Home > Security Tips > > Hacking For Dummies: Chapter 7 -- Passwords
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Hacking For Dummies: Chapter 7 -- Passwords


Written by Kevin Beaver; published by Wiley Publishing
05.14.2004
Rating: -3.80- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This excerpt is from Chapter 7 Passwords in Hacking For Dummies written by Kevin Beaver and published by Wiley Publishing. Download this sample chapter on passwords here for free.

Password hacking is one of the easiest and most common ways hackers obtain unauthorized computer or network access. Although strong passwords that are difficult to crack (or guess) are easy to create and maintain, users often neglect this. Therefore, passwords are one of the weakest links in the information-security chain. Passwords rely on secrecy. After a password is compromised, its original owner isn't the only person who can access the system with it. That's when bad things start happening.

Hackers have many ways to obtain passwords. They can glean passwords simply by asking for them or by looking over the shoulders of users as they type them in. Hackers can also obtain passwords from local computers by using password-cracking software. To obtain passwords from across a network, hackers can use remote-cracking utilities or network analyzers.

This chapter demonstrates just how easily hackers can gather password information from your network. I outline common password vulnerabilities that exist in computer networks and describe countermeasures to help prevent these vulnerabilities from being exploited on your systems.

If you perform the tests and implement the countermeasures outlined in this chapter, you're well on your way to securing your systems' passwords.

Password Vulnerabilities
When you balance the cost of security and the value of the protected information, the combination of user ID and secret password is usually adequate. However, passwords give a false sense of security. The bad guys know this and attempt to crack passwords as a step toward breaking into computer systems.

One big problem with relying solely on passwords for information security is that more than one person can know them. Sometimes, this is intentional; often, it's not. You can't know who has a password other than the owner.

Knowing a password doesn't make someone an authorized user.

Here are the two general classifications of password vulnerabilities:

  • Organizational or end-user vulnerabilities: This includes lack of password awareness on the part of end users and the lack of password policies that are enforced within the organization.
  • Technical vulnerabilities: This includes weak encryption methods and insecure storage of passwords on computer systems.

    Before computer networks and the Internet, the user's physical environment was an additional layer of password security. Now that most computers have network connectivity, that protection is gone.

    DOWNLOAD THIS SAMPLE CHAPTER ON PASSWORDS HERE FOR FREE.


    For more related info on this topic, visit these SearchSecurity.com resources:
  • Ask the Expert: Not changing passwords on regular basis
  • Security Policies Tip: Password policies worst practices
  • Ask the Expert: Pose your security policy and management questions to Kevin

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Password Cracking
    Security360: Identity management market
    How to prevent hackers from accessing your router security password
    Complex password compliance requirements made simple
    Firefox, IE flaw could expose passwords
    Adding 'fudge' to your passwords
    Creating secure passwords you don't have to remember
    Scientists band together for TRUST-worthy research
    Yahoo fixes SSL flaw in Business E-mail
    RSA Conference 2006
    Review: With ID-Synch v4.0, you can easily manage many users

    Password Management
    Former LendingTree employees pilfer firm's customer database
    Hitachi acquires M-Tech Systems for identity management
    Worst practices: Exposing IAM blunders
    Sun shifts strategy with GRC push
    Security360: Identity management market
    IBM releases simplified Tivoli Identity Manager
    Top 10 access-related controls for PCI compliance
    Identity management woes
    What is the best way to securely change the local administrator password in a domain?
    What type of protections should security question and answer authentication credentials have?

    Password Policy
    Former LendingTree employees pilfer firm's customer database
    Security360: Identity management market
    Survey finds access control problems at many firms
    IBM releases simplified Tivoli Identity Manager
    Top 10 access-related controls for PCI compliance
    Identity management woes
    Will enabling Group Policy password settings affect existing user accounts?
    Complex password compliance requirements made simple
    Database authentication, encryption getting priority in some businesses
    Are knowledge-based authentication systems doing more harm than good?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    cracker  (SearchSecurity.com)
    masquerade  (SearchSecurity.com)
    salt  (SearchSecurity.com)
    session replay  (SearchSecurity.com)
    shadow password file  (SearchSecurity.com)
    war dialer  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

  • TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts