1
00:00:00,480 --> 00:00:01,350
In this lesson,

2
00:00:01,350 --> 00:00:03,960
we will explore password attacks.

3
00:00:03,960 --> 00:00:06,360
Password attacks are methods used by attackers

4
00:00:06,360 --> 00:00:08,670
to crack or recover a password.

5
00:00:08,670 --> 00:00:10,830
There are several types of password attacks,

6
00:00:10,830 --> 00:00:12,900
including brute force attacks,

7
00:00:12,900 --> 00:00:14,130
dictionary attacks,

8
00:00:14,130 --> 00:00:15,030
spraying attacks,

9
00:00:15,030 --> 00:00:17,040
and hybrid attacks.

10
00:00:17,040 --> 00:00:19,320
First, we have brute force attacks.

11
00:00:19,320 --> 00:00:20,580
A brute force attack

12
00:00:20,580 --> 00:00:23,730
involves trying every possible combination of characters

13
00:00:23,730 --> 00:00:26,010
until the correct password is found.

14
00:00:26,010 --> 00:00:29,040
For example, an attacker might start with A,

15
00:00:29,040 --> 00:00:30,660
then B, then C

16
00:00:30,660 --> 00:00:32,159
all the way through Z,

17
00:00:32,159 --> 00:00:35,220
and then AA, AB, AC

18
00:00:35,220 --> 00:00:36,900
and so on and so forth.

19
00:00:36,900 --> 00:00:39,510
This type of attack is very thorough,

20
00:00:39,510 --> 00:00:41,580
but can be very time-consuming

21
00:00:41,580 --> 00:00:43,110
and computationally expensive,

22
00:00:43,110 --> 00:00:45,870
especially for long and complex passwords.

23
00:00:45,870 --> 00:00:46,890
On the other hand,

24
00:00:46,890 --> 00:00:49,860
if someone is simply using a four-digit pin,

25
00:00:49,860 --> 00:00:52,200
it will only take you about a minute or two

26
00:00:52,200 --> 00:00:54,033
to conduct a brute force attack against this.

27
00:00:54,033 --> 00:00:57,240
This is only about 10,000 possible combinations

28
00:00:57,240 --> 00:01:01,980
going from 0000 to 9999.

29
00:01:01,980 --> 00:01:03,990
And most password cracking software

30
00:01:03,990 --> 00:01:07,740
can crack between 500 to 1000 keys per second

31
00:01:07,740 --> 00:01:09,420
on most modern laptops,

32
00:01:09,420 --> 00:01:12,120
making a four-digit pin extremely insecure

33
00:01:12,120 --> 00:01:14,313
against any offline brute force attack.

34
00:01:15,240 --> 00:01:17,550
Brute force attacks can be mitigated

35
00:01:17,550 --> 00:01:19,680
through increasing password complexity,

36
00:01:19,680 --> 00:01:21,420
increasing password length,

37
00:01:21,420 --> 00:01:23,730
limiting the number of login attempts,

38
00:01:23,730 --> 00:01:25,830
and using multifactor authentication,

39
00:01:25,830 --> 00:01:26,820
and using CAPTCHAS

40
00:01:26,820 --> 00:01:30,000
to prevent online password cracking attempts.

41
00:01:30,000 --> 00:01:32,430
Second, we have a dictionary attack.

42
00:01:32,430 --> 00:01:35,040
A dictionary attack involves using a list

43
00:01:35,040 --> 00:01:37,740
or a dictionary of commonly used passwords

44
00:01:37,740 --> 00:01:39,150
and trying them all.

45
00:01:39,150 --> 00:01:41,670
When it was first introduced decades ago,

46
00:01:41,670 --> 00:01:45,000
dictionary attack actually use real dictionary words

47
00:01:45,000 --> 00:01:46,620
to attempt to crack the password,

48
00:01:46,620 --> 00:01:48,150
but in more recent years,

49
00:01:48,150 --> 00:01:51,300
these tools rely on a hacker's dictionary instead.

50
00:01:51,300 --> 00:01:53,130
For example, in a regular dictionary,

51
00:01:53,130 --> 00:01:56,130
you might find the word written as password, all lowercase,

52
00:01:56,130 --> 00:01:58,020
or password, all uppercase,

53
00:01:58,020 --> 00:02:01,530
or password with a capital P.

