<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Password Attacks by Ramesha Geethan</title>
      <link>https://padlet.com/rameshageethan/Bookmarks</link>
      <description>Made with a quick smile</description>
      <language>en-us</language>
      <pubDate>2022-05-26 15:51:45 UTC</pubDate>
      <lastBuildDate>2025-11-09 19:07:56 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Shoulder Surfing</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201053304</link>
         <description><![CDATA[<div>Shoulder surfing is a social engineering method that involves peeking over someone's shoulder to observe what they are doing. As a shoulder surfer (with malicious purpose), it's pretty easy to stand next to someone as they fill out a form, use an ATM, or pay with a credit card in a crowded environment.<br><br></div><div>What Can Be Used For Long-Distance Shoulder Surfing?<br><br></div><div>Shoulder surfing may also be done from a distance using binoculars or other vision-enhancing gear.<br><br></div><div><strong>Example for Shoulder Surfing<br></strong><br></div><div>·&nbsp; &nbsp; &nbsp; &nbsp;When a coworker sits next to an employee while they converse on the phone about confidential business, a coworker can listen to the employee's call and take notes.&nbsp;</div><div>·&nbsp; &nbsp; &nbsp; &nbsp;Furthermore, if a person uses a public Wi-Fi network without utilizing a VPN, hackers can intercept important information.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Install a privacy filter</div><div>o &nbsp; Maintain the awareness of your surrounding</div><div>o &nbsp; Use a password manager</div><div>o &nbsp; Protect pins</div><div>o &nbsp; Avoid using public networks<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 15:54:27 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201053304</guid>
      </item>
      <item>
         <title>Dumpster Diving</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201055964</link>
         <description><![CDATA[<div>Dumpster diving is something that looks like taking treasure from someone's trash. In the IT world, dumpster diving is a technique used to retrieve information that could be used to carry out an attack or gain unauthorized access to a computer network from disposed of items.<br><br></div><div>A dumpster does not have limitations. It goes through access code passwords written down in sticky notes, and sensitive information such as phone call list, meeting minutes or calendar events and can be used by attackers using social media techniques to gain access to the network.<br><br></div><div>Disposed computer storage devices are can be a gem mine for attackers because information can be recovered from them, including those that have been improperly formatted or erased.&nbsp; This will include trusted certificates and sensitive passwords. The equipment related to the TPM (Trust Platform Module) data or other hardware IDs that are trusted by an organization is included.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o, Ensure all identical information and data are removed from computer equipment before being disposed of or resold.</div><div>o &nbsp; Use a matching secure storage media deletion method</div><div>o &nbsp; Maintain a data retention policy and keep sensitive data clean.</div><div>o &nbsp; Educate the employee about the risk while disposed organizational equipment</div><div>o &nbsp; Using locked trash and trusted recycle bins<br><br></div>]]></description>
         <enclosure url="https://v1.padlet.pics/1/image.webp?t=c_limit%2Cdpr_2%2Ch_300%2Cw_508&amp;url=https%3A%2F%2Fpadlet-uploads.storage.googleapis.com%2F1715115717%2Fa63174283efdbf157beec5065c7b71eb%2Fimage.png" />
         <pubDate>2022-05-26 15:56:40 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201055964</guid>
      </item>
      <item>
         <title>Dictionary Attack</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201059919</link>
         <description><![CDATA[<div><strong><br></strong><br></div><div>A dictionary attack is a method of breaking a network or a password protected computer by using words in a dictionary as a password. It can be used when asymmetric cryptography (encrypt/ decrypt) is done. This risk was created because personal users and businesses use ordinary words as passwords. These attacks usually fail due to the password policy being much updated.<br><br></div><div><strong>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</strong></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Allow only three password attempts</div><div>o &nbsp; Require a period of 5 – 15 minutes to re-attempt</div><div>o &nbsp; Use meaningless letters, numbers and symbols</div><div>o &nbsp; Use multi-factor authentication in user account<br><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1715115717/874d1a1e8688b3b3b2ef85e7dc0f3cb9/security_password_hygiene_shortcomings_f.png" />
         <pubDate>2022-05-26 15:59:46 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201059919</guid>
      </item>
      <item>
         <title>Dictionary Attack</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201062646</link>
         <description><![CDATA[<div>A dictionary attack is a method of breaking a network or a password protected computer by using words in a dictionary as a password. It can be used when asymmetric cryptography (encrypt/ decrypt) is done. This risk was created because personal users and businesses use ordinary words as passwords. These attacks usually fail due to the password policy being much updated.<br><strong>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</strong><br><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Allow only three password attempts</div><div>o &nbsp; Require a period of 5 – 15 minutes to re-attempt</div><div>o &nbsp; Use meaningless letters, numbers and symbols</div><div>o &nbsp; Use multi-factor authentication in user account<br><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1715115717/6d7ba2a99acb4fe6d17aef91237e68cf/123.png" />
