PDA

View Full Version : Question for Wacki or someone else who is smart


NLSoldier
05-11-2005, 11:37 PM
If a knowledgeable computer programmer/hacker had access to my computer, and I have the password for say, party poker, saved on my comp, so I can automatically login, would it be possible for this person to figure out what my password is, based on the fact that I have it saved for auto login?

edit-basically what I'm asking is if saved passwords are somehow retrievalbe.

KingMarc
05-11-2005, 11:53 PM
An experienced hacker with access to your computer can do absolutely anything.

Matt Flynn
05-11-2005, 11:56 PM
little experience needed.

NLSoldier
05-12-2005, 12:00 AM
OK, thanks guys.

jason_t
05-12-2005, 12:01 AM
[ QUOTE ]
If a knowledgeable computer programmer/hacker had access to my computer, and I have the password for say, party poker, saved on my comp, so I can automatically login, would it be possible for this person to figure out what my password is, based on the fact that I have it saved for auto login?

edit-basically what I'm asking is if saved passwords are somehow retrievalbe.

[/ QUOTE ]

They are stored in an encrypted format. He would have to know how to crack the encryption to get your password.

NLSoldier
05-12-2005, 12:05 AM
[ QUOTE ]
[ QUOTE ]
If a knowledgeable computer programmer/hacker had access to my computer, and I have the password for say, party poker, saved on my comp, so I can automatically login, would it be possible for this person to figure out what my password is, based on the fact that I have it saved for auto login?

edit-basically what I'm asking is if saved passwords are somehow retrievalbe.

[/ QUOTE ]

They are stored in an encrypted format. He would have to know how to crack the encryption to get your password.

[/ QUOTE ]

Yeah, thats waht I was wondering about....

TStoneMBD
05-12-2005, 12:06 AM
your password is mcnutterson32.

i havent had the heart to take all your money yet though.

NLSoldier
05-12-2005, 12:07 AM
[ QUOTE ]
your password is mcnutterson32.

i havent had the heart to take all your money yet though.

[/ QUOTE ]

Holy [censored]! I'll change it ASAP.

jason_t
05-12-2005, 12:07 AM
[ QUOTE ]
[ QUOTE ]
[ QUOTE ]
If a knowledgeable computer programmer/hacker had access to my computer, and I have the password for say, party poker, saved on my comp, so I can automatically login, would it be possible for this person to figure out what my password is, based on the fact that I have it saved for auto login?

edit-basically what I'm asking is if saved passwords are somehow retrievalbe.

[/ QUOTE ]

They are stored in an encrypted format. He would have to know how to crack the encryption to get your password.

[/ QUOTE ]

Yeah, thats waht I was wondering about....

[/ QUOTE ]

The encryption is probably not that complex but is probably difficult enough that the hacker couldn't break it himself without a tool already having been made. Also, your username is stored encrypted too.

TStoneMBD
05-12-2005, 12:09 AM
do not bother.

i have static connection to your password encryption.

make your time. hahahah.

ethan
05-12-2005, 12:13 AM
[ QUOTE ]
They are stored in an encrypted format. He would have to know how to crack the encryption to get your password.

[/ QUOTE ]

That, or use this program (http://www.liewcf.com/blog/archives/2005/03/freeware-to-reveal-hidden-password/). Or this one (http://www.snapfiles.com/get/scpass.html). Or any of these (http://www.google.com/search?q=windows%20masked%20password%20reveal&hl=e n&lr=&c2coff=1&safe=off&sa=N&tab=iw).

jason_t
05-12-2005, 12:16 AM
[ QUOTE ]
[ QUOTE ]
They are stored in an encrypted format. He would have to know how to crack the encryption to get your password.

[/ QUOTE ]

That, or use this program (http://www.liewcf.com/blog/archives/2005/03/freeware-to-reveal-hidden-password/). Or this one (http://www.snapfiles.com/get/scpass.html). Or any of these (http://www.google.com/search?q=windows%20masked%20password%20reveal&hl=e n&lr=&c2coff=1&safe=off&sa=N&tab=iw).

[/ QUOTE ]

Wow. This isn't even based on decryption. This just accesses masked text boxes and grabs the data. Seems like a serious design flaw in Windows to allow other programs access to that data.

TimM
05-12-2005, 12:20 AM
He wouldn't need to be a hacker to do it.

There is a program called AsterWin that reveals stored passwords.

I haven't tried it on poker clients, but it has worked on every other program I've tried.

