EC-Council Certified Ethical Hacker (CEH) v12CryptographyMedium

A penetration tester is attempting to circumvent a web application's authentication mechanism. They discover that the application uses a custom hashing algorithm for passwords without any salting or key stretching. The tester has obtained a database dump of these hashes. Which attack method would be most effective for quickly cracking a significant number of these passwords?

  1. ABrute-force attack with GPU acceleration
  2. BChosen-plaintext attack
  3. CDictionary attack with precomputed hashes
  4. DSide-channel attack
Show answer & explanation

Correct answer: C. Dictionary attack with precomputed hashes

Without salting, identical passwords will produce identical hash values. A custom hashing algorithm, while unknown, is likely susceptible to precomputation. A dictionary attack with precomputed hashes (often called a 'rainbow table' attack in this context, though the option specifies 'dictionary with precomputed hashes') would be highly effective because the attacker can pre-calculate hashes for common dictionary words and compare them directly to the leaked hashes, exploiting the lack of salt.

Why the other options are wrong

  • A. Brute-force is generally slower than precomputed dictionary attacks for common passwords, especially when dealing with a large set of hashes.
  • B. Chosen-plaintext attacks apply to encryption algorithms, not typically to one-way hashing functions for password cracking.
  • D. Side-channel attacks exploit physical implementations (e.g., timing, power consumption) and are not applicable to cracking hashes from a database dump.

Rainbow Table Attack

A rainbow table attack is a precomputed table for reversing cryptographic hash functions, usually for cracking password hashes. It's effective against unsalted hashes as it allows an attacker to quickly find the original password for a given hash.

  • Precomputed lookup table.
  • Effective against unsalted hashes.
  • Vulnerable to common passwords.
  • Mitigated by salting and key stretching.

Memory trick: Dictionary checks words, Brute-force tries all, Rainbow tables look up.

More Cryptography questions