         <pubDate>2022-05-26 16:02:00 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201062646</guid>
      </item>
      <item>
         <title>Brute Forcing Attack</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201079327</link>
         <description><![CDATA[<div>A brute force attack is a type of trial-and-error tuning technique. It has been guessed every possibility to encryption keys from rainbow pages or find hidden web pages. In the brute force, the attack uses excessive forceful attempts and tries to force it is way into the private accounts. This is a very old attack method but it is very popular with hackers because it is very complicated and takes passwords from one second to many years very quickly.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Use encrypting and hashing algorithms</div><div>o &nbsp; Enable two-factor authentication</div><div>o &nbsp; Limiting failing login attempts</div><div>o &nbsp; Implementing CAPTCHAS</div><div>o &nbsp; Increase password complexity</div><div>o &nbsp; Implement proactive threat hunting methods</div><div>o &nbsp; Implement IT hygiene setup and updated security policies<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:15:53 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201079327</guid>
      </item>
      <item>
         <title>Rule-Based Attack</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201080137</link>
         <description><![CDATA[<div>The rule-based attack is one of the more difficult attack styles. The rule-based approach is similar to a computer language developed to generate password candidates. It has so many functions to extend, cut and modify words and has conditional operators to skip some, etc. That makes it the most accurate, flexible and efficient attack.<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:16:32 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201080137</guid>
      </item>
      <item>
         <title>Wire Sniffing</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201082398</link>
         <description><![CDATA[<div>The system and network administrators monitor and troubleshoot network traffic using sniffers. Attackers use sniffers to capture data packets containing sensitive information such as user accounts etc. Sniffers can be software or hardware installed in a system. There are two types of sniffing. There are,<br><br>o Active Sniffing &nbsp; - A switch is a p2p device<br>o Passive Sniffing&nbsp; - Attackers use MAC address to read<br><br>How to Mitigate<br><br>o Avoid unsecured networks<br>o Encrypt messages with a VPN<br>o Network Scanning and Monitoring<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:18:32 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201082398</guid>
      </item>
      <item>
         <title>MITM</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201084247</link>
         <description><![CDATA[<div>Man in The Middle is the most common interception attack. When two computers communicate with each other, but actually with another computer in the middle of communication.&nbsp;<br><br></div><div>An attack's purpose is to steal personal information such as user names, passwords, other account information, and credit card numbers. Users of banking apps, SaaS enterprises, e-commerce websites, etc...<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Avoid open network Wi-Fi connection</div><div>o &nbsp; Immediately log out from an application when it is not in use</div><div>o &nbsp; Not using public networks</div><div>o &nbsp; Paying attention to browser notification&nbsp;</div><div>o &nbsp; Use multifactor authentication</div><div>o &nbsp; Use end-to-end encryption algorithms for applications</div><div>o &nbsp; Using virtual private network</div><div>o &nbsp; Secure browsing plugins<br><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1715115717/ebe02e2202a20b27300cca1bf053514c/02_Phases_of_man_in_middle_attack.png" />
         <pubDate>2022-05-26 16:20:02 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201084247</guid>
      </item>
      <item>
         <title>Replay Attacks</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201086663</link>
         <description><![CDATA[<div>A replay attack is a type of network attack in which an attacker discovers and fraudulently delays or repeats a data transmission.&nbsp;<br><br></div><div>In other words, a replay attack is an assault on the security protocol that uses replays of data transmission from a different sender onto the intended receiving system, misleading the participants into believing the data communication was successful.<br><br></div><div><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Use advanced digital cryptography</div><div>o &nbsp; Using one-time password<br>o &nbsp; Use third party authentication</div><div>&nbsp;</div><div><strong><br></strong><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1715115717/93e17d44706905f71acc190f67b572f5/replay_attacks_article_450x277.png" />
         <pubDate>2022-05-26 16:22:04 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201086663</guid>
      </item>
      <item>
         <title>Rainbow Table Attack</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201088933</link>
         <description><![CDATA[<div>A rainbow table attack is a method of hacking in which the perpetrator attempts to crack passwords stored in a database system using a rainbow hash table. A rainbow table is a hash algorithm used in cryptography to store essential data in a database, such as passwords.<br><br></div><div><strong>&nbsp;How to Mitigate<br></strong><br></div><div>o &nbsp; Use strong password related to password policy (numbers, letters – <sup>uppercase</sup> and <sub>lower case</sub>, symbols)</div><div>o &nbsp; Enable two-factor authentication<br><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1715115717/9f3bfac8633e7b64c73df1ad1e5c922a/flow_of_password_attacking.png" />
