Password Hacking !!
Password Cracking
It is one of the most enjoyable hacks.
The password cracking may not have
a burning desire to hack the password of everyone. The actual password of the
user is not stored in the well-designed password-based authentication system.
Due to this, the hacker can easily access to user's account on the system.
Types of
Password Cracking
·
Non
electronic: It doesn’t require
technical knowledge.
§
Social
Engineering
§
Shoulder
Surfing
§
Keyboard
Sniffing
§
Dumpster
Diving
·
Active Online: An active attack is a network exploit in which
a hacker attempts to make changes to data on the target.
§
Dictionary
attack
§
Brute-Force
attack
§
Rule Based
attack
·
Passive
Online: A network attack in
which a system is monitored and sometimes scanned for open ports and
vulnerabilities.
·
Offline
Attacks: In some cases, an
attacker can get a hash of your password that they can take offline and try to
crack it.
Password
spraying attack
An attacker acquires a
list of usernames, then attempts logins across all usernames using the same
password. The attacker repeats the process with new passwords until the attack
breaches.
Password
guessing
This is a process of
attempting to gain the system’s access by trying on all the possible passwords.
If the attacker manages to guess the correct one, he has complete access to the
remote system, can manipulate the data, and may demand a ransom in exchange for
the system data.
How hash
passwords are stored in windows SAM
On domain members and
workstations, local user account password hashes are stored in a local Security
Account Manager (SAM) database located in the registry.
Comments
Post a Comment