munotes®

How Passwords Are Attacked, and the Arithmetic of a Keyspace

Get access to whole semester resourcesSemester Pass

Chapter Fifty-Eight

Syllabus topic Module 1, "System Hacking and Privilege Escalation Concepts: Analyze password cracking methods ... from a defensive perspective"

Pages 280 to 283 of 578

In one line

Passwords are attacked by guessing, in bulk and cleverly: dictionary attacks try likely words, brute force tries every combination, rainbow tables trade storage for speed against unsalted hashes, and credential stuffing reuses passwords leaked elsewhere. Each is defeated by a specific control, and the arithmetic shows why length matters most.

In examination wording: password cracking is the recovery of passwords from stored data or by repeated guessing; the principal methods are dictionary attacks, brute-force attacks, hybrid attacks, rainbow-table attacks against unsalted hashes, and credential stuffing exploiting reuse; the feasibility of brute force is governed by the size of the keyspace, which grows exponentially with password length.

Online against offline: the distinction that decides everything

Before the methods, the single most important distinction, because it determines which defence matters.

Online attacks guess at a live login. Every attempt goes through the system, which can count them, slow them, and lock the account. The attacker is limited to a handful of guesses before being blocked, so only the very weakest passwords fall, and the defences are rate limiting, lockout and multi-factor authentication.

Offline attacks happen after the attacker has stolen the password store (the previous chapter's scenario). Now there is no live system to count or slow the guesses; the attacker computes hashes on their own hardware, as fast as it allows, limited only by the strength of the hashing and the strength of the passwords. This is where billions of guesses per second happen, and where the storage model (slow, salted) and password strength are the only defences that apply.

The examinable consequence: lockout and rate limiting protect against online attacks and do nothing offline; the storage model and password strength protect against offline attacks. Confusing the two, for example thinking account lockout protects a stolen database, is a common error.

The attack methods

Dictionary attacks. Try likely passwords: common ones, words from a dictionary, names, and, most effectively, lists of passwords leaked from previous breaches. Because human password choice is so predictable, this catches a large fraction of accounts quickly, and leaked-password lists mean the "dictionary" is now tens of millions of passwords real people actually used.

Brute force. Try every possible combination up to some length. Guaranteed to succeed eventually, but "eventually" grows explosively with length, as the arithmetic below shows, so it is practical only against short or weak passwords.

Hybrid attacks. Dictionary words with predictable modifications: a capital first letter, a digit and a symbol appended, common substitutions. These catch exactly the passwords people choose when told to "add a number and a symbol", such as Password1!, which feels complex and is not.

Rainbow-table attacks. Precomputed tables mapping hashes back to passwords, so a stolen unsalted hash is looked up rather than cracked. The expensive computation is done once and reused. Defeated entirely by salting, from the previous chapter, which is why salting is not optional.

munotes.in280

How Passwords Are Attacked, and the Arithmetic of a Keyspace

Credential stuffing. Take username-and-password pairs leaked from one breach and try them, automatically and at scale, on many other services, relying on reuse. This is the most common real attack today, and it is why a password leaked from a trivial site endangers a user's important accounts. It is an online attack in form but uses confirmed credentials, so it succeeds far more often than blind guessing.

The arithmetic of length

"Make passwords longer" is provable, not a slogan. The number of possible passwords is the size of the character set raised to the power of the length. Take a character set of 95 printable characters, and count.

A six-character password has 95 × 95 × 95 × 95 × 95 × 95 = 735091890625 possibilities, about 735 billion. Each extra two characters multiplies that by 95 × 95 = 9025. So an eight-character password has 735091890625 × 9025 = 6634204312890625 possibilities, and a ten-character password has 6634204312890625 × 9025 = 59873693923837890625, close to sixty quintillion.

Length beats complexity: adding two characters multiplies the attacker's work by more than nine thousand, while swapping one letter for a symbol barely changes the count. A twelve-character passphrase of ordinary words is far stronger than an eight-character string of mixed symbols, and far easier to remember, which is why modern guidance favours length over mandated complexity.

The arithmetic also explains the online/offline split quantitatively. Against an online login limited to, say, ten guesses before lockout, even a six-character password is safe from brute force, because 735 billion possibilities against ten guesses is no contest. Against an offline attacker doing billions of guesses per second on a fast unsalted hash, that same six-character password falls in seconds, and only length and slow hashing push it back out of reach. The number that matters is set by which attack applies.

