Good and Bad Password How-To References
References:
- Bobby, Paul, "Password Cracking Using Focused
Dictionaries", July 16, 2000, was originally found at SANS.org but
a PDF as originally formatted is available at
http://www.giac.org/paper/gsec/42/password-cracking-focused-dictionaries/100346
- Feldmeier, David C., Karn, Philip R. "UNIX
Password Security Ten Years Later", 1990, can be downloaded as a PDF
or PS from
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.49.7151
- John the Ripper: Password Cracker, home
page,
http://www.openwall.com/john/
- Klein, Daniel V., " "Foiling the cracker": A
survey of, and Improvements to, Password Security", Feb 22, 1991,
is available in PDF from
http://www.klein.com/dvk/publications/passwd.pdf
and locally as a
PDF or PS.
The actual dictionaries used by Daniel Klein are no longer available at
ftp://ftp.cerias.purdue.edu/pub/dict/dictionaries/DanKlein/
but are available here.
- L0phtCrack, password auditing for windows
NT, home page, seems to move around. I last found it at
http://insecure.org/sploits/l0phtcrack.lanman.problems.html.
LC5, the latest commercial version (late 2006) can be found at
http://www.securityfocus.com/tools/1005.
- Muffet, Alec, Crack v5.0a, FAQ,
I don't believe anyone is maintaining Crack anymore. This next
appears obsolete.
http://www.crypticide.com/users/alecm/security/c50-faq.html
Alec Muffet's current home page appears to be
http://dropsafe.crypticide.com/aboutalecm
- Thompson, Ken & Morris, Robert, "Password
Security: A Case History", 1978, revised 1979,
http://www.cs.yale.edu/homes/arvind/cs422/doc/unix-sec.pdf
- Johnathan Graham, "Security as a Maintenance
Process," 2005 Power Point presentaion is no longer available at its
original location
http://www.its.queensu.ca/oucc/oucc_%20presentations/Johnathan_Graham.ppt
but is available in the Internet Archive at https://web.archive.org/web/http://www.its.queensu.ca/oucc/oucc_%20presentations/Jonathon_Graham.ppt
- Niels Provos and David Mazieres, A Future-Adaptable
Password Scheme, 1999, paper presented at Usenix conference www.openbsd.org/papers/bcrypt-paper.pdf
- Openwall (Solar Designer & Simon Marechal), "Password
security: past, present, future," 2012, a MagicPoint presentation
http://www.openwall.com/presentations/Passwords12-The-Future-Of-Hashing/
also available from this link in PDF.
Other Sources:
Top of Page -
Site Map
Copyright © 2000 - 2014 by George Shaffer. This material may be
distributed only subject to the terms and conditions set forth in
https://geodsoft.com/terms.htm
(or https://geodsoft.com/cgi-bin/terms.pl).
These terms are subject to change. Distribution is subject to
the current terms, or at the choice of the distributor, those
in an earlier, digitally signed electronic copy of
https://geodsoft.com/terms.htm (or cgi-bin/terms.pl) from the
time of the distribution. Distribution of substantively modified
versions of GeodSoft content is prohibited without the explicit written
permission of George Shaffer. Distribution of the work or derivatives
of the work, in whole or in part, for commercial purposes is prohibited
unless prior written permission is obtained from George Shaffer.
Distribution in accordance with these terms, for unrestricted and
uncompensated public access, non profit, or internal company use is
allowed.
|