<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; aol-password-cracking</title>
	<atom:link href="http://www.darknet.org.uk/tag/aol-password-cracking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>AOL Has An Odd Password System</title>
		<link>http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/</link>
		<comments>http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/#comments</comments>
		<pubDate>Thu, 21 Jun 2007 06:02:44 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[aol]]></category>
		<category><![CDATA[aol-password-cracking]]></category>
		<category><![CDATA[aol-passwords]]></category>
		<category><![CDATA[aol-security]]></category>
		<category><![CDATA[hacking-aol]]></category>
		<category><![CDATA[password-policy]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/</guid>
		<description><![CDATA[An interesting snippet from last month, AOL seems to have a strangely configued password system. Users can enter up to 16 characters as a password, but the system only reads the first 8 and discards the rest. They are basically truncating the password at 8 characters. A reader wrote in Friday with an interesting observation: [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>An interesting snippet from last month, AOL seems to have a strangely configued password system.</p>
<p>Users can enter up to 16 characters as a password, but the system only reads the first 8 and discards the rest. They are basically truncating the password at 8 characters.</p>
<blockquote><p>A reader wrote in Friday with an interesting observation: When he went to access his AOL.com account, he accidentally entered an extra character at the end of his password. But that didn&#8217;t stop him from entering his account. Curious, the reader tried adding multiple alphanumeric sequences after his password, and each time it logged him in successfully.</p>
<p>It turns out that when someone signs up for an AOL.com account, the user appears to be allowed to enter up to a 16-character password. AOL&#8217;s system, however, doesn&#8217;t read past the first eight characters. </p></blockquote>
<p>And if you can&#8217;t work out what&#8217;s wrong with this..well.</p>
<blockquote><p>How is this a bad set-up, security-wise? Well, let&#8217;s take a fictional AOL user named Bob Jones, who signs up with AOL using the user name BobJones. Bob &#8212; thinking himself very clever &#8212; sets his password to be BobJones$4e?0. Now, if Bob&#8217;s co-worker Alice or arch nemesis Charlie tries to guess his password, probably the first password he or she will try is Bob&#8217;s user name, since people are lazy and often use their user name as their password.</p>
<p>And she&#8217;d be right, in this case, because even though Bob thinks he created a pretty solid 13-character password &#8212; complete with numerals, non-standard characters, and letters &#8212; the system won&#8217;t read past the first eight characters of the password he set, which in this case is exactly the same as his user name. Bob may never be aware of this: The AOL system also will just as happily accept BobJones for his password as it will BobJones$4e?0 (or BobJones + anything else, for that matter). </p></blockquote>
<p>Not smart eh? AOL apparently are &#8216;looking into it&#8217; and that&#8217;s all they&#8217;ve said regarding the matter.</p>
<p><a href="http://www.schneier.com/blog/">Bruce Schneier</a>, chief technology officer BT Counterpane, called the set-up &#8220;sloppy and stupid.&#8221;</p>
<p></p>
<p>Source: <a href="http://blog.washingtonpost.com/securityfix/2007/05/aols_password_puzzler.html">Washington Post</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=AOL+Has+An+Odd+Password+System+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D565+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/&amp;t=AOL+Has+An+Odd+Password+System" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/&amp;title=AOL+Has+An+Odd+Password+System" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/&amp;title=AOL+Has+An+Odd+Password+System" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/&amp;title=AOL+Has+An+Odd+Password+System" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/&amp;title=AOL+Has+An+Odd+Password+System" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F06%2Faol-has-an-odd-password-system%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/06/aol-has-an-odd-password-system/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

