Bookmark and Share

Background Of Password Cracking

Free PDF eBook!

Enter Your First Name
and Email Address to Download

eMail address:
First Name:

Passwords to access computer systems are usually stored, in some form, in a database in order for the system to perform password verification. To enhance the privacy of passwords, the stored password verification data is generally produced by applying a one-way function to the password, possibly in combination with other available data.

For simplicity of this discussion, when the one-way function does not incorporate a secret key, other than the password, we refer to the one way function employed as a hash and its output as a hashed password. Even though functions that create hashed passwords may be cryptographically secure, possession of a hashed password provides a quick way to verify guesses for the password by applying the function to each guess, and comparing the result to the verification data.

The most commonly used hash functions can be computed rapidly and the attacker can do this repeatedly with different guesses until a valid match is found, meaning the plaintext password has been recovered.

The term password cracking is typically limited to recovery of one or more plaintext passwords from hashed passwords. Password cracking requires that an attacker can gain access to a hashed password, either by reading the password verification database or intercepting a hashed password sent over an open network, or has some other way to rapidly and without limit test if a guessed password is correct. Without the hashed password, the attacker can still attempt access to the computer system in question with guessed passwords.

However well designed systems limit the number of failed access attempts and can alert administrators to trace the source of the attack if that quota is exceeded. With the hashed password, the attacker can work undetected, and if the attacker has obtained several hashed passwords, the chances for cracking at least one is quite high. There are also many other ways of obtaining passwords illicitly, such as social engineering, wiretapping, keystroke logging, login spoofing, dumpster diving, timing attack, etc.. However, cracking usually designates a guessing attack.

Cracking may be combined with other techniques. For example, use of a hash-based challenge-response authentication method for password verification may provide a hashed password to an eavesdropper, who can then crack the password. A number of stronger cryptographic protocols exist that do not expose hashed-passwords during verification over a network, either by protecting them in transmission using a high-grade key, or by using a zero-knowledge password proof.



 

Identity Theft Videos and More Articles

Loading...

15 Easy Solutions To Avoid Identity Theft

... store them in a safe place and have it locked. It is also nice to store your unused checks, social security card and bank statement in a safe place. 4. You should also ensure to make credit card receipt copies when buying something. Moreover, confirm if your credit card was returned to you. 5. It is necessary ...

Benefits Of Proper Computer Recycling And Disposal

... number gets sent to the company and is usually stored in their memory so that the next time you visit their website, shopping and paying is quicker and easier. As many as 9 million Americans have their identity stolen every year, but sadly, most of these victims are cautious consumers who happen to be ...

The Increasing Problem Of Credit Card Identity Theft

... open new credit card accounts in your own name. When using these credit cards and foot the bill in your name, such delinquencies will be reported on your credit report. This will make it harder for you to upgrade or make effective use of your own credit account because of your worsening credit record ...

Simple Tips To Prevent Identity Theft

... shredder is the best way to go. The shredded paper is great for rodent bedding if you have children with small pets or want a pet. In addition to documents, there are many things that should be common knowledge but can be overlooked. Never carry your checkbook, birth certificate, or social security card ...

Erasing Tracks Left On Your Computer

... Play store audio and video playing history. Microsoft Office like Excel and PowerPoint applications store information about the most recently accessed files. Another important thing to remember is that when you delete a file it is not necessarily permanently erased and can be recovered with the right ...

 

Recommended Identity Theft Products









Home |  Free eBook |  Contact Us |  Privacy Policy |  Site Map