Posted by stjames on August 16, 2003, at 13:04:56
If you allow cookies to keep your password for this site, your password is stored with encrytpion that is simple to break with dictionary or brute force methods with the utility "John". Esp. quick with decades old MD5, used here. Another cookie seems to be gathering how log/where you go on this site. Despite the fact the web server logs already contain this info. The server logs already know
OS, browser type, referer, and time spent on page
can be computed.Download John and see how quickly you can crack your password:
http://www.openwall.com/john/
poster:stjames
thread:251317
URL: http://www.dr-bob.org/babble/admin/20030808/msgs/251317.html