Introduction
The following piece of code will create alpha-numeric password. The code will generate a random MD5 hash and truncate the output.
Code: public string PasswordCreation(int Length) { Random random = new Random(); string password = HashData(random.Next().ToString()).Substring(0, 10); string newPass = ""; // Uppercase at random random = new Random(); for (int i = 0; i < password.Length; i++) { if (random.Next(0, 2) == 1) newPass += password.Substring(i, 1).ToUpper(); else newPass += password.Substring(i, 1); } return newPass; } private string HashData(string Data) { MD5 md5 = new MD5CryptoServiceProvider(); byte[] hash = md5.ComputeHash(Encoding.ASCII.GetBytes(Data)); StringBuilder stringBuilder = new StringBuilder(); foreach (byte b in hash) { stringBuilder.AppendFormat("{0:x2}", b); } return stringBuilder.ToString(); }
using System;
using System.Text;
using System.Security.Cryptography;

Paul RobertsPosted Aug 25, 2009, 4:04 PM
The root of yours security is in the Random() class. This does not generate a cryptographically secure random number, but instead generates a psuedo random using the current clock as the seed. All an attacker needs to do is guess the time when the password was generated. Your password space is also restricted as you use only 0-9A-Fa-f as password characters, limiting yourself critically. A better solution would be to use a cryptographic random number generator... using System; using System.Security.Cryptography; const int MinPasswordLength = 6; const int MaxPasswordLength = 32; string GeneratePassword(int length) { if (length < MinPasswordLength || length > MaxPasswordLength) { throw new ArgumentOutOfRangeException("length"); } var raw = new byte[length]; var random = RandomNumberGenerator.Create(); random.GetNonZeroBytes(raw); var password = Convert.ToBase64String( raw, 0, raw.Length, Base64FormattingOptions.None); return password.Substring(0, length); }