54
00:02:01,530 --> 00:02:03,330
But in modern hacker dictionaries,

55
00:02:03,330 --> 00:02:07,110
the word password may appear as those three options

56
00:02:07,110 --> 00:02:10,500
or as one with letters being changed out for numbers

57
00:02:10,500 --> 00:02:11,863
and symbols,

58
00:02:11,863 --> 00:02:13,063
like P

59
00:02:13,063 --> 00:02:14,730
@ symbol,

60
00:02:14,730 --> 00:02:16,110
dollar sign, dollar sign,

61
00:02:16,110 --> 00:02:17,280
lower case W,

62
00:02:17,280 --> 00:02:18,210
zero,

63
00:02:18,210 --> 00:02:19,860
R-D,

64
00:02:19,860 --> 00:02:21,840
or something similar.

65
00:02:21,840 --> 00:02:23,340
When you see the word written

66
00:02:23,340 --> 00:02:26,550
with these kind of symbolic and numerical substitutions,

67
00:02:26,550 --> 00:02:28,200
we call this "Leet Speak",

68
00:02:28,200 --> 00:02:30,090
which is the slang way of talking about

69
00:02:30,090 --> 00:02:31,860
the way former Elite hackers

70
00:02:31,860 --> 00:02:33,390
used to write out their usernames

71
00:02:33,390 --> 00:02:35,550
by adding these special characters and numbers

72
00:02:35,550 --> 00:02:39,420
inside of an otherwise normal looking dictionary word.

73
00:02:39,420 --> 00:02:42,090
Dictionary attacks can be very effective against users

74
00:02:42,090 --> 00:02:44,280
who use common easy-to-guess passwords,

75
00:02:44,280 --> 00:02:47,940
but less effective against complex, unique passwords,

76
00:02:47,940 --> 00:02:51,090
unless they do actually exist within the hacker dictionary,

77
00:02:51,090 --> 00:02:53,490
like most forms are the words password,

78
00:02:53,490 --> 00:02:55,743
administrator, admin, and the word root.

79
00:02:56,790 --> 00:02:58,710
Dictionary attacks can be mitigated

80
00:02:58,710 --> 00:03:01,620
by using the same techniques as brute force attacks,

81
00:03:01,620 --> 00:03:04,110
such as increasing password complexity,

82
00:03:04,110 --> 00:03:05,640
increasing password length,

83
00:03:05,640 --> 00:03:07,770
limiting the number of login attempts,

84
00:03:07,770 --> 00:03:09,270
and using multifactor authentication,

85
00:03:09,270 --> 00:03:10,230
as well as CAPTCHAS

86
00:03:10,230 --> 00:03:13,680
to prevent online password cracking attempts.

87
00:03:13,680 --> 00:03:16,800
Third, we have the password spraying.

88
00:03:16,800 --> 00:03:19,200
Password spraying is a form of brute force attacks

89
00:03:19,200 --> 00:03:20,940
that involves trying a small number

90
00:03:20,940 --> 00:03:22,260
of commonly used passwords

91
00:03:22,260 --> 00:03:25,350
against a large number of users or accounts.

92
00:03:25,350 --> 00:03:28,410
For example, an attacker might try password one

93
00:03:28,410 --> 00:03:31,140
against every account in a company's email system

94
00:03:31,140 --> 00:03:33,450
to see if anyone is using this weak password

95
00:03:33,450 --> 00:03:36,330
to try and protect their email accounts login.

96
00:03:36,330 --> 00:03:38,640
A password spraying attack can be effective

97
00:03:38,640 --> 00:03:41,520
because it avoids account lockups that can occur

98
00:03:41,520 --> 00:03:43,590
after a certain number of failed login attempts

99
00:03:43,590 --> 00:03:45,300
against a single account.

100
00:03:45,300 --> 00:03:46,920
Password spraying relies on the fact that

101
00:03:46,920 --> 00:03:48,240
in a large group of users,

102
00:03:48,240 --> 00:03:49,110
there's a good chance

103
00:03:49,110 --> 00:03:50,430
that at least a few of them

104
00:03:50,430 --> 00:03:54,690
are going to use very commonly known and weak passwords.

105
00:03:54,690 --> 00:03:56,730
Password spraying attacks can be mitigated

106
00:03:56,730 --> 00:03:58,140
by using unique passwords

107
00:03:58,140 --> 00:03:58,973
and, of course,

108
00:03:58,973 --> 00:04:01,980
implementing multi-factor authentication techniques.

109
00:04:01,980 --> 00:04:04,170
Finally, we have a hybrid attack.

