Home Inn Wi-Fi password defects and brute-force cracking
The Home Inn has a Wi-Fi network, and the room number is used as the user name and the name of the check-in personnel is the password. And use WEB for verification. Due to two design defects, you can absolutely successfully verify the logon over wi-fi.
I. Password design defects. The password is the first letter of the name of the person to be checked in. This design allows all possible passwords to be lifted only by combining more than 10 thousand characters earlier.
2. The web login page does not set error count verification or graphic verification code, resulting in brute-force cracking. The above two defects lead to the absolute success of obtaining Wi-Fi network authorization.
People within the valid wifi range of Home Inn hotel can hide their identities, use Home Inn wifi, and use the network to hide their identities.
Solution:
Set the password complexity, the maximum number of password errors, or the graphic verification code of the web logon form.