Attacks and brute force · การโจมตีและการเดารหัส
How attackers get in
- Beyond malware, attackers use direct attacks. The exam lists several:
- Brute-force attack — trying every possible password until one works.
- Hacking — gaining access without permission, often through a weakness.
ผู้โจมตีเข้าได้ยังไง
- นอกเหนือจากมัลแวร์ ผู้โจมตียังใช้ การโจมตีโดยตรง ข้อสอบได้ระบุไว้หลายแบบ:
- การโจมตีแบบบรูต-ฟอร์ซ — ลองรหัสผ่านที่เป็นไปได้ทั้งหมดจนกว่าจะเจอตัวที่ถูกต้อง
- แฮกเกอร์ — เข้าถึงระบบโดยไม่ได้รับอนุญาต มักผ่านช่องโหว่
Attacks on the network
- Data interception — "listening in" on data as it travels, to steal it (a packet sniffer).
- Denial of Service (DoS) — flooding a server with so many requests that it cannot serve real users.
- A DDoS does this from thousands of machines at once, so it is hard to block.
การโจมตีเครือข่าย
- การดักจับข้อมูล — "ฟัง intercepted" ข้อมูลขณะส่งผ่าน เพื่อขโมยมัน (packet sniffer)
- การปฏิเสธการให้บริการ (DoS) — เติมเซิร์ฟเวอร์ด้วยการร้องขอจำนวนมากจนไม่สามารถให้บริการผู้ใช้จริงได้
- DDoS ทำแบบนี้จาก หลายพัน เครื่องพร้อมกัน จึงยากที่จะปิดกั้น
Why short passwords fail
- A 4-digit PIN has only 10,000 combinations. A computer tries millions per second.
- Below, brute-force a PIN by trying every value — then notice how a longer password would have far more combinations.
ทำไมรหัสผ่านสั้นจึงไม่ปลอดภัย
- PIN ที่มีความยาว 4 หลัก มีเพียง 10,000 แบบเท่านั้น คอมพิวเตอร์สามารถลองได้หลายล้านครั้งต่อวินาที
- ด้านล่างนี้ ให้ใช้วิธี brute-force โดยลองทุกค่าที่เป็นไปได้ — แล้วสังเกตว่าหากพาสเวิร์ดยาวกว่านี้จะมีการจัดเรียงแบบที่มากกว่ามาก
The lesson
- Each extra character multiplies the number of guesses needed.
- That is why length is the single most powerful thing about a password — more on that soon.
Covers: IGCSE 5.3 (brute-force, hacking, interception, DDoS).
บทเรียน
- ทุกครั้งที่เพิ่มตัวอักษรจำนวนหนึ่ง จะทำให้จำนวนการเดาที่ต้องทำเพิ่มขึ้นเป็นคูณ
- นั่นคือเหตุผลที่ ความยาว เป็นปัจจัยที่สำคัญที่สุดของพาสเวิร์ด — เราจะพูดถึงรายละเอียดเพิ่มเติมในอีกตอนหนึ่ง
ครอบคลุม: IGCSE 5.3 (brute-force, การแฮก, การ intercept, DDoS).
Common mistakes
- A brute-force attack tries every combination — a longer password makes it far slower.
- Rate-limiting and account lockouts help defend against it.
ข้อผิดพลาดที่พบบ่อย
- การโจมตีแบบ brute-force คือการลองทุกแบบที่เป็นไปได้ พาสเวิร์ดที่ยาวขึ้นจะทำให้การโจมตีช้าลงอย่างมาก
- การจำกัดอัตราการเข้าถึงและการล็อกบัญชีช่วยป้องกันไม่ให้เกิดการโจมตีประเภทนี้ได้
A 4-digit PIN has only 10000 possibilities — a computer can try them all in an instant. Loop through range(10000) and print the value that equals the secret, then stop. · PIN 4 หลักมีเพียง 10000的可能性 — คอมพิวเตอร์สามารถลองทั้งหมดได้ในเสี้ยววินาที ลูปผ่าน range(10000) และ print ค่าที่เท่ากับ secret แล้วหยุด
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่
See why length wins. A lowercase-letters password has 26 ** length combinations. Print the number of combinations for length 4, then for length 8 — watch it explode. · ดูว่าทำไม ความยาว จึงชนะ รหัสผ่านตัวพิมพ์เล็กมี 26 ** length的组合. พิมพ์จำนวนcombination สำหรับความยาว 4, จากนั้นสำหรับความยาว 8 — ดูมันระเบิดออก
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่