Elakiri data leak

Emios

Well-known member
  • Dec 10, 2009
    73,796
    66,326
    113
    Monawada mae website hariyatada hadapanko.ara anduwen genapu software eka data ussanawa:lol:

    IMG-20210801-WA0000.jpg
     
    • Haha
    Reactions: Mandalorian

    tharakaf

    Well-known member
  • Oct 19, 2020
    34,955
    71,190
    113
    Elakiri eke awlk neme. Ohoma pennanne passswords reuse karoth/ too weak passwords/ known data leaks wala thiyana nisa

    Example: https://haveibeenpwned.com/Passwords
    Guys Pro tip

    Sites like this trick you to put your password so that they can create a database of passwords which will be used for password cracking tools. There are enough resources out there where they will tell you how to create a strong password.

    Use commonsense
     

    Emios

    Well-known member
  • Dec 10, 2009
    73,796
    66,326
    113
    Elakiri eken password leak wenna widiyak naha salt wela password save wenne.
    PC/Phone eke use karapu browser addons, password managers, software, spyware/keyloggers gana hoyala balanna.
    lastpass eka thama tiyenne.wena addons ne bn.tiyena ewa ithin verified ewa
     

    MarshMello

    Well-known member
  • Jan 24, 2018
    4,569
    2,968
    113
    Sri Lanka
    Guys Pro tip

    Sites like this trick you to put your password so that they can create a database of passwords which will be used for password cracking tools. There are enough resources out there where they will tell you how to create a strong password.

    Use commonsense
    Dude I wouldn't share it if it's not trustworthy :D

    Launched: 4 December 2013; 7 years ago
    Created by: Troy Hunt



    Are user passwords stored in this site?​

    When email addresses from a data breach are loaded into the site, no corresponding passwords are loaded with them. Separately to the pwned address search feature, the Pwned Passwords service allows you to check if an individual password has previously been seen in a data breach. No password is stored next to any personally identifiable data (such as an email address) and every password is SHA-1 hashed (read why SHA-1 was chosen in the Pwned Passwords launch blog post.)
     
    • Like
    Reactions: Aki992

    asiridol

    Active member
  • Dec 29, 2006
    756
    234
    43
    Still on earth
    Guys Pro tip

    Sites like this trick you to put your password so that they can create a database of passwords which will be used for password cracking tools. There are enough resources out there where they will tell you how to create a strong password.

    Use commonsense
    This website is known to be legit, run by a famous aussie security researcher Troy Hunt https://www.troyhunt.com/
     
    • Like
    Reactions: Aki992

    windows_ubuntu

    Well-known member
  • Jun 2, 2018
    16,519
    24,502
    113
    Fantasy
    ehema nan enne many people use this password,which make it easy to guess kiyalane bn.meka leak wela ivarai ekai mehema enne. :p
    පාස්වඩ් එක මොකක්ද කියලා පී.ම් කරන්ඩ මට මගෙත් ඒකමද කියල බලන්ඩ
     

    tharakaf

    Well-known member
  • Oct 19, 2020
    34,955
    71,190
    113
    This website is known to be legit, run by a famous aussie security researcher Troy Hunt https://www.troyhunt.com/
    You see anything stopping him from saving and selling those passwords to another party?

    https://www.itpro.co.uk/security/34616/the-top-password-cracking-techniques-used-by-hackers

    Dictionary attack is what you should read about.

    Dude I wouldn't share it if it's not trustworthy :D

    Launched: 4 December 2013; 7 years ago
    Created by: Troy Hunt

    Are user passwords stored in this site?​

    When email addresses from a data breach are loaded into the site, no corresponding passwords are loaded with them. Separately to the pwned address search feature, the Pwned Passwords service allows you to check if an individual password has previously been seen in a data breach. No password is stored next to any personally identifiable data (such as an email address) and every password is SHA-1 hashed (read why SHA-1 was chosen in the Pwned Passwords launch blog post.)
    No worries machan. If you guys think that checking your password online is secure just because the guy creating this says so then, go knock yourself out.

    A more trusted way would have been to ask the users to put the oneway hash value (md5 - less secure or sha-1 or something). This way if your hash is already there in his database you know it is hacked and if it isn't there the site owner or hacker cannot back calculate your password using the hash since hashes were generated using a one way function.

    And Kids that is how you make sure you can be trusted ;-).
    ------ Post added on Aug 1, 2021 at 7:57 PM