Security

How to create a random password in PHP

Fadıl

I am trying to generate a random password in PHP.

If you ever have the need to create a random password or username you can use something like this.

function randomPassword($length) { 
  $possible = '0123456789!@#$%^&*()_+' . 
              'abcdefghijklmnopqrstuvwxyz' . 
              'ABCDEFGHIJKLMNOPQRSTUVWXYZ' . 
  $str = ""; 
  while (strlen($str) < $length) { 
     $str .= substr($possible, (rand() % strlen($possible)), 1); 
  } 
  return($str); 
}

How Face Recognition Works

Fadıl

And possible uses (Biometrics)
How it works:
THe first bit in the process is recoginising a face a in a photo and seperating it from a background. The program recognises the shape of a face, and the increases lighting and then sets to work on it

Face recognition works by looking at the distances apart points on the face are. Key points include:

  • Distance between eyes

  • Width of nose

  • Depth of eye sockets

How to Hide Files in Windows

Fadıl

Note: this will not keep fbi/police/anyone who knows computers really good from finding your files, only computer illiterate people and people who aren’t really looking for incriminating files on your computer.

Hiding The Files/Directories:

1) hide directories
2) encrypted directories
3) CDs and floppies

Hiding The Evidence:

1) browser history
2) cookies
3) temp files
4) windows history (Start->documents)
Ok, let me first start off with why you would want to do this.  You live at home with your parents and your brothers and sisters.  They all use the computer every once and a while, but you use it all day.  You do a few things on it that you would rather keep any of them from knowing about.  ex.  hacking. I’ll try to share some knowledge I’ve gained on keeping things secret from people on windows, I don’t know if this will work with any other versions of windows (most likely they will).  I will keep this very short and to the point, there are tons of little details that I could get into, but it would be a waste of everyone’s time.  Just think to yourself how to keep them more secret and you’ll be more productive than reading 40 pages by me telling you not to write down the location of your files on a post-it by the monitor.
I’ve decided to break this tutorial down into 2 main categories.  Hiding Files And Directories is the first, and Hiding The Evidence is the second.

How to Fake the http Refferer

Fadıl

This is used in some scripts to check for security. You mustn’t use this as a security check, as it is very easily spoofed. See here for how to secure your Perl scripts.
Anyway, just telnet to the server where you want to download the file from, eg.
www.multiproxy.org
on port 80 (as usual) then issue the get command to retrieve the file you want as usual eg:
get /env_check.htm
But then ratehr then pressing enter twice, instead press enter, then type:
Referer: http://madeup.com/fake/referer.html
Then press enter.
This is how easy it is to spoof http_referrer.
PHP scripts can be written to fake the referrer, allowing you to fake the referrer in php. This is done by using the simple PHP fopen statement.

Hacking Unix User Passwords

Hacking Unix User Passwords

Fadıl

On most Unix systems passwords are stored in the

file /etc/passwd

This means using the Unix echo out command, cat, you can see the contents of this file:

cat /etc/passwd

The passwords will be encrypted, but unfortunately quite insecurely. But the encryption has long been crackable. A tool called John has long been availble. It runs in dos, and you can crack the average unix password in a couple of hours. A password shorter then four letters takes no time at all (make sure no passwords are this long).