WebCrack: Dynamic Dictionary Adjustment for Web Weak Password Detection based on Blasting Response Event Discrimination

10/26/2022
by   Xiang Long, et al.
0

The feature diversity of different web systems in page elements, submission contents and return information makes it difficult to detect weak password automatically. To solve this problem, multi-factor correlation detection method as integrated in the DBKER algorithm is proposed to achieve automatic detection of web weak passwords and universal passwords. It generates password dictionaries based on PCFG algorithm, proposes to judge blasting result via 4 steps with traditional static keyword features and dynamic page feature information. Then the blasting failure events are discriminated and the usernames are blasted based on response time. Thereafter the weak password dictionary is dynamically adjusted according to the hints provided by the response failure page. Based on the algorithm, this paper implements a detection system named WebCrack. Experimental results of two blasting tests on DedeCMS and Discuz! systems as well as a random backend test show that the proposed method can detect weak passwords and universal passwords of various web systems with an average accuracy rate of about 93.75 advisories for users' password settings with strong practicability.

READ FULL TEXT

page 20

page 21

research
03/06/2022

Adaptive technique for web page change detection using multi-threaded crawlers

World Wide Web is getting dense as many new web pages and resources are ...
research
03/21/2022

Web Page Content Extraction Based on Multi-feature Fusion

With the rapid development of Internet technology, people have more and ...
research
02/22/2018

Investigating the Evolvability of Web Page Load Time

Client-side Javascript execution environments (browsers) allow anonymous...
research
08/07/2019

Making Recommendations from Web Archives for "Lost" Web Pages

When a user requests a web page from a web archive, the user will typica...
research
11/08/2021

Learning Context-Aware Representations of Subtrees

This thesis tackles the problem of learning efficient representations of...
research
08/28/2019

HTMLPhish: Enabling Accurate Phishing Web Page Detection by Applying Deep Learning Techniques on HTML Analysis

Recently, the development and implementation of phishing attacks require...
research
11/14/2006

Cartes auto-organisées pour l'analyse exploratoire de données et la visualisation

This paper shows how to use the Kohonen algorithm to represent multidime...

Please sign up or login with your details

Forgot password? Click here to reset