Ravindra BagaleCourses & study guides

22. Password Attacks

Chala mitrano, aaj passwords cha vishay – hacking cha sarvat junaa pan aajhi sarvat prabhavi darvaja. Log weak passwords thevtat, reuse kartat, aani hech attacker la sarvat sopa marg deto. Aaj aapan shiku ki passwords kase todle jatat (cracking) aani services var kase try kele jatat (guessing) – aani sarvat mahatvacha, aapan swatahche aani users che passwords kase surakshit thevaycha. Punha ekda: sagle labs fakt tumchya lab machines var (Metasploitable 2, tumcha swatahcha server). Baherchya konatyahi account var nahi. Samjla ka? Chala suru!

What you will learn in this chapter

  • How passwords are stored: plain text, hashing, salting
  • Offline vs online password attacks
  • Wordlists and rules; rockyou.txt
  • John the Ripper: cracking captured hashes
  • Hashcat: fast, GPU-based cracking and attack modes
  • Hydra: online login testing against services
  • Defences: strong hashing, account lockout, MFA and rate limiting

Lab scope for this whole chapter

Crack only hashes you captured from your own lab (Metasploitable 2, your own server) and run Hydra only against lab services. Trying passwords against anyone else's account, email or website is a crime under the IT Act, sections 43 and 66.

Concepts in this chapter

  1. 22.1How Passwords Are Stored
  2. 22.2Online vs Offline Attacks, and Wordlists
  3. 22.3John the Ripper: Cracking Hashes
  4. 22.4Hashcat: Fast GPU Cracking
  5. 22.5Hydra: Online Login Testing
  6. 22.6Defending Against Password Attacks
  7. 22.7Red vs Blue, Project and Real Incidents

The chapter recap is at the end of the last concept page.