TStoneMBD
05-12-2005, 12:22 AM
wow ive never seen anything like this before. this is the best thing since sliced bread although i would prefer if it didnt exhist.

ethan
05-12-2005, 12:22 AM
[ QUOTE ]
[ QUOTE ]

That, or use this program (http://www.liewcf.com/blog/archives/2005/03/freeware-to-reveal-hidden-password/). Or this one (http://www.snapfiles.com/get/scpass.html). Or any of these (http://www.google.com/search?q=windows%20masked%20password%20reveal&hl=e n&lr=&c2coff=1&safe=off&sa=N&tab=iw).

[/ QUOTE ]

Wow. This isn't even based on decryption. This just accesses masked text boxes and grabs the data. Seems like a serious design flaw in Windows to allow other programs access to that data.

[/ QUOTE ]

Yea. Programs like these have worked since Win95. (And presumably on earlier versions, but that was the first I'd used them.) So, if someone has access to your computer - physical or remote - they'll be able to get stored passwords.

jason_t
05-12-2005, 12:32 AM
[ QUOTE ]
He wouldn't need to be a hacker to do it.

There is a program called AsterWin that reveals stored passwords.

I haven't tried it on poker clients, but it has worked on every other program I've tried.

[/ QUOTE ]

I tested it on Party and the other skins and it works.

jason_t
05-12-2005, 12:33 AM
[ QUOTE ]
[ QUOTE ]
[ QUOTE ]

That, or use this program (http://www.liewcf.com/blog/archives/2005/03/freeware-to-reveal-hidden-password/). Or this one (http://www.snapfiles.com/get/scpass.html). Or any of these (http://www.google.com/search?q=windows%20masked%20password%20reveal&hl=e n&lr=&c2coff=1&safe=off&sa=N&tab=iw).

[/ QUOTE ]

Wow. This isn't even based on decryption. This just accesses masked text boxes and grabs the data. Seems like a serious design flaw in Windows to allow other programs access to that data.

[/ QUOTE ]

Yea. Programs like these have worked since Win95. (And presumably on earlier versions, but that was the first I'd used them.) So, if someone has access to your computer - physical or remote - they'll be able to get stored passwords.

[/ QUOTE ]

I'm flabbergasted that CERT et al. haven't lobbied Microsoft to change this.

TStoneMBD
05-12-2005, 12:36 AM
im no expert here, but do you really think its even possible for them to change it? my guess is if they could they would. other OSs probably have the same problem. if the computer can recognize the password so that its saved for future use, then there will be programs that can naturally tap into this usage with correct commands.

jason_t
05-12-2005, 12:51 AM
[ QUOTE ]
im no expert here, but do you really think its even possible for them to change it? my guess is if they could they would. other OSs probably have the same problem. if the computer can recognize the password so that its saved for future use, then there will be programs that can naturally tap into this usage with correct commands.

[/ QUOTE ]

What's going on here is that Windows is allowing one program (the password grabber) access to another program's data. This is necessary for Windows to work as seamlessly as it does (drag 'n' drop, etc.). However, Windows could have been programmed so that data in masked text boxes is not available to other programs. I see no reason to allow this to be the case.

wacki
05-12-2005, 12:53 AM
[ QUOTE ]
im no expert here, but do you really think its even possible for them to change it? my guess is if they could they would. other OSs probably have the same problem. if the computer can recognize the password so that its saved for future use, then there will be programs that can naturally tap into this usage with correct commands.

[/ QUOTE ]

Bingo. If you can solve this problem, you can make a lot of money.

wacki
05-12-2005, 12:58 AM
[ QUOTE ]
However, Windows could have been programmed so that data in masked text boxes is not available to other programs. I see no reason to allow this to be the case.

[/ QUOTE ]

This is (basically) called user permissions. Unix/Linux has it and Windows XP doesn't. Longhorn is supposed to have it. On the other hand, if a hacker is good enough to get superuser or root access, then permissions don't matter.

bball233
05-21-2005, 08:47 PM
I have a related question for anyone who might know. Is there a program to retrieve stored AIM passwords? Those other programs that unmask the ***** won't work because AIM just has "Saved - click here to change" in the PW area. Thanks for any help.

Alobar
05-21-2005, 09:05 PM
The subject line of this thread made me laugh

(sorry Wacki /images/graemlins/smile.gif)

wacki
05-21-2005, 09:09 PM
No problem. It made me laugh too.