Attacks and brute force · תקיפות וניסיון כוח גס
How attackers get in
- Beyond malware, attackers use direct attacks. The exam lists several:
- Brute-force attack — trying every possible password until one works.
- Hacking — gaining access without permission, often through a weakness.
איך התוקפים נכנסים
- מעבר לתוכנות רעות, התוקפים משתמשים בתקיפות ישירות. המבחן מציין מספר סוגים:
- תקיפת כוח גס — ניסוי של כל הסיסמאות האפשריות עד שמצאים אחת שעובדת.
- האקינג — רכישת גישה ללא רשות, לעיתים קרובות באמצעות נקודה חלשה.
Attacks on the network
- Data interception — "listening in" on data as it travels, to steal it (a packet sniffer).
- Denial of Service (DoS) — flooding a server with so many requests that it cannot serve real users.
- A DDoS does this from thousands of machines at once, so it is hard to block.
תקיפות ברשת
- תפיסת נתונים — "האזנה" לנתונים בעת מעברם, כדי לגנב אותם (מזהה חבילות).
- פגיעה בשירות (DoS) — הצפת שרת בבקשות כה רבות עד שאינו מסוגל לשמש משתמשים אמיתיים.
- DDoS מבצע זאת מאלפי מכונות בו-זמנית, ולכן קשה לחסום אותו.
Why short passwords fail
- A 4-digit PIN has only 10,000 combinations. A computer tries millions per second.
- Below, brute-force a PIN by trying every value — then notice how a longer password would have far more combinations.
מדוע סיסמאות קצרות נכשלות
- קוד PIN בן 4 ספרות כולל רק 10,000 אפשרויות. מחשב מנסה מיליונים בשנייה.
- למטה, פיצוץ כוח לפינס על ידי ניסוי כל הערכים — ואז שימו לב לכך שסיסמה ארוכה יותר הייתה כוללת הרבה יותר אפשרויות.
The lesson
- Each extra character multiplies the number of guesses needed.
- That is why length is the single most powerful thing about a password — more on that soon.
Covers: IGCSE 5.3 (brute-force, hacking, interception, DDoS).
המסקנה
- כל תוספת של תווה מכפילה את מספר הניסויים הנדרשים.
- זוהי הסיבה שהאורך הוא הדבר החזק ביותר בסיסמה — עוד על כך בקרוב.
מכסה: IGCSE 5.3 (פיצוץ כוח, התקפות, תפיסת נתונים, DDoS).
Common mistakes
- A brute-force attack tries every combination — a longer password makes it far slower.
- Rate-limiting and account lockouts help defend against it.
טעויות נפוצות
- התקפת פיצוץ כוח מנסה כל האפשרויות — סיסמה ארוכה יותר הופכת אותה להרבה איטית יותר.
- הגבלת קצב וסגירת חשבונות עוזרים להגן עליה.
A 4-digit PIN has only 10000 possibilities — a computer can try them all in an instant. Loop through range(10000) and print the value that equals the secret, then stop. · ל-PIN בן 4 ספרות יש רק 10000 אפשרויות — מחשב יכול לנסות אותן כולן ברגע. חזור על לולאה ב-range(10000) ועל print הערך ששווה ל-secret, ואז עצור.
Click Run to see the output here. · לחץ על הרץ כדי לראות את התוצא כאן.
See why length wins. A lowercase-letters password has 26 ** length combinations. Print the number of combinations for length 4, then for length 8 — watch it explode. · ראה מדוע אורך מנצח. סיסמה באותיות קטנות יש לה 26 ** length שילובים. הדפס את מספר השילובים עבור אורך 4, ולאחר מכן עבור אורך 8 — ראה איך הוא מתפוצץ.
Click Run to see the output here. · לחץ על הרץ כדי לראות את התוצא כאן.