Don't use 1234 as your password
nortonwang.com
nortonwang.com
I was around 10 at the time, 1995 plus or minus a year or two.
After booting for the first time, I dialed up AOL and logged on to a Linux-topic IRC channel. I talked to the strangers there about how excited I was to try Linux for the first time.
I quit my IRC client and typed "ls". Command not found. I tried "uptime". Command not find. "cd". Command not found.
While I was on IRC, someone had telnet'd in, guessed my stupidly simple password, and rm -rf'd the whole hard disk. I cried over breaking the computer and had to be consoled by my parents. I never used a common password again.
I now miss the days when hackers and viruses alike just wanted to delete your files or print messages on your screen. Secretly taking over your still-functioning system is much nastier.
[root@localhost ~]# swapon /dev/sdb
swapon: /dev/sdb: read swap header failed: Invalid argument
*edited the formating
http://krebsonsecurity.com/2013/11/cryptolocker-crew-ratchet...
Wanton destruction like the old days, now fueled by profit motive.
I feel like a professional auto mechanic is telling me, all serious-like, that he just learned the hard way why you shouldn't try to drive while running alongside your car, reaching through the window to work the steering wheel, with a brick on the accelerator.
Or.
The more skilled one is, the more confident one is that he can do dumb things and get away with it.
I telnetted to port 25 and tried RCPT TO hypothesized names, like so
$ telnet host 25
MAIL FROM: a@a.com
250 Sender OK
RCPT TO: afranks
550 Recipient not found
RCPT TO: arty.franks
250 Recipient OK
...With this list of usernames I logged into the FTP to try to guess trivial passwords:
$ telnet host 21
USER arty.franks
User OK
PASS 1234
Login failed
PASS password
...Eventually I got a valid username/password combo.
Now I can just telnet <host> and log in. I got a line like this:
Last login April 12, 1992.
$
It had this ancient version of IRIX on it, a hard drive under 100 MB, no X, a version of egcs, some ancient version of perl, no bash, and I think 12MB of RAM?It was fun, but I didn't know what I wanted to do with it. We executed this attack from the school library. Putz'd around a bit, in amazement of how old it was, and that it was still online, and then logged out - never to return.
https://www.youtube.com/watch?v=9EEY87HAHzk - a video of the machine
ChallengeResponseAuthentication no
PasswordAuthentication no
UsePAM no
To your sshd config and then you don't need to worry as much about if one of your accounts has a password of 1234.Also, don't use passwordless keys.
Then there's moving sshd off of port 22 to provide some obscurity.
Yada yada yada... How many times will we have to go over this subject?
I wasn't literally referring to data bit, though. But he has a point.
log(10000) / log(2) == 13.28771
With 5 characters, each 0-9, there are 100,000 possible combinations, and that requires 17 bits: log(100000) / log(2) == 16.60964
Therefore, 12345 offers 3 extra bits of security compared to 1234. sudo apt-get install fail2ban
I remember when I got my very first VPS, and within a couple of days I was getting a really long bruteforce where the attacker tried every common name "aaron, adam, alex, etc" and around 120 common passwords for each of them (fortunately my text-based password on that VPS was 41 characters). I think they tried a few thousand usernames total. That's when I realized the internet is a scary place, and now I only use RSA keys.EDIT: It seems that leaving your VPS unattended for a month is a bad idea. I can't login, because the server terminates the connection immediately and the passwords for the host's backend is changed. Great!
Or if you're going for something really obscure, why not Junkcoin?
I guess PrimeCoin is in 6th in capitalization... maybe it's in that sweet spot of not overly competitive but still capable of retaining some value: http://coinmarketcap.com/