Flipkart

Flipkart

Saturday, March 17, 2012

Password Cracking – Part 2



This is part two of the Password Cracking course within the  (previously known as the Hacker Institute).  


What is Password Cracking?


Password cracking is the act of recovering passwords through unconventional and usually unethical methods from data that has been stored or sent through a computer system.

Password cracking is a very popular computer attack because once a high level user password is cracked, you’ve got the power! There’s no longer a need to search for vulnerabilities and all that other mumbo jump needed to take over a system that we won’t be discussing in this course.

Also, everyone is susceptible to a password cracking attack. Unless you live in a remote, technology absent area, you have a password for something, and there’s usually something to gain from obtaining your password.

To show you how real and popular this form of attack is today, here are a few recent happenings.

  • Password cracking was used to take over a few high-profile twitter accounts, including President Barack Obama, Britney Spears, Kevin Rose, and Rick Sanchez.
  • Wal-Mart was a victim of a security breach where sensitive information was taken. Password cracking was one of the many methods used to gain entry.
  • 10,000 cracked Hotmail passwords were publicly posted, and every day crackers continue to post new lists on forums all over the internet.
  • phpBB.com was hacked and their 200,000+ username/password database was dumped and made publicly available to anyone willing to download it. Of those passwords, over 80,000 were reported to have had been cracked.

What is Password Cracking used for?


Password cracking can be used for both good and evil. If I forgot my password for a certain system or program, I might try cracking it before I completely give up on it. Now if it’s for any other reason, then it probably has an evil basis and is most likely illegal as well.

Notice how for my legitimate reasons I didn’t mention cracking services. Services are usually things like your ISP (Internet Service Provider), email, social networking and other related passwords. The reason why I didn’t mention these is because even if I legitimately forgot my password for a site like Facebook or Yahoo, it is still against their TOS to attempt to crack those passwords. Why? Because you will be attempting 100’s of password/second over the internet which could put a strain on their system and cause a DOS (Denial of Service) attack. Also, if not done properly, most systems would detect it as an attack and lock you out, sometimes even blocking your IP address completely so that you have absolutely no access to the website from your current ISP given IP address. Even though it is possible to change your IP address, you don’t want to keep doing that. No matter what your reasons are for attempting to crack a password from a service site, it will always be seen as a malicious attack because the websites provide methods for the owner to retrieve their forgotten password. With that said, cracking service site passwords is still very possible and in some cases very easy. It will be discussed later on in the course.

Password Cracking Methods



There are many different types of password cracking methods, and I will introduce you to each one of them within this course. Below is a list of the methods you will soon become a pro in:
 
  • Dictionary Attacks
  • Brute Force Attacks
  • Hybrid Attacks
  • Rainbow Tables

Monday, March 12, 2012

Cyber snoopers target NATO commander in Facebook attack


China blamed again
NATO’s most senior military official has come under a concerted cyber attack from hackers believed to be operating from the People’s Republic of China.
The Observer reported on Sunday that cyber fiends had targeted Supreme Allied Commander Europe (SACEUR) Admiral James Stavridis by opening fake Facebook accounts in his name in an attempt to trick colleagues, friends and family into giving away his personal secrets on the social network.
Social engineering via platforms such as Facebook can be one of the early stages of an advanced persistent threat (APT), the latest buzz word on the information security scene and a technique commonly linked to cyber spies operating from China.
As such, the attackers may have been looking for information they could use to guess Stavridis’ email or other log-in credentials which they could subsequently use to infiltrate NATO systems and steal sensitive military information.
NATO confirmed to the paper that Stavridis had been targeted several times in the same way over the past two years, with Facebook co-operating in taking down the offending fake SACEUR pages.
Although NATO itself said it wasn’t clear who was responsible for the cyber snooping attempt, the Observer spoke to “security sources” who had no hesitation in blaming China.
"The most senior people in Nato were warned about this kind of activity. The belief is that China is behind this," one of them is quoted as saying. One possible reason why the hackers decided to use Facebook as its initial attack vector is that Stavridis is an avid social media user and, unusually considering his senior position, is pretty vocal on Facebook.
In October, for example, he announced the end of NATO operations in Libya via his Facebook page.
While the attack has some of the hallmarks of a state-sponsored espionage attempt, it does appear somewhat less sophisticated than some of the APT-style attacks which have come to light in recent years.
These include Operation Aurora, which targeted Google and scores of other western firms, as well as Operation Night Dragon, the series of attacks on global energy firms in 2011.
Despite its protestations of innocence, the People’s Republic has time and again been singled out by officials in the UK and US as one of the main actors in cyber space when it comes to state-sponsored snooping.
Just last week US defence contractor Northrop Grumman released a 136-page report which pointed to China arming its military with information warfare capabilities which could prove a “genuine risk” to US military operations.

Amazon

Flipkart