...
首页> 外文期刊>Journal of Intelligent Manufacturing >Fast password recovery attack: application to APOP
【24h】

Fast password recovery attack: application to APOP

机译:快速密码恢复攻击:应用到APOP

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper, we improve the password recovery attack to Authentication Post Office Protocol (APOP) from two aspects. First, we propose new tunnels to control more fixed bits of MD5 collision, hence, we can recover passwords with more characters, for example, as long as 43 characters can be recovered practically. Second, we propose a group satisfaction scheme, apply divide-and-conquer strategy and a new suitable MD5 collision attack, to greatly reduce the computational complexity in collision searching with high number of chosen bits. We propose a fast password recovery attack to application APOP in local that can recover a password with 11 characters in >1 min, recover a password with 31 characters extremely fast, about 6 min, and for 43 characters in practical time. These attacks truly simulate the practical password recovery attacks launched by malware in real life, and further confirm that the security of APOP is totally broken.
机译:本文从两个方面改进了对身份验证邮局协议(APOP)的密码恢复攻击。首先,我们提出了新的隧道来控制更多的MD5冲突固定位,因此,例如,只要可以实际恢复43个字符,就可以恢复具有更多字符的密码。其次,我们提出了一种群满意方案,应用分而治之策略和一种新的合适的MD5冲突攻击,以大大降低大量选择位的冲突搜索中的计算复杂性。我们对本地应用程序APOP提出了一种快速的密码恢复攻击,可以在> 1分钟内恢复11个字符的密码,极快地(大约6分钟)恢复31个字符的密码,并且在实际时间内可以恢复43个字符。这些攻击真正模拟了由恶意软件在现实生活中发起的实用密码恢复攻击,并进一步证实APOP的安全性已被完全破坏。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号