| Author | Message |
|---|---|
miketikel7 |
Date sent: 2016/06/17 16:19:03
So I went to some programming camp for a week teaching me how to hack basically. I learned basic things in Ruby, command prompt, how to make yourself the owner through the "Resources" section and things like that. One way to prove it is for you to type in "cmd" for the windows search thing on the bottom left, next when that black screen opens up, type in "netstat" and that will basically show all the incoming public IP's. It will not show someone's private IP. I could send traffic to this website which will make it super slow xD, but I won't lol, I just wanna see if I can pretend to be Luigi through the login page. The only time that I can't do this is if the website is HTTPS, which the "S" stands for secured :/. So let me know if I can pretend to be Luigi xD |
WOWMANcommunication |
Date sent: 2016/06/18 06:26:57
Mike you scare me. |
luigiofthebakery Moderator |
Date sent: 2016/06/18 06:50:14
Https just means information sent between the client and server is encrypted. Even though this website doesn't use https, that doesn't mean you can log in as anyone. The website will only create a session for me if the correct username and password is submitted through the form, regardless of whether it is sent encrypted (via https) or not. |
Drago2144 |
Date sent: 2016/06/18 07:01:36
If only it was this easy. |
miketikel7 |
Date sent: 2016/06/18 17:29:07
It obviously wont be that easy to get into anyones account since luigi did a good job of hiding most of the info on where you would know how to set yourself as administrator. But, I could type in Luigi's username and use the console to type in all the passwords possible and get into his account, I do have a fast CPU to type in over 50,000 passwords in less than a minute, well, thats what it was for the other stuff that I tested. But idk lol, I might try it, but not on Luigi's account, and I won't abuse it since this is just for my experience. |
luigiofthebakery Moderator |
Date sent: 2016/06/19 02:25:10
Even assuming 100,000 guesses per second, you wouldn't be able to try all possible combinations for passwords of even 6 or 7 characters in length (including uppercase, lowercase, numerals and special characters) since it would take years. Passwords longer than that would even take centuries.Just take a look at this site: https://www.grc.com/haystack.htm I don't even know if the website will accept that amount of connections anyway, it will be throttled and all login attempts for a specific user cancelled for an amount of time after too many unsuccessful login attempts. |
miketikel7 |
Date sent: 2016/06/19 03:22:04
Well, do you have that option for canceling out too many tries? |
tylermerg |
Date sent: 2016/06/19 03:57:37
i checked out the site someone mihgt get my password in 2 years XD unless id reveals it first i dont have perms to change it |
miketikel7 |
Date sent: 2016/06/19 05:56:59
My password would take... approximately 9.77 million trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion centuries to complete apparently since I use other digits xD. Maybe I can't use brute force hacking but I could try to get into the websites data through the console or the links that it sends you too. |
tylermerg |
Date sent: 2016/06/19 17:58:11
ok so lol i put in a super long password witch one of my old friends used and it would take 1.13 milliontrillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion centuries for someone to get it XD |
miketikel7 |
Date sent: 2016/06/19 22:36:53
Lol |
CaptainSpaceSheep |
Date sent: 2016/06/20 09:13:52
lmao |
XxDJAssasinxX |
Date sent: 2016/06/24 03:47:53
With quantum computers, they just check all the available passwords at ONCE. passwerds r ded |
Doctorwhowian |
Date sent: 2016/06/27 20:58:17
luigi is way too smart holy shirt |
