Log in


Password requirements WTF - 410

About Password requirements WTF

Previous Entry Password requirements WTF Nov. 23rd, 2009 @ 12:16 pm
Just trying to change my password for $COLLABORATOR's network. Does anyone have any idea what sort of password would satisfy this? I've tried many, many different things :).

Your new password does not meet the following password policy requirements:
  • The password must contain: 0 lowercase characters, 0 uppercase characters, 2 alphabetic characters, 8 unique characters, at least 2 digits, digits in positions: 0, 0 ending digits, at least 2 special characters, special characters in positions: 0, 0 ending special characters. The check is case sensitive.

Update: I found the following command somehow generated a valid password:
$ dd if=/dev/urandom bs=10 count=1 2>/dev/null | uuencode - | head -2 | tail -1

Leave a comment
[User Picture Icon]
Date:November 23rd, 2009 01:37 pm (UTC)

A good WTF :-)

When I'm resetting the password of a compromised account, I usually use

    head -c 6 /dev/urandom | uuencode -m x
and copy-and-paste the middle line. But our password requirements aren't particularly onerous.

[User Picture Icon]
Date:November 23rd, 2009 04:40 pm (UTC)
I think 0̸1#*@$אב will fit the bill.
  • 0 lowercase characters (Hebrew is unicase)
  • 0 uppercase characters
  • 2 alphabetic characters "אב" (Hebrew is also alphabetic)
  • 8 unique characters
  • At least two digits "0̸1"
  • A digit in position 0 "0̸"
  • 0 ending digits
  • At least 2 special characters "0̸#*@$"
  • A special character in position 0 "0̸"
  • 0 ending special characters
…though this assumes a zero with combining long solidus overlay counts as both a digit and a special character.

Unfortunately, unless someone comes up with at least a second password meeting the criteria, it's not very secure.
[User Picture Icon]
Date:November 23rd, 2009 05:16 pm (UTC)
Unfortunately, another bullet point I didn't quote mandates the password to be at least 10 characters long :).
[User Picture Icon]
Date:November 23rd, 2009 05:46 pm (UTC)
"0̸1#*@$@$אב", then. :-p
[User Picture Icon]
Date:November 23rd, 2009 06:40 pm (UTC)

Password policy

Given your success (and other criteria) I suspect the password policy is mostly poorly described and actually means:

- must be 10 characters long
- must contain 8 different characters (so at most 2 repeats)
- must contain at least 2 of each of: alphabetic characters, digits, special characters
- cannot end with digit or special character (ie, must end with alphabetic character)
- (possibly) cannot start with digit or special character (ie, must start with alphabetic character)
- doesn't have any specific positions requiring digits or special characters ("special characters in positions: 0", "digits in positions: 0"; I'm assuming "0" here means "no specific positions" rather than "first position, C indexed")
- no specific number of upper/lower case characters ("0 lowercase characters, 0 uppercase characters") but probably wants both

If so, something like:


would seem to satisfy the criteria. It's certainly not the worst password ever. But if everyone resorts to a small set of special characters and you know it's likely there's 2 of them, it does reduce the search space a bit.

(The alternative is that aside from strange excursions into non-english languages with unicase characters, as one of the other commenters did, the criteria is not satisfiable.)

[User Picture Icon]
Date:November 24th, 2009 01:50 am (UTC)
Mmm. I'd like to believe "0 lowercase characters" is just a piss-poor way of saying "no minimum number of lowercase characters". Unfortunately, they elsewhere say "at least 2 digits", implying by omission that they mean exactly 0 in the other case.

That filecoreinuse managed to get a line of uuencode output accepted implies that they're just appalling at expressing whatever they actually meant, though.
[User Picture Icon]
Date:November 24th, 2009 03:12 am (UTC)

Password policy

The way that policy is worded makes me think that it's some sort of "tick the requirements for a password" GUI that is providing those criteria, being turned into a very poorly formatted text string. Hence thinking that "0 lowercase characters" means "no minimum requirement has been set" rather than "cannot use" (whereas in the GUI if you set "must have 2 digits" you get "at least 2 digits").

