Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Privacy » Weak Password Validation - How attackers illegally obtain, change or recover another people's password

Weak Password Validation - How attackers illegally obtain, change or recover another people's password

Category: Privacy
Published: 02/02/2007, 11:59  
Editor: Security Software Zone
 
Print article
Send to a friend
Search in reviews

Conventional web site authentication methods require users to select and remember a password or passphrase. The user should be the only person that knows the password and it must be remembered precisely. As time passes, a user's ability to remember a password fades. The matter is further complicated when the average user visits 20 sites requiring them to supply a password. (RSA Survey: http://news.bbc.co.uk/1/hi/technology/3639679.stm)

Thus, Password Recovery is an important part in servicing online users. Examples of automated password recovery processes include requiring the user to answer a "secret question" defined as part of the user registration process. This question can either be selected from a list of canned questions or supplied by the user. Another mechanism in use is having the user provide a "hint" during registration that will help the user remember his password. Other mechanisms require the user to provide several pieces of personal data such as their social security number, home address, zip code etc. to validate their identity.

After the user has proven who they are, the recovery system will display or e-mail them a new password. A web site is considered to have Weak Password Recovery Validation when an attacker is able to foil the recovery mechanism being used. This happens when the information required to validate a user's identity for recovery is either easily guessed or can be circumvented. Password recovery systems may be compromised through the use of brute force attacks, inherent system weaknesses, or easily guessed secret questions. For example (Weak methods of password recovery) Information Verification Many web sites only require the user to provide their e-mail address in combination with their home address and telephone number. This information can be easily obtained from any number of online white pages. As a result, the verification information is not very secret. Further, the information can be compromised via other methods such as Cross-site Scripting and Phishing Scams.

Password Hints A web site using hints to help remind the user of their password can be attacked because the hint aids Brute Force attacks. A user may have fairly good password of "122277King" with a corresponding password hint of "bday+fav author". An attacker can glean from this hint that the user's password is a combination of the users birthday and the user's favorite author. This helps narrowing the dictionary Brute Force attack against the password significantly. Secret Question and Answer A user's password could be "Richmond" with a secret question of "Where were you born". An attacker could then limit a secret answer Brute Force attack to city names. Furthermore, if the attacker knows a little about the target user, learning their birthplace is also an easy task.

Bookmark to:
Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Del.icio.us Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to digg Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to FURL Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to reddit Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Technorati Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Yahoo My Web Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Stumble Upon Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Google Bookmarks Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to RawSugar Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Squidoo Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Spurl Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Netvouz Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Rojo Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Bloglines Add 'Weak Password Validation - How attackers illegally obtain, change or recover another people's password' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to Weak Password Validation - How attackers illegally obtain, change or recover another people's password
 

How To Get A Pop Up Blocker
 Where can you acquire a pop up blocker for your computer?
Read More >
12/07/2006, 17:17
 

Amphora's PatentSafe Solution Selected by Functional Genetics, Inc.
 A key provider of electronic laboratory notebook (ELN) products for the biotech industry, Amphora Research Systems (http://www.amphora-research.com), announces the purchase of a biotechnology company leveraging innovative science to develop new therapeutics for infectious disease and to improve the quality and efficiency of biologics, Amphora's PatentSafe solution for researchers at Functional Genetics.
Read More >
05/16/2008, 13:24
 

Javelin Strategy & Research Report Sees Innovative Approach TranscationVault
 A provider of enterprise payment solutions to the integrated point-of-sale industry, Merchant Link (http://www.merchantlink.com ), announced that its TransactionVaultTM product for its innovative ability to move customer credit card data to a safe, secure, and fully monitored and managed location away from the merchant's POS terminals, was recognized and cited in a recent analysis by Javelin Strategy & Research.
Read More >
03/27/2008, 12:07
 

New Service that Secures the Wi-Fi and Edge Based Internet Connections for Apple iPhone Users Launched by GoTrusted.com
 GoTrusted.com guards iPhones from vulnerabilities exploited over insecure networks and encrypts all of the iPhone's Internet traffic.
Read More >
08/02/2007, 21:57
 

GoTrusted Secure Tunnel - One-Click Simplicity to Encrypting any Unsecured Internet Connection, Such as Public WiFi Hotspots
 Named 'GoTrusted Secure Tunnel,' the new software brings the one-click simplicity to encrypting any unsecured Internet connection, such as public WiFi hotspots.
Read More >
05/25/2007, 18:34

Sponsored