Search
Recommended Products
Related Links


 

 

Informative Articles

Business Continuity Testing starts with the risks
Business Continuity Testing starts with the risks All business continuity analysis should be risk based, and risk prioritised to deal with the important business risks first. This means that any risks to your business need to be identified,...

Identity Theft: The road back
A couple of weeks ago, a friend of mine mentioned that one of his co-workers recently recovered his stolen identity. I asked how long the process took. "Only two years" he replied. Compared to the six year nightmare suffered by one of my business...

IT Department Skills to Support Microsoft Great Plains and Microsoft CRM
Microsoft Great Plains as ERP and Microsoft CRM as Client Relation Management system is very robust combination and could serve midsize to large corporation as Business System. Being VP IT or IT Director you need to foresee the positions to have...

Need A Copy Of Your Tax Return Information?
Taxpayers have two easy and convenient options for getting copies of their federal tax return information — tax return transcripts and tax account transcripts — by phone or by mail. A tax return transcript shows most line items from the tax...

The Essential Data Recovery Report
Your worst nightmare just became a horrifying reality. You keep hearing that little voice in your head mockingly shout “you should have backed that stuff up” The voice keeps echoing throughout your head as you perform a quick inventory all of the...

 
Google
Background Of Password Cracking

Passwords to access computer systems are usually stored, in some form, in a database in order for the system to perform password verification. To enhance the privacy of passwords, the stored password verification data is generally produced by applying a one-way function to the password, possibly in combination with other available data. For simplicity of this discussion, when the one-way function does not incorporate a secret key, other than the password, we refer to the one way function employed as a hash and its output as a hashed password. Even though functions that create hashed passwords may be cryptographically secure, possession of a hashed password provides a quick way to verify guesses for the password by applying the function to each guess, and comparing the result to the verification data. The most commonly used hash functions can be computed rapidly and the attacker can do this repeatedly with different guesses until a valid match is found, meaning the plaintext password has been recovered.

The term password cracking is typically limited to recovery of one or more plaintext passwords from hashed passwords. Password cracking requires that an attacker can gain access to a hashed password, either by reading the password verification database or intercepting a hashed password sent over an open network, or has some other way to rapidly and without limit test if a guessed password is correct. Without the hashed password, the attacker can still attempt access to the computer system in question with


guessed passwords. However well designed systems limit the number of failed access attempts and can alert administrators to trace the source of the attack if that quota is exceeded. With the hashed password, the attacker can work undetected, and if the attacker has obtained several hashed passwords, the chances for cracking at least one is quite high. There are also many other ways of obtaining passwords illicitly, such as social engineering, wiretapping, keystroke logging, login spoofing, dumpster diving, timing attack, etc.. However, cracking usually designates a guessing attack.

Cracking may be combined with other techniques. For example, use of a hash-based challenge-response authentication method for password verification may provide a hashed password to an eavesdropper, who can then crack the password. A number of stronger cryptographic protocols exist that do not expose hashed-passwords during verification over a network, either by protecting them in transmission using a high-grade key, or by using a zero-knowledge password proof.


About the Author: David and his team developed Article Post Robot, http://www.articlepostrobot.com, the software which can post articles to hundreds of article sites and mail lists automatically.

Source: www.isnare.com