeezer.&lt;br /&gt;Which could be mine only for a small delivery fee of 39.90₪.&lt;br /&gt;Needless to say our conversation ended there.&lt;br /&gt;&lt;br /&gt;I guess we will never know whether it was "buy a 5₪ necklace for 40₪" scam or just an attempt to steal someone`s credit card info. But doing this on Purim? Where is the ethics!!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-5294453785460083081?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/5294453785460083081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=5294453785460083081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/5294453785460083081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/5294453785460083081'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2009/03/scamming-on-purim-thats-just-low.html' title='Scamming on Purim. That&apos;s just low!'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_7ySd6iEmEgw/SbbDRhplnNI/AAAAAAAAACs/OTRVpQVTZRI/s72-c/duck-cash-scam.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-8550708348349291717</id><published>2009-03-10T19:21:00.005+02:00</published><updated>2009-03-10T19:38:24.818+02:00</updated><title type='text'>Better Place</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_7ySd6iEmEgw/SbajVgNBsCI/AAAAAAAAACk/iCCrVWXE9xk/s1600-h/phpThumb_generated_thumbnailjpg.jpeg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 86px;" src="http://4.bp.blogspot.com/_7ySd6iEmEgw/SbajVgNBsCI/AAAAAAAAACk/iCCrVWXE9xk/s200/phpThumb_generated_thumbnailjpg.jpeg" alt="" id="BLOGGER_PHOTO_ID_5311612400347230242" border="0" /&gt;&lt;/a&gt;There this big thing going in Israel and subsequently in Denmark, Australia, US, and some other places - an attempt to convert current transportation infrastructure based on internal combustion engines to EV with renewable-energy in mind.&lt;br /&gt;Besides of the economical and ecological prospects, what interests me the most is the purely technological side of the process.&lt;br /&gt;There is not much information regarding this currently available, however during one of the Q&amp;amp;A sessions Shy (founder of the Better Place) mentions that each car will be equipped with GPS navigation system allowing driver to locate battery swap stations and/or make recharging spot reservation. Which in turn implies that some sort of two-way radio communication will be present.&lt;br /&gt;The obvious question arises: is how well will it come along with personal privacy and will it open new horizons for abuse.&lt;br /&gt;I think it's safe to assume that at least for the earlier steps of the project (counted in years) a statistics will collected about car travelling habits. It's necessary in order to provide a better recharging station coverage. There simply no way to do it efficiently and reliable basing solely on theoretical calculations.&lt;br /&gt;Less likely, but this could also mean that a remote updates will be performed on the vehicle software in order to support newly arising recharging spots - in other words the vehicle's computer will be probably remotely controllable. The same computer in control of the vehicle mechanics.&lt;br /&gt;It's not the possibility of malicious attacks that concerns me, mobile telephony have proved that the means for data transfer over air could be rather reliable (at least against the average hacker, government agencies are a completely different story), but the fact that a vehicle could be remotely controlled. On one hand all this could greatly reduce car theft. On other the idea of someone able to remotely control your vehicle makes one ponder.&lt;br /&gt;In any case there is not much left to wait, according to the schedule full deployment is circa 2012. Will see then how it goes...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-8550708348349291717?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/8550708348349291717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=8550708348349291717' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/8550708348349291717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/8550708348349291717'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2009/03/better-place.html' title='Better Place'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_7ySd6iEmEgw/SbajVgNBsCI/AAAAAAAAACk/iCCrVWXE9xk/s72-c/phpThumb_generated_thumbnailjpg.jpeg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-3468777276817672188</id><published>2008-11-01T22:05:00.005+02:00</published><updated>2008-11-06T20:30:12.313+02:00</updated><title type='text'>Identity theft (the lazy way)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_7ySd6iEmEgw/SQy8L6TJBDI/AAAAAAAAACc/xGRkn-80T24/s1600-h/tz.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 144px; height: 200px;" src="http://3.bp.blogspot.com/_7ySd6iEmEgw/SQy8L6TJBDI/AAAAAAAAACc/xGRkn-80T24/s200/tz.jpg" alt="" id="BLOGGER_PHOTO_ID_5263788977303389234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Supposedly you need to register for something and a valid Identity Number (מספר זהות) is required. What would you do?&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;q=%22%D7%9E%D7%A1%D7%A4%D7%A8+%D7%AA%D7%A2%D7%95%D7%93%D7%AA+%D7%96%D7%94%D7%95%D7%AA%22"&gt;--&gt;&gt;&lt;&lt;---&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;Or the actual photo of someone's id card:&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;a href="http://images.google.com/images?um=1&amp;amp;hl=en&amp;amp;q=teudat+zehut"&gt;--&gt;&gt;&lt;&lt;---&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;Or full credit card information.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;a href="http://you.wish/"&gt;--&gt;&gt;&lt;&lt;---&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;.. Nah, just kidding. I won't be surprised if some wisely crafted google query could get you even this though.