         <pubDate>2022-05-26 16:23:44 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201088933</guid>
      </item>
      <item>
         <title>Distributed Network Attack</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201090000</link>
         <description><![CDATA[<div>Distributed Network Attack is a new method to recover password-protected files. When we are looking after before so many years there is limited the processing power of the user matching. DNA uses the power across the network to decrypt passwords. DNA server installed in a central location of the network. Then DNA server client can access the network.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Get to know about network traffic of the using network</div><div>o &nbsp; Create a DOS response plan</div><div>o &nbsp; Scale up your bandwidth</div><div>o &nbsp; Move to the cloud<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:24:33 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201090000</guid>
      </item>
      <item>
         <title>Credential Stuffing </title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201092375</link>
         <description><![CDATA[<div>The automatic insertion of stolen username and password pairs ("credentials") into website login forms in order to illegally obtain access to user accounts is known as credential stuffing. Because many users reuse the same password and username/email, entering those stolen credentials to dozens or hundreds of other sites can allow an attacker to breach those accounts as well.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Use a unique password for each service</div><div>o &nbsp; Use a web application Firewall</div><div>o &nbsp; Limit authentication requests and send notification</div><div>o &nbsp; Use multi-factor authentication<br><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1715115717/9c75e5f0caafe0981e9167879be6504a/credential_stuffing.png" />
         <pubDate>2022-05-26 16:26:35 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201092375</guid>
      </item>
      <item>
         <title>Key Loggers </title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201094065</link>
         <description><![CDATA[<div>A key logger is a tool that can record and report on a user of a computer. Key loggers keep track of you by recording what you type as you type it and malicious hackers often install key loggers for nefarious purposes.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Use Firewall</div><div>o &nbsp; Install a password manager</div><div>o &nbsp; Update the system</div><div>o &nbsp; Consider other additional security tools</div><div>o &nbsp; Change your password<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:27:29 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201094065</guid>
      </item>
      <item>
         <title>Phishing </title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201094810</link>
         <description><![CDATA[<div>Phishing is the practice of delivering fake messages that appear to come from a trusted source. It is often done by email. The aim is to steal sensitive information such as credit card and account information or to install malware on the victim's PC. Phishing is a popular form of cyber threat that everyone should be aware of in order to be protected.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Do not click on unknown links</div><div>o &nbsp; Do not give information to unsecured websites</div><div>o &nbsp; Rotate password regularly</div><div>o &nbsp; Do not ignore security patch updates</div><div>o &nbsp; Install firewalls</div><div>o &nbsp; Do not be tempted by pop-up messages<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:28:01 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201094810</guid>
      </item>
      <item>
         <title>Interception attacks</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201095904</link>
         <description><![CDATA[<div>An interception occurs when an unauthorized person has access to secret or private information. Interception attacks are assaults on the network that aim to compromise the CIA Triad's secrecy.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Use authorization and authentication mechanisms</div><div>o &nbsp; Use Firewalls</div><div>o &nbsp; Use Digital Signatures<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:28:54 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201095904</guid>
      </item>
      <item>
         <title>Password spraying</title>
         <author>rameshageethan</author>
         <link>https://padlet.com/rameshageethan/Bookmarks/wish/2201096870</link>
         <description><![CDATA[<div>Password spraying is an attack that uses a few regularly used passwords to gain access to a large number of accounts. Traditional brute-force attacks try to guess a password in order to obtain unauthorized access to a single account. This can provided useful in the targeted account being locked out, as most account-lockout rules only allow for a certain number of failed attempts within a given time period. Password spray campaigns typically target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols. Targeting federated authentication can help mask malicious traffic.<br><br></div><div><strong>How to Mitigate<br></strong><br></div><div>o &nbsp; Enable multi-factor Authentication</div><div>o &nbsp; Enforce the&nbsp; use of strong passwords</div><div>o &nbsp; Review passport management programs</div><div>o &nbsp; Create security awareness in workplace<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-26 16:29:45 UTC</pubDate>
         <guid>https://padlet.com/rameshageethan/Bookmarks/wish/2201096870</guid>
      </item>
   </channel>
</rss>
