lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 10 Oct 2011 19:20:38 +0000
From: Michael Schmidt <mschmidt@...gstore.com>
To: 'Rack911 Security Lists' <lists@...k911.com>,
	"full-disclosure@...ts.grok.org.uk" <full-disclosure@...ts.grok.org.uk>
Subject: Re: 0day Full disclosure: American Express

A lot of the banking industry uses lowercase only. Easier to type form a telephone handset. Legacy system suckage.

From: full-disclosure-bounces@...ts.grok.org.uk [mailto:full-disclosure-bounces@...ts.grok.org.uk] On Behalf Of Rack911 Security Lists
Sent: Monday, October 10, 2011 10:58 AM
To: full-disclosure@...ts.grok.org.uk
Subject: Re: [Full-disclosure] 0day Full disclosure: American Express

American express also utilizing case-insensitive password storing.

On 10/5/2011 11:55 PM, John Doe wrote:
http://qnrq.se/full-disclosure-american-express/




_______________________________________________

Full-Disclosure - We believe in it.

Charter: http://lists.grok.org.uk/full-disclosure-charter.html

Hosted and sponsored by Secunia - http://secunia.com/


Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