&lt;br /&gt;&lt;br /&gt;For a full personal information however there is nothing better than a good old resumes.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;q=%D7%AA.%D7%96.+%2B+%D7%A7%D7%95%D7%A8%D7%95%D7%AA+%D7%97%D7%99%D7%99%D7%9D"&gt;http://www.google.com/search?hl=en&amp;amp;q=%D7%AA.%D7%96.+%2B+%D7%A7%D7%95%D7%A8%D7%95%D7%AA+%D7%97%D7%99%D7%99%D7%9D&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;Most of the them contain more than enough information for a successful identity theft. This is obviously not some local phenomenon and happens all over the world. What sets Israelis apart however, is an overwhelming tendency to include ID numbers and helluva other personal information.&lt;br /&gt;Fresh from college applicants tend to do this to fill their otherwise empty resumes, some search for jobs in government/military sector. Another source of the problem is recruiting agencies. Upon application you usually will be asked for ID number. Sole purpose of this is to ease applicants tracking in their internal database. The problem is that some agencies decide to spice up the resume and add an id number, among other things.&lt;br /&gt;Anyway, next time some your friends decides to put his or hers CV for public viewing, remind them, for example up to what degree exactly the ID card is checked for validity at the bank on opening a new account.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-3468777276817672188?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/3468777276817672188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=3468777276817672188' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/3468777276817672188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/3468777276817672188'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2008/11/identity-theft-lazy-way.html' title='Identity theft (the lazy way)'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_7ySd6iEmEgw/SQy8L6TJBDI/AAAAAAAAACc/xGRkn-80T24/s72-c/tz.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-9166391025111859224</id><published>2008-10-21T02:23:00.003+02:00</published><updated>2008-10-23T05:46:23.344+02:00</updated><title type='text'>Password Habits</title><content type='html'>Data on users' password habits is hard to come by. Most available researches base their publications on data collected with help of control groups. While these results are fairly good and representative, it makes sense that there will be a number of inaccuracies dragged alongside due to how usually control groups assembled and people who generally participate in them (I was unable to find any research on the subject with good explanation of their selection criterion. Why is that never discussed in depth?). Fortunately for us, these inaccuracies or impurities are rather insignificant, and the collected information still can be successfully extrapolated over the general public. After all, most of us share similar preferences when it comes to remembering things.&lt;br /&gt;Here I would like to present some real life statistics, albeit based only on ~48000 samples, it should give a good view of password selection habits. Only the actual results are shown, it's left up to the reader to draw any conclusions.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Background information:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Source data is a list of 48595 username-password pairs, coming partially from a public discussion board (28595) and partially from a corporate network resource (20000). Users awareness about information security is unknown, but we could assume with a great deal of certainty that the users' expertise represents a complete spectrum from 'casual user' to 'technically inclined'.&lt;/li&gt;&lt;li&gt;We can also assume that the average age for the 20000 list is 20+ (people working in the company are most likely after a college, army, etc.)&lt;/li&gt;&lt;li&gt;Alpha-numeric and general characters allowed. Minimum password length is 6.&lt;/li&gt;&lt;li&gt;Initial password generated by the administrator is 10 characters long, consist of interleaving cases and numbers. E.g. &lt;span style="font-style: italic;"&gt;UaI7VyijSt&lt;/span&gt;&lt;/li&gt;&lt;li&gt;For passwords from public discussion board: users with last access date - registration date difference no greater than a week were removed. This is done in order to clean up the list from one-time users who presumably chose a common, simple to remember, combination. This should remove a great share of non representative passwords and give us better statistics.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Results:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Overall distribution by length (X axis - length, Y axis- distribution percentage):&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_7ySd6iEmEgw/SP0mYu4iLrI/AAAAAAAAAB8/ekgKxBIfBnE/s1600-h/len.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_7ySd6iEmEgw/SP0mYu4iLrI/AAAAAAAAAB8/ekgKxBIfBnE/s400/len.jpg" alt="" id="BLOGGER_PHOTO_ID_5259402146182475442" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Combination match in a publicly available wordlist (~3349730 words): 5.12%&lt;br /&gt;Distribution by length:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_7ySd6iEmEgw/SP0kfXfebbI/AAAAAAAAABk/6yPgKlNTPPM/s1600-h/match_len.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_7ySd6iEmEgw/SP0kfXfebbI/AAAAAAAAABk/6yPgKlNTPPM/s320/match_len.gif" alt="" id="BLOGGER_PHOTO_ID_5259400061139185074" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Consists solely of numbers: 11.91%&lt;br /&gt;Distribution by length:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_7ySd6iEmEgw/SP0k2rsFQRI/AAAAAAAAABs/gs2IQ_yBWho/s1600-h/numeric_len.