Palisade Magazine

 
Rainbow Cracking and Password Security

February 2006

Rainbow Cracking and Password Security

by Sam Varughese, CISSP, SCSA

Passwords are often stored hashed on the premise that significant time is required to brute force a hashed password. The value of password hashes, however, has been undermined by the Rainbow Cracking attack. Rainbow tables readily available today reduce the time required for cracking hashed passwords to minutes. This article presents this recent attack on password hashes.… more →

Assert Safely: How to use .Net's Assert wisely

by Sangita Pakala, GCIH

.NET’s Code Access Security is a powerful mechanism to ensure that your code is protected from malicious assemblies. In this article, we show you how to use a powerful feature of .NET securely: the assert security action.… more →

QuizQuiz: Quiz: Handling Secrets in .Net

Which of these is not a good strategy for handling secrets in .Net?

  1. Use SecureZeroMemory to clear secrets in the memory
  2. Use aspnet_setreg to encrypt passwords in the registry
  3. Use .Net’s isolated storage to store secrets safely

more →

Review: Software Security : Building Security In

by Gary McGraw

We discuss Gary McGraw’s excellent book on the philosophy of software security and how it is present in all stages of the software development lifecycle. A must read for software managers.… more →

Search this website

 Search website

Stay Informed

Want to know when the new issues are out? Just fill in your details, we will take care of notifying you when new issues are released:




Subscribe  Unsubscribe

Write to Us

All flowers, brickbats and suggestions are welcome. You can put in yours on the feedback page.

News & Events

  • 20.02.07. Paladion conducts Operational Risk Management Conference in Dubai, Bahrain
  • 27.11.06. Paladion enables ORC achieve ISO 27001:2005
  • 10.11.06. Deloitte’s Asia Pacific Technology Fast 500 calls Paladion/Plynt one of the fastest growing technology companies.
  • 10.11.06. Paladion/Plynt ranked among the fastest growing 50 technology companies in India by Deloitte.
  • 01.08.06. Rajat speaks on the current state of security in Financial firms outsourcing to India