110
00:04:04,170 --> 00:04:05,280
And a hybrid attack

111
00:04:05,280 --> 00:04:07,740
simply combines elements of a brute force

112
00:04:07,740 --> 00:04:08,880
and dictionary attack

113
00:04:08,880 --> 00:04:12,090
by starting out a dictionary of commonly used passwords,

114
00:04:12,090 --> 00:04:14,910
but also including variations like adding numbers

115
00:04:14,910 --> 00:04:17,790
or special characters to the ends of the passwords.

116
00:04:17,790 --> 00:04:20,880
This variation can be included in the dictionary itself,

117
00:04:20,880 --> 00:04:22,530
which would make it a dictionary attack

118
00:04:22,530 --> 00:04:24,420
or they can be created dynamically

119
00:04:24,420 --> 00:04:26,160
by your password cracking software

120
00:04:26,160 --> 00:04:27,960
in a true hybrid attack.

121
00:04:27,960 --> 00:04:30,570
For example, an attacker might have discovered

122
00:04:30,570 --> 00:04:31,680
during reconnaissance

123
00:04:31,680 --> 00:04:34,650
that the company requires that everyone uses a password

124
00:04:34,650 --> 00:04:37,470
that contains a eight-character dictionary word

125
00:04:37,470 --> 00:04:40,980
and then append a six-digit random number to the end of it.

126
00:04:40,980 --> 00:04:43,320
So if my dictionary word was fabulous,

127
00:04:43,320 --> 00:04:45,970
and my randomly assigned number was 617238

128
00:04:47,820 --> 00:04:52,320
then my new password would be set as fabulous61238.

129
00:04:52,320 --> 00:04:55,920
So if you know that everyone's password follows this format,

130
00:04:55,920 --> 00:04:57,750
you can use a dictionary based attack

131
00:04:57,750 --> 00:04:59,719
to find the first word like fabulous

132
00:04:59,719 --> 00:05:01,200
and then use a brute force attack

133
00:05:01,200 --> 00:05:04,330
to try every combination from fabulous000001

134
00:05:06,101 --> 00:05:09,120
to fabulous999999

135
00:05:09,120 --> 00:05:12,713
until the correct password is found as fabulous617238.

136
00:05:15,540 --> 00:05:16,890
In this short demonstration,

137
00:05:16,890 --> 00:05:17,820
I will walk you through

138
00:05:17,820 --> 00:05:21,660
how to use the John the Ripper password cracking tool.

139
00:05:21,660 --> 00:05:24,300
John the Ripper, commonly just referred to as John,

140
00:05:24,300 --> 00:05:26,190
is a popular password cracking tool

141
00:05:26,190 --> 00:05:28,950
that has gained a reputation for speed and versatility.

142
00:05:28,950 --> 00:05:32,250
It's primarily used to identify weak Unix passwords

143
00:05:32,250 --> 00:05:35,220
though it supports hashes of many other platforms as well.

144
00:05:35,220 --> 00:05:36,900
Now let's walk through a quick demonstration

145
00:05:36,900 --> 00:05:38,340
of how to use John.

146
00:05:38,340 --> 00:05:39,300
Before starting,

147
00:05:39,300 --> 00:05:41,580
let's ensure John is installed on your system.

148
00:05:41,580 --> 00:05:44,146
On Linux, you can often use it with the "sudo

149
00:05:44,146 --> 00:05:47,460
apt-get install john".

150
00:05:47,460 --> 00:05:50,430
Now I'm using Kali Linux, so it's already pre-installed,

151
00:05:50,430 --> 00:05:52,200
but I'm just going to run through the command really quick

152
00:05:52,200 --> 00:05:55,140
for those of you who doesn't have Kali Linux.

153
00:05:55,140 --> 00:05:56,580
All right.

154
00:05:56,580 --> 00:06:00,480
Password in for sudo, elevated privileges.

155
00:06:00,480 --> 00:06:02,760
Okay, we see John is already installed

156
00:06:02,760 --> 00:06:04,260
and I have the latest version now.

157
00:06:04,260 --> 00:06:05,610
Again, if you didn't have it,

158
00:06:05,610 --> 00:06:07,620
it would've installed it for you there.

159
00:06:07,620 --> 00:06:11,130
Next, let's create a simple file with a MD5 hash

160
00:06:11,130 --> 00:06:12,780
for John the Ripper to crack.

