Attacks and brute force · الهجمات والقوة الغاشمة
How attackers get in
- Beyond malware, attackers use direct attacks. The exam lists several:
- Brute-force attack — trying every possible password until one works.
- Hacking — gaining access without permission, often through a weakness.
كيف يدخل المهاجمون
- بالإضافة إلى البرمجيات الخبيثة، يستخدم المهاجمون هجمات مباشرة. يذكر الامتحان عدة أنواع:
- هجوم القوة الغاشمة — تجربة كل كلمة مرور محتملة حتى تعمل واحدة.
- الاختراق — الحصول على الوصول بدون إذن، غالباً عن طريق استغلال ثغرة.
Attacks on the network
- Data interception — "listening in" on data as it travels, to steal it (a packet sniffer).
- Denial of Service (DoS) — flooding a server with so many requests that it cannot serve real users.
- A DDoS does this from thousands of machines at once, so it is hard to block.
هجمات على الشبكة
- اعتراض البيانات — "التنصت" على البيانات أثناء انتقالها لسرقتها (مُشتت الحزم).
- حجب الخدمة (DoS) — إغراق خادم بطلبات كثيرة جداً بحيث لا يستطيع خدمة المستخدمين الحقيقيين.
- تقوم DDoS بذلك من آلاف الأجهزة في آن واحد، مما يجعل حصرها صعباً.
Why short passwords fail
- A 4-digit PIN has only 10,000 combinations. A computer tries millions per second.
- Below, brute-force a PIN by trying every value — then notice how a longer password would have far more combinations.
لماذا تفشل كلمات المرور القصيرة
- الرمز التعريفي المكوّن من 4 أرقام له فقط 10,000 احتمالات. يحاول الحاسوب ملايين الاحتمالات في الثانية.
- أدناه، جرب اختراق رمز تعريفي بتجربة كل قيمة — ثم لاحظ كم عدد الاحتمالات الأكثر بكثير لكلمة مرور أطول.
The lesson
- Each extra character multiplies the number of guesses needed.
- That is why length is the single most powerful thing about a password — more on that soon.
Covers: IGCSE 5.3 (brute-force, hacking, interception, DDoS).
الدرس المستفاد
- كل حرف إضافي يُضاعف عدد المحاولات المطلوبة.
- ولهذا السبب الطول هو العامل الأقوى وحده في كلمة المرور — المزيد من التفاصيل قريباً.
يتناول: IGCSE 5.3 (القوة الغاشمة، الاختراق، Intercepting, DDoS).
Common mistakes
- A brute-force attack tries every combination — a longer password makes it far slower.
- Rate-limiting and account lockouts help defend against it.
أخطاء شائعة
- تحاول هجمة القوة الغاشمة كل الاحتمالات — وكلمة المرور الأطول تجعل الأمر أبطأ بكثير.
- الحد من معدل الطلبات وإغلاق الحسابات يساعد في الدفاع ضدها.
A 4-digit PIN has only 10000 possibilities — a computer can try them all in an instant. Loop through range(10000) and print the value that equals the secret, then stop. · رمز PIN مكون من 4 أرقام له 10000 احتمال فقط — يمكن لحاسوب تجربتها جميعاً في لحظة. مرر عبر range(10000) وprint القيمة التي تساوي secret، ثم توقف.
Click Run to see the output here. · اضغط تشغيل لرؤية المخرجات هنا.
See why length wins. A lowercase-letters password has 26 ** length combinations. Print the number of combinations for length 4, then for length 8 — watch it explode. · رَ لماذا الطول يفوز. كلمة مرور بأحرف صغيرة لها 26 ** length احتمالات. اطبع عدد الاحتمالات للطول 4، ثم للطول 8 — شاهد كيف تنفجر.
Click Run to see the output here. · اضغط تشغيل لرؤية المخرجات هنا.