TechKnowSurge
ISC2 CC 5.1 CompTIA Security+ 1.4
InteractiveSecurityFree

After the Password Table Leaks

TechKnowDJ's password table has leaked. For each setup, predict what the attacker gets, then see why.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Storing password hashes instead of passwords is the first defense, but the lesson starts from the moment that defense is tested: the table has been stolen. This activity runs that scenario again and again with different defenses in place, and asks you to predict what the attacker gets. A plain hash cannot be reversed, but it can be looked up. A rainbow table is a precomputed list of passwords and their hashes, so a common password is found in an instant. Long passwords are far less likely to be in one. A salt is a random value added to each user's password before it is hashed. It makes the stored hashes unlike anything in a precomputed table, so rainbow tables stop working. Because each user has their own salt and the system needs it at every login, it is stored in the same table, so a stolen table hands the attacker the salts too. They can still guess: add the salt to each guess, hash it, and compare. A pepper is a secret value added the same way, but stored somewhere else: in the application code or in hardware. If only the database is stolen, the attacker is missing a piece of every hash and their guesses never match. A separate pepper for every user is costly to look up, so systems often use one pepper for everyone, and if that single value leaks, it protects nobody. Neither salt nor pepper stops an insider who can read both locations. Key stretching runs the hashing process many times, for example a thousand. Every guess the attacker makes now costs a thousand hashes, so guessing slows down a thousandfold. The server pays the same cost at every login, so the setting has to be high enough to hurt attackers and low enough not to hurt users.

What you'll learn

Aligned to

ISC2 CC
5.1 Understand data security
CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.

Key terms

Salting
The practice of appending a unique random value to a password before hashing to prevent rainbow table lookups and ensure identical passwords produce different hash outputs.
Peppering
The practice of appending a secret value to a password before hashing, where that value is stored separately from the password database to add a layer of protection against database theft.
Key Stretching
A technique that increases the computational cost of hashing by running the hash function many times, slowing down brute-force guessing attacks.
Rainbow Table
A precomputed lookup table used to reverse cryptographic hash functions, allowing attackers to recover plaintext passwords from stolen hashed credentials. Rainbow table attacks are defeated by adding a unique salt to each password before hashing.
Brute Force Attack
An attack method that systematically tries all possible combinations of passwords or keys until the correct one is found.
Dictionary Attack
A type of brute force attack that uses a predefined list of common words and phrases to guess passwords.
Hash Function
A mathematical algorithm that converts input data of any size into a fixed-size output value used to verify data integrity.

Topics

Interactive Predict

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →