Topic 3 - System Hacking - Password Hacking
Topic 3 - System Hacking - Password Hacking
Cracking
By Paul Mutinda
1. Dictionary Attacks
◦ An attack of this type takes the form of a password-cracking application
that has a dictionary file loaded into it.
◦ The dictionary file is a text file that contains a list of known words up to
and including the entire dictionary.
◦ The application uses this list to test different words in an attempt to
recover the password.
◦ Systems that use pass phrases typically are not vulnerable to this type of
attack.
2. Brute-force Attacks
◦ In this type of attack, every possible combination of
characters is attempted until the correct one is uncovered.
◦ According to RSA Labs, “Exhaustive keysearch, or brute-
force search, is the basic technique for trying every possible
key in turn until the correct key is identified.”
A hacker can also create a script file that tries each password in
a list.
This is still considered manual cracking, but it’s time
consuming and not usually effective.
System Hacking. By P. Mutinda 27
Cracking a Password – Automated tools
Hashkiller - https://hashkiller.co.uk
Md5hashgenerator - http://www.md5hashgenerator.com/
Ophcrack - from http://ophcrack.sourceforge.net/.
Rainbow Crack - used to recover a password
NTInfoScan - is a security scanner for NT 4.0
L0phtCrack - is a password auditing and recovery package
distributed by @stake software,
Default Passwords
One of the biggest potential vulnerabilities is also one of the easiest to
resolve: default passwords.
Default passwords are set by the manufacturer when the device or system is
built.
They are documented and provided to the final consumer of the product and
are intended to be changed.
Hackers can look up your default password at any of the following sites:
http://cirt.net
http://default-password.info
www.defaultpassword.us
www.passwordsdatabase.com
https://w3dt.net
www.virus.org
http://open-sez.me
http://securityoverride.org
www.routerpasswords.com
www.fortypoundhead.com