3 ms·
I'm sorry if it's dumb question, but how could one perform dictionary attack without having access to the hash table? From the login page? Unlikely, it will loc
by roman_savchuk 9y ago
I'm sorry if it's dumb question, but how could one perform dictionary attack without having access to the hash table? From the login page? Unlikely, it will lock itself after a few unsuccesful attempts. Yet article implies that if password is weak everything else doesn't matter.
- k4ch0w 9y agoBro, totally not a dumb question. From an Attacker's point of view, yes logging in from the same IP against the same account will get you banned fairly quickly. People put up their best defenses on the most obvious endpoint, which is why a good attacker quickly tries something else. However, two possible routes to circumvent this are 1. Find a vulnerable API call/Webportal on the bank's other sites that don't have IP banning but require authentication. This happens much more than you'd realize. 2. A distributed attack, either with a large proxy network or if you have a botnet, in which you bruteforce the credentials with different time intervals/simulated human behavior to not lock out the account.
- roman_savchuk 9y agoOk, thanks for explaining.
- sgt101 9y ago1. seems like someone is really screwing up with an API like this. 2. Ok, for a three word combo with I think >40000^3 =64 billion possibles, so to have a 50% chance of cracking a password you need 32 billion goes, with a human speed api you're talking 5 seconds per go (mean, and probably you'd get caught on this rate) so 1 million bots (and I think the bank would be suspicious if it saw 1 million different IP's trying one account- would need 32 * 5000 seconds.. 2 days to get one account. Doesn't feel remotely feasible!
- k4ch0w 9y ago1. It happens more than you'd think. Some legacy system is still up and they are connected to the same credential store. You find a hole and get into their internal network and some random webportal that no one maintains still has access to the database. 2. Yes, so this one is more like you are shooting with a shotgun from a long long range and hoping to hit. You can improve the accuracy by using a password dump on your target. People have a common pattern that they use with their passwords. You can either find one that is still being used or try to find a couple they have used and create a new one. Great site to demonstrate the power of a password dump is https://haveibeenpwned.com/ https://haveibeenpwned.com/. So in some cases it is possible, but as someone who professionally red teams, I wouldn't bruteforce past a certain time period before trying something else.