nist-password-validator

command module
v0.0.0-...-45ab5d3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Mar 21, 2019 License: MIT Imports: 4 Imported by: 0

README

NIST Password Validator

Build Status Go Report Card Coverage Status GoDoc

NIST recently updates their Digital Identity Guidelines in June 2017. The new guidelines specify general rules for handling the security of user supplied passwords.

This program will detect passwords that do not meet the following requirements:

  1. Minimum of 8 characters
  2. Maximum of 64 characters
  3. Only contain ASCII characters
  4. Not be a common password based on a supplied common password file

The program will take a list of newline-delimited passwords from STDIN. It will check each of these passwords against the above criteria and output any passwords that fail to meet the criteria along with the failure reason.

A filename which contains the list of common passwords should be supplied as the first parameter of the program.

Installing and running

First, make sure you have the latest version of Go installed.

To install the binary:

go install github.com/caitlin615/nist-password-validator

To run it:

  • myCommonPasswordList.txt is a newline-delimited file containing a list of common passwords. You will need to supply this yourself, or see here
# Run with a single password
echo "MyPassword" | nist-password-validator myCommonPasswordList.txt

# Run with a file of passwords
cat "myPasswordFile.txt" | nist-password-validator myCommonPasswordList.txt

Building and running locally

# Download the repo
go get -d github.com/caitlin615/nist-password-validator
cd $GOPATH/src/nist-password-validator

# Download the common password list (see Makefile for more details)
make 10-million-password-list-top-1000000.txt

# Build the binary
go build -o nist-password-validator

Now you can run it!

# Run with a single password
echo "MyPassword" | ./nist-password-validator myCommonPasswordList.txt

# Run with a file of passwords
cat "myPasswordFile.txt" | ./nist-password-validator myCommonPasswordList.txt

Expected output

The program will only output a list of passwords that fail the validation tests and their reason for failure.

Here's an example:

abc123 -> Error: Too Short
password -> Error: Common Password
abcd -> Error: Too Short
asdlfdja;lsdijfa;sdfpoaisdufpoaisuf9oarpfauhrfiuehfpiudhfioufgoiudfhgoiudfgpdupodsifpuosiUFPAOSIDUFPAOSDIUFP -> Error: Too Long
*** -> Error: Invalid Characters
*** -> Error: Invalid Characters
*** -> Error: Invalid Characters
*** -> Error: Invalid Characters

Downloading Common Password List

You can download a common password list using the following command:

curl -LO "https://github.com/danielmiessler/SecLists/raw/master/Passwords/Common-Credentials/10-million-password-list-top-1000000.txt"
# OR
make 10-million-password-list-top-1000000.txt
Running Tests
make test
# OR
go test -v ./...

Documentation

Overview

nist-password-validator will detect passwords that do not meet the following requirements:

1. Minimum of 8 characters 1. Maximum of 64 characters 1. Only contain ASCII characters 1. Not be a common password based on a supplied common password file

The program will take a list of newline-delimited passwords from STDIN. It will check each of these passwords against the above criteria and output any passwords that fail to meet the criteria along with the failure reason.

A filename which contains the list of newline-delimited common passwords should be supplied as the first parameter of the program.

# Run with a single password
echo "MyPassword" | nist-password-validator myCommonPasswordList.txt

# Run with a file of passwords
cat "myPasswordFile.txt" | nist-password-validator myCommonPasswordList.txt

Based on https://gist.github.com/buckhx/45a54e75f7a9484ca9d69f699b929eca

Directories

Path Synopsis
Package password provides utilities to validate a password or list of passwords against a set of criteria
Package password provides utilities to validate a password or list of passwords against a set of criteria

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL