Re: Detecting Brute-Force and Dictionary attacks



Hi,

I didn't read the whole discussion about this issue but I came up with
an idea which might be usefull to detect brute force attempt. By
storing the passwords a certain user has used in the past along with
the current password you could be able to compare to password (by
pattern matching) used at the login attempts with the passwords list.
If the password used differs significantly (this excludes typos) from
the entries in the password list, there could be a possible brute
force attempt. The reason for storing the previous passwords is that
people tend to use every password they've used in the past when they
forgot their password. Maybe this idea can be used along with the
other methods of detecting brute force attempts. Anyway, it's just a
random thought.

Greets,

Sebastiaan



Relevant Pages

  • Re: SYS$LIBRARY:TRACE_V74.EXE on VMS 7.3-1 causing error
    ... >been from some ECO we applied, but we have applied many ECOs and I don't who ... but I need a reason to make them do so. ... I do not believe it is defined by any VMS patch, nor by any "normal" VMS system ... by brute force, SEARCHing every file which is invoked as part of system startup ...
    (comp.os.vms)
  • Re: OT Clinton
    ... Whether or not I can reason with him is debatable... ... Brute force never did convert gun grabbers that "just don't get it". ... come to realize that it bears a very close resemblance to the first." ...
    (misc.fitness.weights)
  • Re: using sumif function with mutliple criteria
    ... Just curious, but is there some reason you are avoiding AND, i.e. ... >kind of brute force but simple way is to create col for each of the 70 ... >the codes we want for a particular cell the if statement would be- ...
    (microsoft.public.excel.worksheet.functions)
  • Re: Performance tests of some AES implementations in C
    ... > Now the reason for this post (since I can't make my code ... > public) is that the way I get the best speed is by brute force. ... > plugging in the best Athlon/gcc options. ... > options depending on the platform. ...
    (sci.crypt)
  • Re: OT Clinton
    ... jcderkoeing wrote: ... Whether or not I can reason with him is debatable... ... Brute force never did convert gun grabbers that "just don't get it". ...
    (misc.fitness.weights)