HomeSecuritySix ways hackers can crack your password!

Six ways hackers can crack your password!

If you've ever had your bank account or online accounts like Gmail, Yahoo, Facebook, or Twitter hacked, you should know that cybercriminals use special tricks to get into your account. With passwords being the central theme of almost all your accounts, hackers prefer to go after yours to hack into your financial as well as online accounts.

If your account has been hacked, criminals likely used one of the 6 ways below to get into your account. If you have studied these methods, you can be better prepared to ward off such unpleasant events in the future and control your accounts easily.

Six ways hackers can crack your password!

Brute force attack

Brute force is about overloading a computer's defenses by using repetition. Brute force attack is a random trial and error hacking method that is repeated until the password is finally cracked. Hackers randomly enter names and numbers to crack passwords using this pattern. Sometimes, multiple guesses are used to crack the password. Some of the most commonly used passwords are arithmetic numbers, date of birth, pet's name, or favorite actor's name.

Dictionary Hacking

Dictionary Hacking is also a form of Brute force attack. But in Dictionary Hacking, hackers use different variations and combinations of words from a dictionary. They repeatedly use a dictionary software and try a combination of words to crack your password. One report states that over 50 percent of passwords have been cracked through this process.

Brute force dictionaries always start with simple letters “a”, “AA”, “AAA”, and eventually then, they progress to whole words like “dog”, “doggie”, “doggy”. These Brute force dictionaries can make up to 50 attempts per minute in some cases.

Phishing

Phishing is the next most commonly used tool by hackers to obtain usernames and passwords. Phishing is also the most widely used method because it only takes one trick to trick the victim into revealing credentials . Most trojans are spread through phishing, while sometimes hackers create cloned websites or fake web addresses, in which they ask for a username and password.

phishing

Phishing is the attempt to obtain sensitive information, such as usernames, passwords, and credit card details (and sometimes, indirectly, cash), often for malicious purposes, by disguising themselves as a trusted entity behind an electronic communication.

Spidering attack

Another hacking tool is the spidering attack. Just as the name suggests, hackers crawl your website like a spider and collect all the common information. Cybercriminals usually use the spidering attack when targeting large companies.

A spider is a tool that crawls a website and searches for all available content. There are a few different ways to discover content:

– Static Content

– Dirbuster

– HTTP Method

– Ascension Fuzz

– Query Fuzz

– Cookie Fuzz

– Robots.txt / Sitemap.xml

– RIA Checks

– UserAgent

– Regexp path/url

– Public cache search

– /status

Keylogger attack

This hacking tool is very similar to Phishing and is generally spread through malware infections. The victim is usually tricked into installing the keylogger on their computer or laptop by clicking on an attachment that has been sent to the victim via email. The moment the attachment is downloaded, it is scanned through browser . Once installed, the keylogger records all your Internet activity which is then sent back to the command and control servers.

Rainbow Table

While you might think of Rainbow Tables as fancy colorful furniture, that's not what we're going to be discussing. The Rainbow Tables we're talking about here are used to crack passwords and are yet another tool in the ever-growing arsenal of hackers.

hackers Rainbow Table hackers

This method requires good computer and programming skills. Rainbow Tables are basically huge sets of precomputed tables filled with hash values ​​that are pre-matched to possible plaintext passwords. Rainbow Tables essentially allow hackers to reverse the hash function to figure out what the plaintext password. It is possible for two different passwords to end up with the same hash so it is not important to figure out what the original password was, just because it has the same hash. The plaintext password may not even be the same password that the user created, but as long as the hash matches, then it does not matter what the original password was.

Using Rainbow Tables allows passwords to be cracked in a very short time compared to Brute force methods, however, the "flaw" is that it consumes a lot of storage space (sometimes Terabytes) to hold Rainbow Tables. However, storage is not a big issue for hackers these days. You can also get precomputed Rainbow tables to crack passwords of vulnerable operating systems like Windows XP, Vista, Windows 7 and applications that use MD5 and SHA1 as password hashing mechanisms (many web application developers still use these hashing algorithms).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS