Four attacks

  • Brute force: try every possible password, or a list of common ones, until one works.
  • Denial of service (DoS): flood a server with requests so real users cannot get through. A distributed DoS uses many computers at once, often a botnet.
  • SQL injection: type SQL into an input box on a site that puts input straight into its database queries, so the extra code runs.
  • Data interception: capture data as it travels, for example with a packet sniffer on open Wi-Fi.
SELECT * FROM Users WHERE username = 'x' OR '1'='1'

The text x' OR '1'='1 closes the quote early; '1'='1' is always true, so every record comes back.

Counting possible passwords

If each of n positions can be any of c characters, there are c^n possible passwords.

  1. A 4-digit PIN: 10^4 = 10 000 possibilities.
  2. 6 lower-case letters: 26^6 = 308 915 776.
  3. Time for a brute force attack = possibilities ÷ guesses per second.

Each extra character multiplies the work by c, which is why length matters so much. Locking an account after a few wrong tries makes brute force almost useless.

How many PINs?

Multiply the choices for each position.