HomeYoutubePassword attacks: Were you hacked and didn't "notice" it?

Password attacks: Were you hacked and didn't realize it?

Password attacks are one of the most common cyberattacks. See below for everything you need to know.

Password attacks

The authentication mechanism most people use to protect their accounts and systems is a password. A password is a string of characters, usually consisting of letters, numbers, and symbols.

The man behind the idea of ​​the password is Fernando Corbató. In 1961, Corbató was leading the Compatible Time-Sharing System (CTSS) project at the Massachusetts Institute of Technology. While working on this project, he realized there was a problem. As he said in an interview in 2012, multiple terminals had been created that would be used by multiple people, but with each person having their own private set of files. Corbató's solution was simple: give each user their own password.

Gradually, things evolved and passwords started to be used across various platforms, applications, etc. Passwords are very important, since they are used for protection. Given this, as well as the increase in cyberattacks, one finds that passwords are often targeted by criminals.

The first documented case of password theft occurred shortly after the password was invented. In 1962, Allan Scherr, a researcher at the Massachusetts Institute of Technology, wanted more time with CTSS to run some detailed simulations. To gain this extra access, he decided to exploit a process that allowed him to print out a list of all the passwords stored in the system, allowing him to log in with anyone's password.

Fortunately, Scherr was not an intruder, but a research collaborator working on the project.

Now, if someone has access to third-party passwords, it's probably not going to be good. And when we're talking about professional hackers, getting access passwords is a piece of cake.

Criminals use various methods to obtain passwords from unsuspecting users, which often makes the hackers' job easier. Many users use personal information as a passwordbecause it is easier to remember. However, this information may be known to other people (e.g., date of birth may be available on social media).

All the processes that hackers use to guess, steal, or generally obtain users' passwords fall into the category of password attacks.

Let's look at some of the most common types of password attacks:

Password attacks: Were you hacked and didn't realize it?

Brute-Force attacks

Brute force attacks are perhaps the most common type of password attack. It is said that 80% of breaches involve this type of attack. These password attacks take advantage of the fact that many users use short passwords. The shorter the password, the easier brute-force attacks are.

In this type of attack, cybercriminals use software that tries various combinations of usernames and passwords until they hit on the right combination that will give them access to a user's account. 

The password-cracking process starts with common passwords, such as “123456” and the word “password,” which take less than a second to crack. Then, more complex combinations. The programs used by hackers can generate a huge number of combinations to guess the correct password.

Password attacks

Dictionary attacks

Dictionary attacks are a form of brute-force attack. Initially, criminals tried simple words from dictionaries in various languages, such as English, French, or Spanish.

The idea behind this type of attack is that many people use a simple everyday word as a password. Everyday words and phrases are also tried, as well as well-known people's names, movie titles, etc.

Over time, however, attackers also began to exploit password lists exposed on the Internet.

More sophisticated dictionary attacks use information that is personalized for each target and that can be easily found online. For example, 's pet name , which could be easily found through the target's social media.

Password attacks: Were you hacked and didn't realize it?

Password Spraying (type of brute force attack)

The next password attack is the password spraying attack, where criminals use some common and well-known passwords on many different accounts to see if access can be gained.

Since passwords are reused so often, this attack has high success rates.

See also: Using the same passwords on different accounts is very dangerous!

Password spraying attacks typically target single sign-on and cloud-based platforms and can prove particularly dangerous for them.

Password attacks

Credential Stuffing

Next attack is the credential stuffing attack. Attackers use combinations of usernames and passwords to gain access to accounts, but they don't guess them, as in brute force attacks. Hackers use stolen credentials.

See also: 2020: 193 billion credential stuffing attempts detected

Credential stuffing attacks are based on the assumption that many people reuse passwords across multiple accounts.

Over the years, many breaches have led to the leakage of a huge number of compromised credentials.

Attackers use lists of exposed credentials to verify which of the stolen passwords are still valid or work on other platforms. As with brute force attacks, there are automated tools that make credential stuffing attacks incredibly successful.

Password attacks: Were you hacked and didn't realize it?

Keylogger

A keylogger is a type of spyware that monitors a user's activity by recording their keystrokes. A keylogger is particularly dangerous, as even the strongest passwords cannot protect the user.

Cybercriminals use keyloggers to steal a variety of sensitive data, from passwords to credit card numbers.

In a password attack, the keylogger records not only the username and password, but also the website or application that those credentials are used on. So it's all in the clear and the criminal doesn't have to guess or search for the credentials for an account.

Attackers typically install the keylogger on the victim's computer by getting the victim to click on a malicious link or attachment.

Password attacks

Phishing

Finally, we should not forget phishing, which also falls into the category of password attacks. Perhaps the simplest method of obtaining a user's credentials to compromise their account.

See also: Phishing emails target employees with bait to return to the office

Why would a hacker guess the password when he could simply ask the user for it?

Criminals send victims emails from seemingly legitimate and well-known services. They often target employees, impersonating a company executive. Through these emails, the hackers lead victims to fake login pages, where they are asked to provide their credentials.

Phishing and credential theft through this method is extremely common.

Password attacks

Strategies to reduce the risk of a password attack

1. Pen Test

The best way to find out if your organization is vulnerable to password attacks is to try a pen test. An automated pen testing tool can be used to quickly perform password attacks.

For example, a password spraying scenario can be run to determine if your environment is vulnerable by revealing which machines are sharing credentials.

This gives time for passwords to be changed before an actual attack.

2. Use multi-factor authentication (MFA)

MFA is not enough to use the user's password.

3. Strong passwords

Multi-factor authentication adds more barriers, but each barrier should be as strong as possible. For example, many types of MFA only require the second form of authentication once the first is validated.

This means that an attacker does not gain access, but will know that they had the correct credentials. This way, they can launch a password spraying attack on the rest of the network and potentially fall into applications that do not have MFA.

Therefore, it is important to ensure that passwords are as complex and unique as possible. Password managers can help create strong passwords. Ideally, passwords should be more than 12 characters long and include random numbers, symbols, and letters.

4. Activity/systems monitoring

Continuous monitoring of systems and networks is necessary in order to detect any suspicious activity.  

Also, banning access to an account after a certain number of failed attemptscan be quite helpful in detecting a potential breach.

5. Multi-layered defense

Password-focused tools like password managers and MFA should be combined with other security solutions, such as antivirus software and other forms of threat detection.

These can be used both for prevention and for response to attacks.

By implementing multi-layered defense, organizations can be more secure.

6. Education

In many cases, such as in phishing attacks, credential theft is due to human error.

Hackers manage to trick users, who then voluntarily give up their credentials or open malicious links that install malware.

Therefore, staff (and personal) training is essential to identify various threats.

As it turns out, password attacks can get us into trouble, and unfortunately, these attacks are very common. For this reason, we all need to be very careful!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS