CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard
A security researcher demonstrates that two different input files can be crafted to produce the identical output when processed by a hashing algorithm with a small digest size, allowing an attacker to substitute a malicious file for a legitimate one without detection. This scenario best illustrates which type of vulnerability?
- AA birthday attack (hash collision)
- BA replay attack
- CA downgrade attack
- DA cryptographic side-channel attack
Show answer & explanationAnswer & explanation
Correct answer: A. A birthday attack (hash collision)
A birthday attack exploits the probability that two different inputs produce the same hash output (a collision), which becomes more likely with smaller digest sizes; this can be leveraged to substitute malicious content while preserving the same hash value.
Why the other options are wrong
- B. A replay attack reuses captured legitimate data/transactions, not crafted colliding files.
- C. A downgrade attack forces use of a weaker protocol version, not hash collisions.
- D. A side-channel attack exploits physical implementation leakage (timing, power), not mathematical collisions.
Birthday Attack / Hash Collision
A cryptographic attack that exploits the mathematical probability of two different inputs producing the same hash output, undermining hash integrity guarantees.
- Named after the birthday paradox in probability
- Risk increases with smaller hash digest sizes (e.g., MD5, SHA-1)
- Mitigated by using strong, collision-resistant algorithms like SHA-256
Memory trick: Just like shared birthdays in a room, hash collisions happen sooner than expected.