All this really seems to prove is that "tick the boxes" configuration doesn't necessarily lead to sane results, especially when one tries to interpret the error messages literally... (I was amused by the use of unicase Hebrew to "route around" the "no uppercase"/"no lowercase"/"must include alphabetic" restrictions.)

Date:January 26th, 2011 03:17 pm (UTC)

Flirt-Chat kaviar treffen sexuellen Vorlieben kaviar treffen

Willkommen und Hallo in unseren Flirt-Chat.

Dieser Flirt-Chat bietet dir die Möglichkeit kaviar treffen und jedemenge andere Sachen,unter anderem Aufregend chatten
Hier im besten Flirt-Chat findest du kaviar treffen Blind Date
Suchst du eventuel Sexgeschichten , sicher bist du hier genau richtig.Ok,los gehts,stellt sich die Frage,worauf wartest du?
Blind Date erotik kontaktmarkt ,schnell anmelden .
Suchst du jemand aus Bregenz, oder aus Oldenburg, vieleicht aus Aargau , vieleicht aus Zürich, in Marchtrenk? Mit Sicherheit kein Problem.!
Date:February 11th, 2011 07:42 pm (UTC)

louis vuitton bags

It is remarkable, rather useful message
Date:February 15th, 2011 12:54 am (UTC)
Hey, I attempted to email you pertaining to this post but aren?t able to reach you. Please e-mail me when get a moment. Thanks.
Date:February 20th, 2011 06:17 pm (UTC)

Topamax Bipolar

Side Effects Topamax (http://tenamingrockper.over-blog.com/article-side-effects-topamax-67276172.html)
20 Nov 2009 ... The study's researchers also found that 11400 prescriptions for dangerous ... (for epileptic seizures) were taken by women during pregnancy. ...
31 Jan 2011 ... klonopin no prescription overnight delivery klonopin medication pregnancy .... klonopin epilepsy seizures. klonopin pills anxiety ...
Topamax Medication (http://tenamingrockper.over-blog.com/article-topamax-medication-67277533.html)
Top offer where to buy cheap lamictal online without prescription.Copyright © 2010 Lamictal Online ... lamictal breakthrough seizures epilepsy foundation ...
Witnessing your dog have an epileptic seizure can be a frightening experience. ... Chronic seizures can usually be controlled with prescription medications ...
LAMICTAL is a prescription medication for epilepsy and for maintenance ... with other medicines, to treat certain types of seizures (partial seizures, ...
Topamax Forum (http://tenamingrockper.over-blog.com/article-topamax-forum-67275678.html)
Yes I did receive the order and am pleased with the medication. It's a life saver! .... rivotril addiction epileptic seizures gouttes rivotril mg ml ...
7 Nov 2007 ... The Prescription Drug Assistance Programs section of Medicare.gov ... Take Control of your seizures by starting My Epilepsy Diary today. ...
Generic Topamax (http://tenamingrockper.over-blog.com/article-generic-topamax-67276331.html)
Topamax Bipolar (http://tenamingrockper.over-blog.com/article-topamax-bipolar-67279853.html)
Date:February 22nd, 2011 07:23 am (UTC)

