Four attacks
- Brute force: try every possible password, or a list of common ones, until one works.
- Denial of service (DoS): flood a server with requests so real users cannot get through. A distributed DoS uses many computers at once, often a botnet.
- SQL injection: type SQL into an input box on a site that puts input straight into its database queries, so the extra code runs.
- Data interception: capture data as it travels, for example with a packet sniffer on open Wi-Fi.
SELECT * FROM Users WHERE username = 'x' OR '1'='1'
The text x' OR '1'='1 closes the quote early; '1'='1' is always true, so every record comes back.
Counting possible passwords
If each of n positions can be any of c characters, there are c^n possible passwords.
- A 4-digit PIN: 10^4 = 10 000 possibilities.
- 6 lower-case letters: 26^6 = 308 915 776.
- Time for a brute force attack = possibilities ÷ guesses per second.
Each extra character multiplies the work by c, which is why length matters so much. Locking an account after a few wrong tries makes brute force almost useless.
How many PINs?
Multiply the choices for each position.