2月
5
第6回 パスワードの定期変更という”不自然なルール”
Warning: preg_match(): Compilation failed: invalid range in character class at offset 4 in /home/users/0/fool.jp-pentest/web/n/wordpress/wp-content/plugins/lightbox-plus/classes/shd.class.php on line 1384
Warning: preg_match_all(): Compilation failed: invalid range in character class at offset 4 in /home/users/0/fool.jp-pentest/web/n/wordpress/wp-content/plugins/lightbox-plus/classes/shd.class.php on line 700
Warning: foreach() argument must be of type array|object, null given in /home/users/0/fool.jp-pentest/web/n/wordpress/wp-content/plugins/lightbox-plus/classes/shd.class.php on line 707
Warning: preg_match_all(): Compilation failed: invalid range in character class at offset 4 in /home/users/0/fool.jp-pentest/web/n/wordpress/wp-content/plugins/lightbox-plus/classes/shd.class.php on line 700
Warning: foreach() argument must be of type array|object, null given in /home/users/0/fool.jp-pentest/web/n/wordpress/wp-content/plugins/lightbox-plus/classes/shd.class.php on line 707
今回は、とあるところのとある記事を発端にTwitterでも盛り上がった(?)
パスワードの定期変更について取り上げさせていただきました。
パスワードの定期変更へのボクの見解だけではなく
オンラインパスワードクラッカー(hydara、medusa、ncrack)の話から、
定期変更よりも気をつけないといけないことってあるのでは?
といったお話も書かせていただいております。
それについては、記事の最後でペネトレーションテストの現場では
どのような手法により再現しているかというところにも触れています。
少々長めの記事となっていますが、お読みいただけき
パスワードについて再考する機会となれば幸いです。