Topiramate And Migraine

Topiramate Dosage (http://www.box.net/shared/5x8je8sfa8)
Authoritative in formation about the use of topiramate (Topamax) as a treatment for mania, depression, and the symptoms of post-traumatic stress disorder.
Topiramate And Phentermine (http://www.box.net/shared/x6c4t6t4pq)
8 Dec 2010 ... TOPAMAX is a safe, well tolerated antiseizure medicine, proven to be effective in controlling a broad range of seizures in adults and ...
In patients not diagnosed with epilepsy, seizures have occurred in patients ... about all prescription, over-the-counter, and herbal medications you are ...
Topiramate Kidney Stones (http://www.box.net/shared/6rmgulzq4b)
TOPAMAX ® (topiramate) Tablets and TOPAMAX ® (topiramate capsules) Sprinkle Capsules are indicated as adjunctive therapy for adults and pediatric patients ... - Cached - Similar
Side Effects Medicine (http://www.box.net/shared/29amltxmp1)
Side Effects Topiramate (http://www.box.net/shared/n4fil0sozf)
Why is Topamax prescribed? How should you take Topamax? If you miss a dose Storage instructions How to Buy Topamax from this website ...
Side Effects Of Topiramate (http://www.box.net/shared/n3qsd2cqus)
10 May 2010 ... Consumer information from the manufacturer about the use of Topamax (topiramate). - Cached - Similar
Topiramate Tablets (http://www.box.net/shared/ybktsap8jn)
2 May 2009 ... The issue of prescription drug substitution - using a generic product to replace ... Epilepsy Patients and Medication Interchange Joint Interim ..... of epileptic seizures, from substituting a drug product without prior ... - Cached - Similar
Topamax. Topiramate is a neuronal stabilizing agent (aka anticonvulsant medication) that has proven effective as a Migraine preventive for some patients. ...
Topiramato (http://www.box.net/shared/0fsnttyoo2)
Date:February 22nd, 2011 12:15 pm (UTC)

Phentermine And Topiramate Emotional Side Effects

Order Topiramate (http://www.box.net/shared/cjks2mhvb6)
... individuals with epilepsy and seizure disorders to have access to all the available anti-epileptic medications through prescription drug formularies, ... - Cached - Similar
Topiramate (http://www.box.net/shared/9tqoeuke0y)
Learn about the prescription medication Topamax (Topiramate), drug uses, dosage, side effects, drug interactions, warnings, reviews and patient labeling. - Cached - Similar
Topiramate Addiction (http://www.box.net/shared/2a92jh86oo)
Topiramate And Pregnancy (http://www.box.net/shared/6njdo6ch0u)
In the eyes of a health insurer, it is unpredictable to an epileptic ... have been diagnosed more than 10 years and is controlled by prescribed medication. ... Some patients can become seizure free without medication indication of the ...
10 Mar 2010 ... Buy Topamax From Trusted Pharmacy, Sale Topamax, Order Topamax Online C.o.d, Topamax In Japan, Ordering Topamax Online, Topamax From ...
6 posts - Last post: 17 Aug 2010
Topiramate Uses (http://www.box.net/shared/82ivtk2c4n)
Klonopin online a prescription medication that is commonly used to treat Epilepsy and panic disorders. ... Epilepsy (Seizure disorders) Panic Disorders ...
Find patient medical information for Topamax Oral on WebMD including its uses, side effects and safety, interactions, pictures, warnings and user ratings.
medication carbatrol tegretol xr tegretol cannabis one tegretol website carbatrol tegretol and trileptal partial seizures tegretol induced pancreatitis ...
Prescription Medication FAQ - Get the answers you need to the most commonly ... against the epileptic seizures, even during a period of abstinence. ...
31 Dec 2010 ... People with seizures that begin with a warning may be able to breathe .... when compared to the standard prescription medications which are ... - Cached
PDF/Adobe Acrobat - Quick ViewAnti-epileptic drugs (AEDs) are prescribed to control seizures. They do not cure epilepsy. .... Yes, and not only your AEDs but ALL prescription medication. ...www.epilepsyresearch.org.uk/docs/leaflets/14_FAQs.pdf - Similar
Date:April 9th, 2011 08:15 am (UTC)
Great post! I want to see a follow up to this topic

Date:April 14th, 2011 12:13 pm (UTC)
I hope you will keep updating your content constantly as you have one dedicated reader here.

(Leave a comment)
Top of Page Powered by LiveJournal.com