Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Brute force attacks?
Well, first of all, what is it, a brute force attack is an attempt using trial and error to crack
a password and username, find the high, then you are an encryption key and so on.
It's probably not very clear.
So let's see a simple example from the non digital world.
We have this lock that has ten thousand maximum combinations.
This means that if we tried them one by one, we will eventually find the right key that unlocks it.
Imagine that this is your password.
That, of course, has many more possible combinations.
But instead of having two hands, we have quite some advanced computing power that can calculate possible
solutions at a very high rate.
This is a very simple example of how trial and error works and how to crack a lock.
But let's get back to our digital world and see what types of brute force attacks are out there.
We have six main categories.
The first one is a simple brute force attack.
This uses a systematic approach to guess that doesn't rely on outside logic.
Second, hybrid brute force attacks this start from the external logic to determine which person variation
may be most likely used to succeed and then continues with the simple approach to try many possible
variations.
Third, dictionary attacks.
This gives us usernames and passwords using a dictionary of possible strings or phrases.
Fourth rainbow table attacks, a rainbow table is a free computer table for reversing cryptographic
hash functions, it can be used to get the function up to a certain length consisting of a limited set
of characters.
Five reverse brute force attack, this uses a common password or collection of passwords against many
possible usernames, targets a network of users for which the attackers have previously obtained Data
six credential stuffing users previously well known password username Pear's, trying them against multiple
websites, exploit the fact that many users have the same username and password across different systems.
Now that you have an idea about what brute force is and what are the types of attacks.
Let's get back to some scenarios that you can apply as a home user.
We will see how you can secure your passwords and how you can protect against possible attacks.
How secure is a password?
This is the average computer time on which a password can be brute force.
And this is quite interesting because a simple password like admin can be roughly cracked in around
eight seconds.
But a complex password that has multiple types of characters can take up to some months or even centuries.
And now let's see, based on this, what are the best practices, we compiled a list of six recommendations
that we wanted to give you.
First, use a password manager.
This will actually help you for the other five items from our list.
We're going to live in the brute force document from the resources, a link with all the free and paid
password managers.
Second, use a minimum password length of twenty or more characters if permitted.
Third, include lowercase and uppercase, alphabetical characters, numbers and symbols if permitted.
Fourth, generate passwords randomly, one possible.
Here is also where the password manager can help since they can generate passwords based on different
options that you can select.
Fifth, avoid using the same password twice across multiple user accounts and or software systems.
As we saw earlier.
If a database is hack and your username and password combination is there, the hackers will try those
combinations on multiple platforms to see if they get a match.
Sixth, avoid character, repetition, keyboard patterns, dictionary words, letters or numbers sequences.
Avoid using information that the user's colleagues and or acquaintances might know to be associated
with the user, such as relatives but names, romantic links and biographical information.
And now that you have all this information, let's have a fun workshop, go to the link in the slide
and play with passwords to see how fast you can brute force them.
However, we don't recommend you using your real passwords.
Try to keep it safe.
And with this, we conclude our brute force lesson, we hope that we provided some interesting information
and please find the links discussed here in the brute force text file from the resource section.
Thank you.
And see you soon in our next chapter.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.