Password Attacks 101: Exploiting Human Weaknesses

Presented at CackalackyCon 2 (2023), May 5, 2023, 7 p.m. (60 minutes)

It may come as no surprise, but humans are bad at passwords. Passwords are complicated, hard to remember, and always seem to get compromised.

In this talk, I'll cover a brief history of passwords, the different types of password cracking and attacks, the psychology behind password attacks, and why understanding these attacks and weaknesses are so important. Special attention will be given to demos related to effective hash cracking techniques and introduction to toolsets for making the process as efficient and effective as possible.

From breaking into companies due to the Ashley Madison data dump (yup, there's a story there), to a decade+ old password list, password cracking will always be a threat for any system that still uses passwords.

For offensive security pros, you will hopefully walk away with a newfound vigor for password attacks (or a few new techniques). Defenders will learn how hackers go about attacking passwords, and measures that they can take to stop or slow these attacks. And, for everyone else, come find out what makes a strong password, or how attackers can break into so many accounts!


Presenters:

Links:

Similar Presentations: