Home > Ask the Information Security Experts > Questions & Answers > How to prevent brute force webmail attacks
Ask The Information Security Expert: Questions & Answers
EMAIL THIS

How to prevent brute force webmail attacks

Sherri Davidoff, featured expert EXPERT RESPONSE FROM: Sherri Davidoff, featured expert

Pose a Question
Other Information Security Categories
Meet all Information Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 23 April 2009
Why is the brute-force of webmail accounts a popular hacking technique? How is it done, and what can be done to prevent it on an enterprise level?

>
Great question. Brute forcing Web-based email accounts is popular because it's so easy. There are a number of publicly available brute-force password-guessing tools, which require minimal skill to use, including ones like "Brutus." You give Brutus a list of words (a "dictionary") to use as usernames or passwords, and it will try every possible combination until one works. Some tools will also try permutations on each password (i.e. "fluffy8", "fluffy9", etc.). The program is simple enough that a teenager could use it to point, click and break, or brute force, into webmail accounts.

The good news is that there are effective ways to foil enterprise Web-based email attacks. Probably the most straightforward strategy is to use two-factor authentication. It is often said that there are three forms of authentication:

  1. Something you have (i.e. a debit card)
  2. Something you know (i.e. a password)
  3. Something you are (i.e. your fingerprint)

Password-protected Web email is an example of single-factor authentication (something you know). Since passwords are often remotely guessed or stolen, this is a fairly low-security method for restricting access.

For Web-based email, I recommend using at least two-factor authentication, such as RSA Security Inc.'s hardware SecurID token. These tokens fit in the palm of your hand, and they display a different password for every login. The password is never repeated, and the odds of guessing it at the right time are extremely small. The user generally also types in a personal PIN, combining the hardware token (something you have) with the PIN (something you know). There are also many other ways to implement two-factor authentication, such as software-based authenticators or cell phone-based systems.

You can also reduce the risk of brute-force webmail attacks by limiting login attempts (i.e. three failed logins in one minute results in a 15-minute lockout). This dramatically limits an attacker's number of guesses. Make sure you have a strong password policy so passwords are difficult to guess, and test accounts regularly. Finally, if you have a password reset system, ensure the answers to questions are not easily attainable from public records or social networking sites.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Email and instant messaging threat defenses
Social media governance needs appropriate security strategy: ISACA
Bloxx provides means of filtering personal emails
Gartner: Enterprises must learn to detect botnet threats
Zeus botnet analysis: Past, present and future threats
Latest Adobe Flash Player update to fix 32 security vulnerabilities
Malware and email authentication for financial services
Are you too small for an email retention and archiving policy?
FTIL tackles Web 2.0 security threats with content filtering
UTM buying essentials for India Inc.
Understand role-based access control in Microsoft Exchange 2010

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite Papers
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2009 - 2010, TechTarget | Read our Privacy Policy
  TechTarget