Brute force cracking is a method for cracking passwords, which involves calculating the passwords one by one until the real password is found.
For example, a password known to be four digits and consisting entirely of numbers may have 10,000 combinations, so it takes a maximum of 10,000 attempts to find the correct password. When encountering scenarios where passwords are manually set (with patterns to follow), a password dictionary can be used to look up high-frequency passwords, greatly shortening cracking time.
Brute-force cracking is a common cybersecurity attack method, also known as exhaustive methods or enumeration methods. It is a method for cracking passwords. So what is brute-force cracking? What are some methods for brute-force hacking? Let's take a look at the specific details.
Brute force cracking is a method of deciphering passwords, which involves calculating the passwords one by one until the real password is found. For example, a password that is known to be four digits and consists entirely of numbers may have 10,000 combinations, so it takes a maximum of 10,000 attempts to find the correct password. When encountering scenarios where passwords are manually set, a password dictionary can be used to look up high-frequency passwords, greatly shortening cracking time.
Setting long and complex passwords, using different passwords in different places, avoiding using personal information as passwords, and changing passwords regularly are effective ways to prevent brute-force cracking.
1. Exhaustive Method
Exhaustive method refers to generating a complete set of possible passwords based on the set length of the input password and the selected character set, and performing a carpet search. For example, a password that is known to be four digits and consists entirely of numbers may have 10,000 combinations, so it takes a maximum of 10,000 attempts to find the correct password. Theoretically, this method can be used to crack any type of password, but as the complexity of the password increases, the time to crack the password will increase exponentially.
The exhaustive method is suitable for guessing randomly generated SMS verification codes, etc., because the probability of various randomly generated passwords appearing is the same and is not affected by human memory.
2. Dictionary attack
A dictionary attack saves the most frequently occurring passwords into a file, which is a dictionary. During a breach, these passwords in the dictionary are used to guess them.
Dictionary attacks are suitable for guessing artificially set passwords because the probability of different passwords appearing due to artificial memory is different. The probability of 12345678 and password being used as passwords is much higher than the probability of fghtsaer being used as passwords. Compared with exhaustive methods, dictionary attacks save more time although they lose less hit rate.
3. Rainbow table attack
Rainbow table attack is also a dictionary attack, but it is an efficient attack method to crack hash algorithms.