Password Attacks 2.4 Flashcards
1
Q
Hashing a Password
A
- Creating a message digest or “finger print”
- Creates a one way trip, a common way to store passwords
2
Q
Spraying Attack
A
- Online brute force attack
- Using a limited number of passwords on all accounts.
3
Q
Brute Force
A
- The attacker attempts all possible password combinations
4
Q
Protection Against a Brute Force Attack
A
- Using a strong hashing algorithm
- Creating a hash this very long.
5
Q
Brute Force Attack - Online
A
- Keep trying the login process
- Very slow
- Most accounts will lockout after a certain amount of failed attempts.
6
Q
Brute Force Attack - Offline
A
- Attacker steals a password file.
- Calculate a password hash, compared it to a stored hash
- Performs hash comparisons.