Welcome to TechNet Blogs Sign in | Join | Help

Enterprise IT Identity & Access Management

A Buyer's & Integrator's Guide - WebLog Version 1.0

Syndication

News

Hi, I've moved into an Information Security Research & Strategy role from an IAM Architecture role. So this blog site is retired. I may launch a security blog in the future. Thank you all for visiting!
Ways to Compromise Password

Passwords are vulnerable by virtue of the following attacks:


Password Cracking Tools - A variety of software tools, such as L0Phtcrack and NT Crack, automate the guessing of passwords through brute force and with extensive dictionaries of frequently used passwords.


Network Monitoring - This technique, also known as ”sniffing,” allows monitoring (without detection) the contents for any message that streams by and flagging messages based on keywords, such as “login” or “password.”

Brute Force Dialing (or War Dialing) - Programs like ToneLoc automate the process of locating modem telephone lines; then the hacker attempts sign-on with various password alternatives.

Abuse of Administrative Tools. Many tools that have been designed to control and improve networks can be misused for destructive purposes.

Social Engineering. In contrast to the high-tech tools available to uncover passwords, some intruders use non-technical approaches to steal passwords.

 

Keystroke monitoring - This technique monitor and record user’s keystrokes remotely when user types in password at public kiosks.

Published Saturday, March 25, 2006 1:00 AM by Yale Li

Filed under:

Comments

No Comments

Anonymous comments are disabled
Page view tracker