473,383 Members | 1,798 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,383 software developers and data experts.

mdw security

kai
Hi,
I created user-level security for my database. I found several software
can crack my mdw file. If without my mdw file, can some one still crack the
database?

Thanks

Kai

Nov 13 '05 #1
5 2089
"kai" <ka******@earthlink.net> wrote in message news:<%E*****************@newsread2.news.atl.earth link.net>...
Hi,
I created user-level security for my database. I found several software
can crack my mdw file. If without my mdw file, can some one still crack the
database?


Most of the password 'cracker' programs I've seen for Access, Excel,
etc. rely on the fact that most of us use relatively short passwords
and/or passwords created from common words. The first type of
password is vulnerable to a brute force approach in which every
possible combination of 1-n letters and numbers is tried where n is
the number of characters in your password and the second is vulnerable
to a slightly more sophisticated approach where the cracker program
uses a dictionary of words or word fragments to try to guess your
password. If you make your password long enough, mix numbers and
letters, and make the combination of letters and numbers sufficiently
random (i.e., not a meaningful word) those cracker programs could be
occupied for weeks or months trying to figure out your password on the
fastest PC.

Bruce
Nov 13 '05 #2
> Most of the password 'cracker' programs I've seen for Access, Excel,
etc. rely on the fact that most of us use relatively short passwords
and/or passwords created from common words. The first type of
password is vulnerable to a brute force approach in which every
possible combination of 1-n letters and numbers is tried where n is
the number of characters in your password and the second is vulnerable
to a slightly more sophisticated approach where the cracker program
uses a dictionary of words or word fragments to try to guess your
password. If you make your password long enough, mix numbers and
letters, and make the combination of letters and numbers sufficiently
random (i.e., not a meaningful word) those cracker programs could be
occupied for weeks or months trying to figure out your password on the
fastest PC.

Bruce


I've came across a software that can reveal the actual password in MDW
within seconds...
Nov 13 '05 #3
Bruce wrote:
"kai" <ka******@earthlink.net> wrote in message news:<%E*****************@newsread2.news.atl.earth link.net>...
Hi,
I created user-level security for my database. I found several software
can crack my mdw file. If without my mdw file, can some one still crack the
database?

Most of the password 'cracker' programs I've seen for Access, Excel,
etc. rely on the fact that most of us use relatively short passwords
and/or passwords created from common words. The first type of
password is vulnerable to a brute force approach in which every
possible combination of 1-n letters and numbers is tried where n is
the number of characters in your password and the second is vulnerable
to a slightly more sophisticated approach where the cracker program
uses a dictionary of words or word fragments to try to guess your
password. If you make your password long enough, mix numbers and
letters, and make the combination of letters and numbers sufficiently
random (i.e., not a meaningful word) those cracker programs could be
occupied for weeks or months trying to figure out your password on the
fastest PC.

Not true at all. This is general advice which is hardly applicable to
Access, where the security is poorly implemented and removable without
any brute force attack.
Nov 13 '05 #4
"Peter Miller" <pm*****@pksolutions.com> wrote...
This is general advice which is hardly applicable to
Access, where the security is poorly implemented
and removable without any brute force attack.


There are also techniques that allow security to simply be ignored for a
bit, leaving no indication to a database owner that someone was
tampering....
--
MichKa [MS]
NLS Collation/Locale/Keyboard Technical Lead
Globalization Infrastructure and Font Technologies
Windows International Division

This posting is provided "AS IS" with
no warranties, and confers no rights.
Nov 13 '05 #5
Michael (michka) Kaplan [MS] wrote:
"Peter Miller" <pm*****@pksolutions.com> wrote...
This is general advice which is hardly applicable to
Access, where the security is poorly implemented
and removable without any brute force attack.


There are also techniques that allow security to simply be ignored for a
bit, leaving no indication to a database owner that someone was
tampering....


I'm getting in on this late, but here is my 2cents too.

I bought a cracker from a place called passwordtools.com just to test it
out and see how well these things worked. It worked admirably on my
test files, even for non-trivial passwords.

According to Ad-Aware, it also installed a keylogger on my machine.
Whether Ad-Aware was correct or not, I cannot say but I can tell you
their software is no longer resident on my machine.
--
To Email Me, ROT13 My Shown Email Address

Nov 13 '05 #6

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

2
by: robert | last post by:
well, talk about timely. i'm tasked to implement a security feature, and would rather do so in the database than the application code. the application is generally Oracle, but sometimes DB2. ...
116
by: Mike MacSween | last post by:
S**t for brains strikes again! Why did I do that? When I met the clients and at some point they vaguely asked whether eventually would it be possible to have some people who could read the data...
4
by: Ashish | last post by:
Hi Guys I am getting the following error while implementing authentication using WS-security. "Microsoft.Web.Services2.Security.SecurityFault: The security token could not be authenticated...
0
by: prithvi g via .NET 247 | last post by:
Hi I am a newbie to .NET remoting, I am trying to implementauthorization using SSPI example provided by Michael Barnett. Ihave included the required dll(Microsoft.Samples.Security.SSPI.dll...
1
by: Earl Teigrob | last post by:
Background: When I create a ASP.NET control (User or custom), it often requires security to be set for certain functionality with the control. For example, a news release user control that is...
7
by: Magdelin | last post by:
Hi, My security team thinks allowing communication between the two IIS instances leads to severe security risks. Basically, we want to put our presentation tier on the perimeter network and the...
0
by: Jay C. | last post by:
Jay 3 Jan. 11:38 Optionen anzeigen Newsgroups: microsoft.public.dotnet.framework.webservices.enhancements Von: "Jay" <p.brunm...@nusurf.at> - Nachrichten dieses Autors suchen Datum: 3 Jan...
3
by: Velvet | last post by:
I ran FxCop on one of the components for my web site and the security rules what me to add " tags like the ones listed below: This breaks my ASP.NET application. So my question is,...
1
by: Jeremy S. | last post by:
..NET's code Access Security enables administrators to restrict the types of things that a .NET application can do on a local computer. For example, a ..NET Windows Forms application can be...
2
by: Budhi Saputra Prasetya | last post by:
Hi, I managed to create a Windows Form Control and put it on my ASP .NET page. I have done the suggestion that is provided by modifying the security settings. From the stack trace, I would...
1
by: CloudSolutions | last post by:
Introduction: For many beginners and individual users, requiring a credit card and email registration may pose a barrier when starting to use cloud servers. However, some cloud server providers now...
0
by: Faith0G | last post by:
I am starting a new it consulting business and it's been a while since I setup a new website. Is wordpress still the best web based software for hosting a 5 page website? The webpages will be...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 3 Apr 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome former...
0
by: ryjfgjl | last post by:
In our work, we often need to import Excel data into databases (such as MySQL, SQL Server, Oracle) for data analysis and processing. Usually, we use database tools like Navicat or the Excel import...
0
by: taylorcarr | last post by:
A Canon printer is a smart device known for being advanced, efficient, and reliable. It is designed for home, office, and hybrid workspace use and can also be used for a variety of purposes. However,...
0
by: aa123db | last post by:
Variable and constants Use var or let for variables and const fror constants. Var foo ='bar'; Let foo ='bar';const baz ='bar'; Functions function $name$ ($parameters$) { } ...
0
by: ryjfgjl | last post by:
If we have dozens or hundreds of excel to import into the database, if we use the excel import function provided by database editors such as navicat, it will be extremely tedious and time-consuming...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
1
by: nemocccc | last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.