22.6 Defending Against Password Attacks
Attack samajla ki defence sopa hoto. He sagle tumhi tumchya reels app aani servers var lavu shakta:
| Defence | What it stops | How (from earlier chapters) |
|---|---|---|
| Slow, salted hashing (bcrypt/Argon2) | Offline cracking | password_hash() in PHP; never md5/sha1 |
| Strong password policy | Weak, guessable passwords | Length over complexity; check against leaked lists |
| Account lockout / rate limiting | Online guessing (Hydra) | Lock after N failures; fail2ban for SSH |
| Multi-factor authentication (MFA) | Stolen or cracked passwords | OTP/app on logins; AWS MFA (Chapter 25) |
| Key-only SSH | SSH password attacks | Disable PasswordAuthentication (Chapter 4, hardening in 28) |
| No password reuse + a manager | One leak breaking many accounts | User awareness |
fail2ban watches log files and bans an IP after too many failed logins:
sudo yum install epel-release -y && sudo yum install fail2ban -y # Amazon Linux
sudo service fail2ban start
sudo fail2ban-client status sshd # see banned IPs
Why this matters for security
Most real breaches do not use a clever exploit – they use a weak, reused or leaked password. Strong hashing, MFA and lockouts stop the large majority of attacks in this chapter at almost no cost.
Ravindra Bagale's Tip
"Password madhe capital, number, symbol pahije" ha juna salla aahe – log Pass@123 sarkhe andajache passwords banvtat. Aajcha changla salla: motha (long) passphrase + MFA. GhodaChaChahaPeto2024 he P@ss1 peksha khup surakshit aahe. He students la aavarjun sanga.
Lab
Install fail2ban on your lab server, run Hydra against its SSH from Kali, and confirm your Kali IP gets banned (sudo fail2ban-client status sshd). Then enable MFA on your AWS account and describe how it would stop a cracked console password.