161
00:06:12,780 --> 00:06:16,020
Remember using MD5 for hashing is not recommended

162
00:06:16,020 --> 00:06:19,680
for any actual security purposes due to its vulnerabilities.

163
00:06:19,680 --> 00:06:22,260
This demonstration is for educational purposes only.

164
00:06:22,260 --> 00:06:24,240
Now, if you're going to store passwords,

165
00:06:24,240 --> 00:06:27,120
always use a strong cryptographic hashing algorithm

166
00:06:27,120 --> 00:06:30,060
like SHA-256 combined with a salt.

167
00:06:30,060 --> 00:06:31,200
Now, salting and hashes

168
00:06:31,200 --> 00:06:33,630
involve adding a random string of characters,

169
00:06:33,630 --> 00:06:34,860
also known as a salt

170
00:06:34,860 --> 00:06:37,470
to protect the password before hashing it.

171
00:06:37,470 --> 00:06:39,030
Now, this enhances the security

172
00:06:39,030 --> 00:06:40,770
by preventing any dictionary text

173
00:06:40,770 --> 00:06:44,310
or hashing table lookups like we're about to perform here.

174
00:06:44,310 --> 00:06:46,410
Now let's create this file.

175
00:06:46,410 --> 00:06:47,820
I'm going to use the Echo command

176
00:06:47,820 --> 00:06:49,710
so I'm going to use the "echo -n".

177
00:06:49,710 --> 00:06:51,420
I'm going to put in the word password

178
00:06:51,420 --> 00:06:54,300
and I'm going to make sure I get the md5sum of it.

179
00:06:54,300 --> 00:06:56,010
So I'm going to use a pipe command.

180
00:06:56,010 --> 00:06:58,170
And then one thing to note about

181
00:06:58,170 --> 00:06:59,820
when you use the md5sum command,

182
00:06:59,820 --> 00:07:01,650
it's going to add this hyphen at the end.

183
00:07:01,650 --> 00:07:03,600
So I'm going to use the alt command

184
00:07:03,600 --> 00:07:05,730
to remove that particular character

185
00:07:05,730 --> 00:07:08,580
and then add it to the mypassword.txt file.

186
00:07:08,580 --> 00:07:10,560
I have this command already pre-formatted,

187
00:07:10,560 --> 00:07:12,390
so I'm just going to click enter.

188
00:07:12,390 --> 00:07:15,150
Now, let's look and see this particular file.

189
00:07:15,150 --> 00:07:17,190
Okay, we see we have our MD5 hash.

190
00:07:17,190 --> 00:07:19,790
Next we're going to run a command to get John cracking.

191
00:07:20,670 --> 00:07:23,580
We're going to use the "john --format

192
00:07:23,580 --> 00:07:25,947
=Raw-md5"

193
00:07:25,947 --> 00:07:27,990
and then we're going to specify the particular file

194
00:07:27,990 --> 00:07:28,890
that we're going to use.

195
00:07:28,890 --> 00:07:30,960
And I'm going to use mypassword.txt

196
00:07:30,960 --> 00:07:32,860
or you can use whatever name you have.

197
00:07:34,440 --> 00:07:35,880
Here's that command for you.

198
00:07:35,880 --> 00:07:37,770
Now I'm going to go ahead and click enter.

199
00:07:37,770 --> 00:07:39,600
And we see that was very quick.

200
00:07:39,600 --> 00:07:42,660
And you see highlighted in the orange, the password,

201
00:07:42,660 --> 00:07:44,820
that's the actual password,

202
00:07:44,820 --> 00:07:47,520
showing that it was easily cracked.

203
00:07:47,520 --> 00:07:48,540
And if you note,

204
00:07:48,540 --> 00:07:51,240
right before it said it proceeded with the word list,

205
00:07:51,240 --> 00:07:54,060
meaning that password was already in the list

206
00:07:54,060 --> 00:07:55,860
of all the different hashes,

207
00:07:55,860 --> 00:07:59,130
more so specifically the MD5 hash lookup table.

208
00:07:59,130 --> 00:08:01,410
So all they did was just find the hash for password

209
00:08:01,410 --> 00:08:03,420
and just print it out for me.

210
00:08:03,420 --> 00:08:05,550
And again, that's why it's critical

211
00:08:05,550 --> 00:08:07,530
to make sure that you're using strong passwords

212
00:08:07,530 --> 00:08:09,780
and nothing that's easily and commonly used

213
00:08:09,780 --> 00:08:11,430
because something like John the Ripper

214
00:08:11,430 --> 00:08:13,503
could easily find it in a second.

