Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Not so much a bug as a warning of new brute force attack

Re: Not so much a bug as a warning of new brute force attack

From: Aaron Merifield <amerifie_at_chat.carleton.ca>
Date: Mon, 3 Jun 1996 12:37:59 EDT

Brett L. Hawn writes:
>
> Given a file full of usernames and the standard 'dict file' one can
>
> Solution:
>
> Implement random delay times, logging, and disconnection within the pop3
> daemom

Why not just change the system so that it wont accept a dictionary name as
a valid password. Six to eight characters and at least 1 or 2 numbers
would make it a little more difficult too.
The main way to crack password files seems to involve using dictionary
files (that you can easily get from the net) and using brute force to
compare the encrypted dictionary words to the encrypted passwords.
Therefore just dont allow dictionary words as passwords. Although the
number you can still make your own dictionary files of random characters,
the percentage of people that would even bother drops big time, IMO.

---=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=---
Aaron Merifield
Carleton University
Graduated spring-95, B.Sc. Physics.
Department of Computer Mathematics, 3rd yr.
      *=--=-==-=--=-==-=--=-==-=--=-==-=--=-==-=--=-==-=--=-=*
E-MAIL: Amerifie_at_chat.carleton.ca
WEB-PAGE: http://chat.carleton.ca/~amerifie
---=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=---
Received on Jun 03 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos