+ All Categories
Home > Documents > Playin with Password

Playin with Password

Date post: 18-May-2015
Category:
Upload: ammar-wk
View: 1,064 times
Download: 3 times
Share this document with a friend
Popular Tags:
36
Ahmad Muammar W. K. http://google.com/search?q=y3dips
Transcript
Page 1: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 2: Playin with Password

http://google.com/search?q=y3dips

DetailsPassword

Deal with Cracking

Passive ActionSimulationDiscussion

Page 3: Playin with Password

http://google.com/search?q=y3dips

PasswordWhy ?“Kata Kunci”

diansastro090382mickey

Page 4: Playin with Password

http://google.com/search?q=y3dips

PasswordPanjang Minimum 6 KarakterTidak Ber-Makna (bukan nama pacar, bukan tanggal lahir)Kombinasi Huruf, Angka dan karakter lainUsernameX PasswordPerlu Pengamanan extra

Page 5: Playin with Password

http://google.com/search?q=y3dips

PasswordPassPhrase ?

D1an545TR04m1nkExtravaganz4KaptenTSUBASA

Page 6: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 7: Playin with Password

http://google.com/search?q=y3dips

Simulation !Cracking windows Password

via linuxvia windows

Cracking Linux PasswordRemote Cracking

Page 8: Playin with Password

http://google.com/search?q=y3dips

Cracking windows PasswordTools

Bkhive + sampdump2 (getting hash)Pwdump2 (getting hash)

John the ripper for cracking the hashDatabase password : SAM file , system

Page 9: Playin with Password
Page 10: Playin with Password
Page 11: Playin with Password
Page 12: Playin with Password

http://google.com/search?q=y3dips

Cracking Linux PasswordTools

Unshadow

John the ripper for cracking the hashDatabase password : passwd, shadow

Page 13: Playin with Password
Page 14: Playin with Password

http://google.com/search?q=y3dips

Remote CrackingBruteforcing via networkSlow speedBrutus, hydra, ssh crack, tftpd-bruteforce

Page 15: Playin with Password
Page 16: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 17: Playin with Password

http://google.com/search?q=y3dips

Passive Action?Browser Ability?KeyloggerApplication/Engine HoleInsecure protocol/line

Page 18: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 19: Playin with Password

http://google.com/search?q=y3dips

Browser AbilityWand/Remember PasswordHistoryCache abilityetc

Page 20: Playin with Password
Page 21: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 22: Playin with Password

http://google.com/search?q=y3dips

KeyloggerMalicious ProgramKey stroke Passive tools

Page 23: Playin with Password
Page 24: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 25: Playin with Password

http://google.com/search?q=y3dips

Bugs in ApplicationApplication/Engine Vulnerability Information disclosuree.g: phpnuke, postnuke, mambo

Page 26: Playin with Password
Page 27: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 28: Playin with Password

http://google.com/search?q=y3dips

Insecure LinePlaintext protocol ( http, tcp, smtp )Plaintext DataSniff it & collect it ( ethereal, ettercap, dsniff, etc)

Page 29: Playin with Password

http:// clear text

Page 30: Playin with Password
Page 31: Playin with Password
Page 32: Playin with Password
Page 33: Playin with Password
Page 34: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 35: Playin with Password

http://google.com/search?q=y3dips

SurviveUsing a better pass phraseUsing secure line/protocolEncryption

Securing tools (firewall, antivirus)Update infoE.t.c

Page 36: Playin with Password

Ahmad Muammar W. K.http://google.com/search?q=y3dips


Recommended