215
00:08:14,340 --> 00:08:15,300
Something to note,

216
00:08:15,300 --> 00:08:16,260
if you are on the command

217
00:08:16,260 --> 00:08:17,880
and miss the output for some reason,

218
00:08:17,880 --> 00:08:20,370
the hash will not be attempted to be cracked again

219
00:08:20,370 --> 00:08:24,870
and will instead be stored in the /.john/john.pot file,

220
00:08:24,870 --> 00:08:28,110
which is usually under user's home directory.

221
00:08:28,110 --> 00:08:30,903
So really quick, let me show you that.

222
00:08:31,740 --> 00:08:34,559
So we see that MD5 hash is stored in here.

223
00:08:34,559 --> 00:08:36,929
So again, it won't crack it again.

224
00:08:36,929 --> 00:08:38,100
You see how it now states

225
00:08:38,100 --> 00:08:40,590
that there's no password hashes left to be cracked.

226
00:08:40,590 --> 00:08:42,000
That's because it's already cracked

227
00:08:42,000 --> 00:08:43,590
and it's in that particular file.

228
00:08:43,590 --> 00:08:45,300
So if you have this issue,

229
00:08:45,300 --> 00:08:46,890
that's where you need to look.

230
00:08:46,890 --> 00:08:48,090
And if you want to run it again,

231
00:08:48,090 --> 00:08:49,770
you can just simply clear that file

232
00:08:49,770 --> 00:08:51,240
or just delete the file entirely

233
00:08:51,240 --> 00:08:52,500
and then it will create another one

234
00:08:52,500 --> 00:08:55,710
after you run that new John the Ripper command.

235
00:08:55,710 --> 00:08:58,650
So remember, brute force attacks

236
00:08:58,650 --> 00:09:01,500
are used to try all of the possible combinations

237
00:09:01,500 --> 00:09:03,720
for a password in order to crack it,

238
00:09:03,720 --> 00:09:06,930
but they can be very time-consuming and expensive to conduct

239
00:09:06,930 --> 00:09:09,240
from a computational perspective.

240
00:09:09,240 --> 00:09:10,290
A dictionary attack

241
00:09:10,290 --> 00:09:12,540
will use a list of commonly used passwords

242
00:09:12,540 --> 00:09:14,370
from a text file known as a dictionary

243
00:09:14,370 --> 00:09:16,380
to attempt to guess the password.

244
00:09:16,380 --> 00:09:17,670
A password spraying attack

245
00:09:17,670 --> 00:09:20,040
attempts to try the same few passwords

246
00:09:20,040 --> 00:09:21,750
against a lot of different accounts

247
00:09:21,750 --> 00:09:22,920
to try and prevent

248
00:09:22,920 --> 00:09:26,100
locking out of any individual user account

249
00:09:26,100 --> 00:09:29,010
during the online password cracking attempt.

250
00:09:29,010 --> 00:09:30,480
And a hybrid attack

251
00:09:30,480 --> 00:09:33,030
is used to combine the benefits of a dictionary

252
00:09:33,030 --> 00:09:35,850
and brute force attack to find longer, stronger,

253
00:09:35,850 --> 00:09:37,470
and more complex passwords

254
00:09:37,470 --> 00:09:39,990
in less time than a brute force attack could do on it

255
00:09:39,990 --> 00:09:41,220
and so on.

256
00:09:41,220 --> 00:09:42,780
To protect against these attacks,

257
00:09:42,780 --> 00:09:45,720
your organization should require the use of a unique,

258
00:09:45,720 --> 00:09:47,460
long, and complex password,

259
00:09:47,460 --> 00:09:49,230
such as using password managers

260
00:09:49,230 --> 00:09:52,260
to help manage your user's passwords on the network.

261
00:09:52,260 --> 00:09:54,450
Also, to really prevent password attacks

262
00:09:54,450 --> 00:09:55,650
from being successful,

263
00:09:55,650 --> 00:09:57,570
you should enable multi-factor authentication

264
00:09:57,570 --> 00:09:58,620
whenever possible,

265
00:09:58,620 --> 00:10:01,170
since it adds an additional layer of security

266
00:10:01,170 --> 00:10:04,380
by requiring a second factor of authentication to be used

267
00:10:04,380 --> 00:10:06,063
in addition to just a password.