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_7ySd6iEmEgw/SP0k2rsFQRI/AAAAAAAAABs/gs2IQ_yBWho/s320/numeric_len.gif" alt="" id="BLOGGER_PHOTO_ID_5259400461697761554" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Top 30 most frequently occurring passwords:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_7ySd6iEmEgw/SP0m7E3t9OI/AAAAAAAAACE/5x_uETnN600/s1600-h/top30combo.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_7ySd6iEmEgw/SP0m7E3t9OI/AAAAAAAAACE/5x_uETnN600/s400/top30combo.gif" alt="" id="BLOGGER_PHOTO_ID_5259402736200185058" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Has a numerical suffix (remaining characters are alphabetic): 19.83%&lt;br /&gt;Has a numerical prefix (remaining characters are alphabetic): 2.81%&lt;br /&gt;&lt;br /&gt;Top 30 suffixes/prefixes:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_7ySd6iEmEgw/SP0nGa2JnOI/AAAAAAAAACM/kJiPwFy29vE/s1600-h/suf_pref.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_7ySd6iEmEgw/SP0nGa2JnOI/AAAAAAAAACM/kJiPwFy29vE/s400/suf_pref.gif" alt="" id="BLOGGER_PHOTO_ID_5259402931077749986" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Original passwords assigned by server retained (under assumption that the passwords of the form &lt;span style="font-style: italic;"&gt;UaI7VyijSt&lt;/span&gt; are indeed system assigned and not user chosen): 1.44%&lt;/li&gt;&lt;li&gt;Capitalized (remaining characters are lowercase/numbers/general): 2.41%&lt;br /&gt;&lt;/li&gt;&lt;li&gt;All letters are uppercase (remaining characters are either numbers or general): 0.19%&lt;/li&gt;&lt;li&gt;Consist solely of same repeating character (e.g. &lt;span style="font-style: italic;"&gt;aaaaaaa&lt;/span&gt;, &lt;span style="font-style: italic;"&gt;33333333&lt;/span&gt;): 0.74%&lt;/li&gt;&lt;li&gt;A double pattern (e.g. &lt;span style="font-style: italic;"&gt;funkyfunky&lt;/span&gt;): 2.84%&lt;/li&gt;&lt;li&gt;Password is an username derivative (e.g. username: &lt;span style="font-style: italic;"&gt;vikk&lt;/span&gt; -&gt; password: &lt;span style="font-style: italic;"&gt;Zvikk007&lt;/span&gt;): 1.52%&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-9166391025111859224?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/9166391025111859224/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=9166391025111859224' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/9166391025111859224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/9166391025111859224'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2008/10/password-habits.html' title='Password Habits'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_7ySd6iEmEgw/SP0mYu4iLrI/AAAAAAAAAB8/ekgKxBIfBnE/s72-c/len.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7021629415348487315.post-143548186143271964</id><published>2008-10-18T15:49:00.000+02:00</published><updated>2008-10-20T01:22:37.868+02:00</updated><title type='text'>Authorized Personnel Only</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_7ySd6iEmEgw/SPu9GTTffNI/AAAAAAAAAAc/hdqms8i9z5g/s1600-h/jcbs.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://2.bp.blogspot.com/_7ySd6iEmEgw/SPu9GTTffNI/AAAAAAAAAAc/hdqms8i9z5g/s320/jcbs.jpg" alt="" id="BLOGGER_PHOTO_ID_5259004905844079826" border="0" /&gt;&lt;/a&gt; A couple of weeks ago I decided, that a time has finally come to abuse my student status and purchase one of those, too good to be true, discounted Egged (Israeli Transport Cooperative) bus passes. Instructions at Egged's site on getting the card were surprisingly thorough. And so, I went wandering through Central Bus Station in search of platform number 19 opposite of which, according to the instructions, cards would be selling.&lt;br /&gt;The only thing in front of the platform was a shady door marked with "Authorized Personnel Only". It didn't looked much like a box-office. At this point I am not sure whether it was my overwhelming confidence in Israeli bureaucracy or more likely just a brief moment of stupidity, but since there were no other doors in vicinity of the platform I went in.&lt;br /&gt;&lt;br /&gt;Walking through the halls didn't yield much except of two workers, man sitting in front of bunch of computers at a commanding office of some sort and a teller, of whom neither showed even a slightest interest in an obvious stranger.&lt;br /&gt;Eventually after some ten minutes of poking at offices another teller asked me if she can be of any assistance, and even that was not before a couple seconds of confusing blabbering from my side accompanied by 'Where the hell am I?' facial expression.&lt;br /&gt;&lt;br /&gt;OK, lack of even the simplest physical security measures. Workspace with confidential data left unattended (raw materials for cards plus UNLOCKED terminal interface). Workers not instructed in basic security measures. Not that surprising really. But a box-office location being specified by its back entrance for personnel and not by the actual window for general public (located, apparently, near platform 17)?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7021629415348487315-143548186143271964?l=ibrium.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ibrium.blogspot.com/feeds/143548186143271964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7021629415348487315&amp;postID=143548186143271964' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/143548186143271964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7021629415348487315/posts/default/143548186143271964'/><link rel='alternate' type='text/html' href='http://ibrium.blogspot.com/2008/10/authorized-personnel-only.html' title='Authorized Personnel Only'/><author><name>ibrium</name><uri>http://www.blogger.com/profile/14866240782018419814</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09010115707490445583'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_7ySd6iEmEgw/SPu9GTTffNI/AAAAAAAAAAc/hdqms8i9z5g/s72-c/jcbs.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>