Pwned Passwords, Version 6
troyhunt.com
troyhunt.com
Most seem to use the web API: for example https://github.com/search?l=PHP&q=haveibeenpwned+API+v2+pwne...
Other projects for pwnedpasswords: https://github.com/search?q=pwnedpasswords&type=Repositories YMMV, “read the source, Luke!” :)
I think it's a good study in game theory at the least.
See https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByR...
We who understand what's going on know it's perfectly fine, but it's hard to get that message across. Just like the first time you try to explain what a hash is to a non-technical person.
> GET https://api.pwnedpasswords.com/range/{first 5 hash chars}
The service is only receiving the first 5 hash chars and thus could not collect your password.
Or you could read the javascript code of the page when you visit it.
> var i = sha1(n).toUpperCase(),
> r = i.substring(0, 5);
> $.get('https://api.pwnedpasswords.com/range/' + r).done(function (n) ...
Or you could download the file and check it locally.
#!/bin/bash
baseurl="https://api.pwnedpasswords.com/range/"
read -s pass
hash=$(echo -n "$pass"|sha1sum)
hashhead=${hash:0:5}
hashtail=${hash:5:35}
curl -s ${baseurl}/${hashhead}|grep ${hashtail^^}
It'll dump the hash and the number of times the given password was found. If the password is not found it won't return anything.[0]: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
If you don't want the password to end up in your shell history, this works on in the shell with common tools:
tr -d '\n' | sha1sum
Then type the password you want to look for, hit enter and control-d. You can test with "common" passwords like https://www.reddit.com/r/XFiles/comments/6ge7h4/mulders_home... if you're doing it right.
then
PT=$(echo -n $PASS | gsha1sum | awk '{print toupper($1)}'); curl -s https://api.pwnedpasswords.com/range/$(awk '{print substr($0,1,5)}' <<< $PT) | grep $(awk '{print substr($0,6)}' <<< $PT)
Hihi, this cracked me up, best joke for today. Keep up the good work Troy
Also, the password doesn't go to the server but its hash goes.
Lastsly, he had to make the free API paid because people were DDOSing it
As for pwned passwords, it doesn't send the password. The way it works is that you submit the first 5 characters of a hash, and get back a list of all hashes.
You then locally compare the complete hash to see if it is there.
Have I Been Pwned is the tool where you search your email, and it displays breaches.
Pwned Passwords is an API (there is a front-end but that's not the usecase) where you send a partial hash of a password to the API, and it returns a list of partial hashes that match, and the implementation from there sees if any of them match the full hash. It's used by quite a few online services to ensure users don't use weak passwords, as if it's shown up in multiple data breaches, they might not let you set it as your password.
https://blog.cloudflare.com/validating-leaked-passwords-with...