Detailedlikelihood: Mediumseverity: MediumDraft
CAPEC-55Rainbow Table Password Cracking
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
Medium
Description
An attacker gets access to the database table where hashes of passwords are stored. They then use a rainbow table of pre-computed hash chains to attempt to look up the original password. Once the original password corresponding to the hash is obtained, the attacker uses the original password to gain access to the system.
Related weaknesses· 8
MITRE ATT&CK crosswalk· 1
Related attack patterns· 6
Exploits8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
| Weakness | Password Aging with Long Expirationcwe-263 | 100% | live |
| Weakness | Not Using Password Agingcwe-262 | 100% | live |
| Weakness | Use of Password System for Primary Authenticationcwe-309 | 100% | live |
| Weakness | Weak Encoding for Passwordcwe-261 | 100% | live |
| Weakness | Reliance on a Single Factor in a Security Decisioncwe-654 | 100% | live |
| Weakness | Weak Password Requirementscwe-521 | 100% | live |
| Weakness | Use of Password Hash With Insufficient Computational Effortcwe-916 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Password Crackingt1110.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.