免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 779 | 回复: 0
打印 上一主题 下一主题

Microsoft Certifications For You [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2009-03-12 17:39 |只看该作者 |倒序浏览

When you look at the enable secret in a Cisco router configuration, it looks like it would be impossible to guess. After setting the enable secret on this router to the word security, here’s how it appears in the
cisco exam
:
enable secret 5 $1$24me$gVFxUOI4gYp0IQbhtH8Rz0
That password has been encrypted by MD5, the Message Digest 5 algorithm. The result of the MD5 algorithm being applied to the password is a 32-character hexadecimal value.
That password is hard to guess, but not terribly hard to crack. Anyone looking over your shoulder would not be able to come up with that password, but there are readily-available password cracking software devices that can crack that encryption in a matter of minutes. That’s true of any MD5-encrypted password, not just those on
cisco study guide
.
So what can we do about this? We can add SALT to our MD5.
The salt itself is simply a string of random characters that are added to the encryption process. Salting makes it much more difficult for a hacker to come up with the password; each bit added by the salt process literally makes it twice as difficult for the password to be compromised. A recent Wikipedia entry states that if a password was one of 200,000 words, a 32-bit salt would require 800 trillion hashes for a full-blown brute force attack.
The actual creation and application of a salt is beyond the scope of the CCNA Security exam, but once you’ve earned that valuable certification - or maybe while you’re preparing for it - do a Google search on “salt md5″ and read up on this powerful security tool. In the meantime, look for more CCNA Security tutorials on the site you’re on now as well as
cisco book
!
Chris Bryant, CCIE #12933, is the owner of The
compatible printer cartridge
Exam tutorials.


本文来自ChinaUnix博客,如果查看原文请点:http://blog.chinaunix.net/u3/91511/showart_1860594.html
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP