Ethical Hacker Community Forums

Ethical Hacking Discussions and Related Certifications => CEH - Official Course Modules v5 => Topic started by: don on November 15, 2006, 01:43:34 PM



Title: CEH v5 Module 13: Web-based Password Cracking Techniques
Post by: don on November 15, 2006, 01:43:34 PM
 Definition of Authentication
 Authentication Mechanisms
    o HTTP Authentication
        • Basic Authentication
        • Digest Authentication
    o Integrated Windows (NTLM) Authentication
    o Negotiate Authentication
    o Certificate-based Authentication
    o Forms-based Authentication
    o RSA Secure Token
    o Biometrics
        • Face recognition
        • Iris scanning
        • Retina scanning
        • Fingerprinting
        • Hand geometry
        • Voice recognition
 How to Select a Good Password?
 Things to Avoid in Passwords
 Changing Your Password
 Protecting Your Password
 How Hackers get hold of Passwords?
 Windows XP: Remove Saved Passwords
 Microsoft Password Checker
 What is a Password Cracker?
 Modus Operandi of an Attacker Using Password Cracker
 How does a Password Cracker Work?
 Classification of Attacks
 Password Guessing
 Query String
 Cookies
 Dictionary Maker
 Available Password Crackers
    o LOphtcrack
    o John The Ripper
    o Brutus
 Hacking Tools
    o Obiwan
    o Authforce
    o Hydra
    o Cain And Abel
    o RAR
    o Gammaprog
    o WebCracker
    o Munga Bunga
    o PassList
    o SnadBoy
    o WinSSLMiM
    o ReadCookies.html
    o Wireless WEP Key Password Spy
    o RockXP
    o WinSSLMiM
    o Password Spectator
 Countermeasures

Source:
http://www.eccouncil.org/EC-Council%20Education/ceh-course-outline.htm

Don


Title: Re: CEH v5 Module 13: Web-based Password Cracking Techniques
Post by: ChrisG on November 15, 2006, 03:22:06 PM
i dont see it on there, but medusa is a pretty good tool and will do SSH attacks as well