19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Threats Catalogue Deliberate Acts Remarks<br />

____________________________________________________________________ .........................................<br />

T 5.18 Systematic trying-out of passwords<br />

Passwords which are too simple can be found out by systematically trying<br />

them out.<br />

Example:<br />

A study made by Klein (Klein, Daniel V. 1990, USENIX Security<br />

Workshop Proceedings, Portland, August 1990) of 15,000 accounts yielded<br />

a success rate of 24.2 per cent; the following password options were tried<br />

out:<br />

About 130 variations of the log-in name (first and last names) and of other<br />

personal data from the /etc/passwd file; frequent names, names of wellknown<br />

persons, names and places in movies, from sports events and from<br />

the Bible; abusive common invectives/swear-words, and words from<br />

foreign languages; different variations of these words, e.g. changes from<br />

upper and lower case, insertion of special characters and check symbols,<br />

reversing of the sequence of letters, repeated letters (e.g. aaabbb), or<br />

frequent abbreviations (e.g. rygbv for the colours of the rainbow) and pairs<br />

composed of two short words.<br />

All these combinations and more can be tried out by any user of the UNIX<br />

system in which the password file is freely accessible, using the crack PD<br />

program. Moreover, for passwords that are too short, it is highly probable that<br />

the password can be found out by systematically trying out all combinations.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!