Watch your door.-Authentication mechanism is attacked (1)-Password is not strong

Source: Internet
Author: User
Tags strong password

The first thing to declare is that this article is purely an ignorant view of a little developer without foresight and knowledge, and is intended only for reference in Web system security.

1. Brief description

In siege, the gate is always the easiest place to be breached.
If a web system is not secure enough, there are often problems from landing on it.
Many Web applications have no or little control over the strength of the user's password, so it's easy to find a loophole here;

2, common confidentiality is not strong password

Very short or even blank password;
The password and user name are exactly the same;
The initial default password;
Use common vocabulary Pinyin, English, etc. as the password;
Like what:
123
123456
Site name
Qwert (look at the keyboard carefully)
11111
Admin
Qaz123
...

3. The process of being attacked

1, first to identify and password strength-related rules;
2, if it is a public Web site, find the description of password and user name-related content;
3, if you can do self-registration, with a fragile password to register different accounts, see what the application actually adopted the rules;
4, if you have a password, change the password for a variety of confidential password not strong try.
5, for the general application, the protection of most people is enough, if someone own ways to change the strong password into a weak password, it is his own things. The so-called "no Zuo,no die"

Watch your door.-Authentication mechanism is attacked (1)-Password is not strong

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.