Analysis of system passwords

This practical task requires you to perform a detailed analysis of system passwords as part of an ethical hacking engagement. You will first crack then analyse a sample password file from a client, then advise them on the weaknesses discovered. You will also provide recommendations for ways to improve their password hygiene and access control in general.

Your task is as follows:

  • Crack the password file supplied using any suitable tool, and report the contents
  • Analyse the contents of the password file using commonly accepted password hygiene and system security standards
  • Make recommendations for improving user access control supported by literature