Attacks and brute force · Ataques e força bruta
How attackers get in
- Beyond malware, attackers use direct attacks. The exam lists several:
- Brute-force attack — trying every possible password until one works.
- Hacking — gaining access without permission, often through a weakness.
Como os atacantes entram
- Além de malware, os atacantes usam ataques diretos. O exame lista vários:
- Ataque de força bruta — tentar todas as senhas possíveis até uma funcionar.
- Hacking — obter acesso sem permissão, frequentemente através de uma vulnerabilidade.
Attacks on the network
- Data interception — "listening in" on data as it travels, to steal it (a packet sniffer).
- Denial of Service (DoS) — flooding a server with so many requests that it cannot serve real users.
- A DDoS does this from thousands of machines at once, so it is hard to block.
Ataques na rede
- Interceptação de dados — "espiar" nos dados enquanto viajam, para roubá-los (um coletor de pacotes).
- Denegação de Serviço (DoS) — inundar um servidor com tantas solicitações que ele não consegue atender usuários reais.
- Um DDoS faz isso de milhares de máquinas ao mesmo tempo, tornando-o difícil de bloquear.
Why short passwords fail
- A 4-digit PIN has only 10,000 combinations. A computer tries millions per second.
- Below, brute-force a PIN by trying every value — then notice how a longer password would have far more combinations.
Por que senhas curtas falham
- Um PIN de 4 dígitos possui apenas 10,000 combinações. Um computador tenta milhões por segundo.
- Abaixo, faça força bruta em um PIN tentando todos os valores — depois note como uma senha mais longa teria muito mais combinações.
The lesson
- Each extra character multiplies the number of guesses needed.
- That is why length is the single most powerful thing about a password — more on that soon.
Covers: IGCSE 5.3 (brute-force, hacking, interception, DDoS).
A lição
- Cada caractere extra multiplica o número de tentativas necessárias.
- É por isso que o comprimento é a única coisa mais poderosa sobre uma senha — mais sobre isso em breve.
Cobre: IGCSE 5.3 (força bruta, hacking, interceptação, DDoS).
Common mistakes
- A brute-force attack tries every combination — a longer password makes it far slower.
- Rate-limiting and account lockouts help defend against it.
Erros comuns
- Um ataque de força bruta tenta todas as combinações — uma senha mais longa o torna muito mais lento.
- Limitação de taxa e bloqueio de contas ajudam a defender contra isso.
A 4-digit PIN has only 10000 possibilities — a computer can try them all in an instant. Loop through range(10000) and · e print the value that equals the secret, then stop. · Um PIN de 4 dígitos tem apenas 10000 possibilidades — um computador pode tentar todos instantaneamente. Itere sobre range(10000) e print o valor igual ao secret, então pare.
Click Run to see the output here. · Clique em Executar para ver a saída aqui.
See why length · comprimento wins. A lowercase-letters password has 26 ** length combinations. Print the number of combinations for length 4, then for length 8 — watch it explode. · Veja por que o comprimento vence. Uma senha com letras minúsculas tem 26 ** length combinações. Imprima o número de combinações para comprimento 4 e depois para comprimento 8 — observe a explosão.
Click Run to see the output here. · Clique em Executar para ver a saída aqui.