Showing posts with label Password Protection. Show all posts
Showing posts with label Password Protection. Show all posts

Friday, January 5, 2018

Network Security: Passwords and Human Error

A past IBM cyber security intelligence index report concluded that 95% of security breaches are caused by human error. Human error definitely includes password choices by users. It also includes password requirements and password storage by systems administrators. Passwords are a large part of network security. Hackers can use a technique called "password guessing" in which they manually enter passwords at a log-in prompt to gain access to an account when they have a valid user name. There are tools to automate this guessing process, known as an online attack, including Medusa, Ncrack, and Hydra.

These tools were built to help companies secure their networks as security specialists can test hosts and networking devices for poor passwords. These tools are used to audit devices as well. Online attacks can also be used to check that your firewalls, IDSs, and IPSs detect when a server gets bombarded with unsuccessful log-in attempts and that accounts lock in a short period when this happens. Password guessing through manual or automated means is obviously very noisy, so hackers need a better way to do it. Passwords should never be stored in plain text in databases. Storing passwords in plain text allows them to be used immediately after they're stolen. Passwords should be stored in a strong hash format since hashing is a one-way function. 

In many of the data breaches of recent years, stolen password databases contain passwords that were either stored in plain text or hashed with weak algorithms like MD5 or SHA-1. The current standards of hashing include SHA-256 and SHA-512, both forms of SHA-2.

On Linux systems, password hashes are stored in the etc/shadow file. Most Linux distros use SHA-512 with something called "SALT".

On Windows systems, password hashes are stored in the SAM file located at C:windows\system32\config\SAM. Some Microsoft documentation expands SAM to Security Account Manager while other Microsoft documentation expands SAM to Security Accounts Manager. On Windows domain controllers running Active Directory, password hashes are stored in the NTDS.dit file located at C:windows\NTDS\NTDS.dit. The Windows NTLM, Lan Manager Protocol Suite, actually uses MD4 without SALT for storing Windows hashes.

Websites that we log into store passwords in a backend database likely using the MySQL relational database management system. If a hacker enters the stolen hash into the password field, the hash itself would be hashed, so the attacker won't do that. What happens when a database containing hashed passwords are stolen? The hackers have three attack options after they steal the hashed password database. The first is called a "brute force attack" which uses a tool that generates a file containing all possibilities of letters, numbers, and symbols given a minimum and maximum length. The second is a dictionary attack which uses common words and their variations instead of trying all possibilities like a brute force attack does. The third is a rainbow table attack which requires more processing but less storage than a dictionary attack.

Thursday, July 7, 2016

Cyber Security: Passwords – what are they for?

Millions of people use online services every day, and it is crucial that these systems prevent users from accessing each other’s information. To do this, they need a way of uniquely identifying each user in a way that prevents users from impersonating each other. This is called identification and authentication.

Passwords and passcodes are the most common way of authenticating users. Examples of their use includes the PIN (Personal Identifier Number) you use with your debit and credit card as well as the many passwords you are expected to remember when logging in to computer-based services.

An ideal password must satisfy two conflicting aims. It should be:
  • memorable enough that the user can recall it without writing it down
  • long enough and unique enough that no one else can guess it.
Coursera - Hundreds of Specializations and courses in business, computer science, data science, and more

As you’ve almost certainly found out, remembering passwords is hard and it can be even harder to think of one that is secure. For these reasons many services are thinking about replacing passwords.

What happens when you enter a password?
When a user enters a password it is matched against the password stored by that website. If the passwords match, the user is granted access.

There are a couple of potential weaknesses with this approach that you can probably recognise:
  • The password is transmitted as plaintext (what you see is exactly what you get; it isn’t hidden in any way) – it could be intercepted as it travels across the network.
  • The password is stored as plaintext – an attack on the server could not only reveal the user’s password, but all the passwords for all the users of the system.
Top Data Science Specializations on Coursera

The first problem is usually overcome by encrypting the communication between the user and the server. The most common form of encryption is the SSL standard (Secure Socket Layer). You’ll recognise that SSL is being used when you see ‘https’ at the beginning of a web page address instead of ‘http’, and by a padlock symbol in your browser.

The second problem can also be solved using a technique called hashing. A hash is the result of processing plaintext to create a unique, fixed length identifier. It cannot be used to reconstruct the original data – even if the hash falls into hostile hands. In this scheme, a hashing function is used to create a hash of a password, which is stored on the server – the password itself is discarded. When the user enters a password, this is sent over the network and hashed on the server using a copy of the same hashing function. The resulting hash is compared to the hash stored on the password server. Only if they match will the user be granted access. Some implementations of this scheme will hash the user’s password before sending it across the network to be compared with the hash stored on the server.

Almost all online services and computer systems store passwords as hashes – but surprisingly, errors still happen. The problems described in the following case study could have been avoided if hashing had been used.

Machine Learning Specialization from University of Washington  

Case study: RockYou
The game and advertising company RockYou suffered a major security breach in 2009 when 32 million user accounts were compromised, revealing that not only did the company store passwords in plaintext, it encouraged insecure passwords by only requiring them to be five alphanumeric characters long.

RockYou’s problems were made worse when it became clear that they had known that their database was vulnerable to an attack for more than ten years. The company had previously been criticised on privacy grounds for sending emails containing complete lists of their advertising partners, and for poor security in issuing passwords through insecure email.

Even when hashing and encrypted communications are used, there are still ways in which attackers can successfully learn your password.

https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83045