The defences, each matched to a method

Every defence maps to a specific attack, which is the defensive analysis MU asks for:

AttackDefeated by
Brute forceLength (the arithmetic), and a slow hash offline
Dictionary and leaked-listBlocking known-breached and common passwords at the point of choice
HybridLength again; a longer passphrase has no predictable pattern to exploit
Rainbow tablesSalting (previous chapter), completely
Offline cracking generallyA slow, salted hash (previous chapter)
Online guessingRate limiting and account lockout
Credential stuffingUnique passwords per site (a password manager) and multi-factor authentication
Any stolen or guessed passwordMulti-factor authentication, which makes it insufficient alone

The defensive summary in one line: make each guess slow (hashing), make each account hard to hammer (rate limiting, lockout), make the password space huge (length), make reuse harmless (uniqueness), and make a stolen password insufficient (multi-factor).

munotes.in281

How Passwords Are Attacked, and the Arithmetic of a Keyspace

A worked example, framed defensively

A company's password database is stolen. What happens depends entirely on the defender's earlier choices, which is the chapter's point:

  • Stored as fast, unsalted hashes: an attacker uses a rainbow table and recovers most passwords in minutes. Defence that would have prevented it: salting and a slow hash.
  • Stored as a slow, salted hash: offline cracking is reduced to the weakest passwords only, and even those take real time. The storage did its job; now length and blocking common passwords determine how many fall.
  • For accounts with multi-factor authentication: the recovered password alone does not grant access, so the breach's impact is limited regardless of password strength.
  • For users who reused these passwords elsewhere: credential stuffing endangers their other accounts, which uniqueness and multi-factor on those services would limit.

The response ranks the defences by which attack now applies: because this is an offline scenario, lockout is irrelevant and the storage model plus password strength plus multi-factor are what matter, which is exactly the online/offline reasoning applied.

What beginners get wrong

  • Thinking account lockout protects a stolen database. It protects online logins and does nothing offline, where the attacker has the hashes and no live system to lock.
  • Believing mandated complexity is the main defence. It mostly produces predictable Password1! strings that hybrid attacks catch. Length matters far more.
  • Assuming a strong password survives a breach. Once the store is stolen, only the storage model and multi-factor protect it; the password's strength helps only against brute force, not against a fast unsalted hash or a leaked plaintext.
  • Ignoring reuse. The biggest real-world attack is credential stuffing, which strong-but-reused passwords do nothing against. Uniqueness per site is essential.
  • Confusing the online and offline settings. They call for entirely different defences, and naming which one applies is the first step of any analysis.
  • Treating rainbow tables as a current threat against salted stores. Salting defeats them entirely; they matter only where hashes are unsalted.

Quick revision

  • Online attacks guess at a live login and are limited by rate limiting, lockout and multi-factor; only the weakest fall. Offline attacks work on a stolen store at hardware speed, limited only by the hashing and the password strength.
  • Methods: dictionary (likely words and leaked lists), brute force (all combinations, grows with length), hybrid (words with predictable tweaks), rainbow tables (precomputed, against unsalted hashes), credential stuffing (reuse across sites, the commonest today).
  • Length arithmetic (95-character set): six characters 95 × 95 × 95 × 95 × 95 × 95 = 735091890625; each extra two characters multiplies by 95 × 95 = 9025; eight characters 6634204312890625; ten characters 59873693923837890625. Length beats complexity.
  • Defences by attack: length (brute force), block known-bad (dictionary), salting (rainbow tables), slow salted hash (offline), rate limiting and lockout (online), uniqueness and multi-factor (credential stuffing), multi-factor (any stolen password).
munotes.in282

How Passwords Are Attacked, and the Arithmetic of a Keyspace

Test yourself

  1. Distinguish online and offline password attacks, and say which defences apply to each.

Online attacks guess at a live login, which can count, slow and lock the attempts, so they are limited to a few guesses and defeated by rate limiting, account lockout and multi-factor authentication. Offline attacks run against a stolen password store on the attacker's own hardware with no live system to slow them, so they are limited only by the strength of the hashing and of the passwords, and are defeated by a slow, salted hash, strong passwords and multi-factor authentication.

  1. Why does length defeat brute force more effectively than mandated complexity?

Because the number of possibilities is the character-set size raised to the length, so each added character multiplies the attacker's work: for a 95-character set, each extra two characters multiplies the space by 9025. Swapping one character type for another barely changes the count, so a longer passphrase grows the keyspace exponentially while adding a symbol does not.

  1. What is credential stuffing, why is it so effective, and what defeats it?

It is the automated reuse of username-and-password pairs leaked from one breach against many other services. It is effective because it uses confirmed credentials rather than blind guesses and exploits widespread password reuse, so it succeeds far more often than guessing. It is defeated by using a unique password per site, typically via a password manager, and by multi-factor authentication, which makes a reused password insufficient alone.

  1. Once a password database is stolen, which defences still protect the users, and why is lockout not among them?

The storage model, a slow salted hash that makes offline cracking infeasible for strong passwords, and multi-factor authentication, which makes a recovered password insufficient. Account lockout is not among them because it only limits guesses at a live login; an offline attacker has the hashes and computes guesses on their own hardware, where there is nothing to lock.

  1. Why does salting defeat rainbow-table attacks entirely?

Because a rainbow table is precomputed against passwords with no salt, and a per-user random salt means the attacker would have had to build a separate table for each specific salt, which they could not anticipate. The precomputed work is therefore useless, and the attacker is forced back to cracking each salted password individually at full cost.

munotes.in283

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!