Joke Collection Website - Blessing messages - What is a library collision attack? And how to prevent library collision attacks.

What is a library collision attack? And how to prevent library collision attacks.

Database collision means that hackers collect leaked user and password information on the Internet, generate corresponding dictionary tables, and try to log in to other websites in batches, so as to obtain a series of users who can log in. Many users use the same account password on different websites. Hackers can try to log in to website B by obtaining the user's account on website A, which can be understood as a library collision attack.

Database security protection technology can solve database conflicts, mainly including: database leak scanning, database encryption, database firewall, data desensitization and database security audit system.

Extended data:

Famous case:

Take JD for example. Take the library collision before COM as an example. First of all, JD The database of COM has not been leaked. Hackers just "bumped into the library" and "happened" to get some data (user names and passwords) of users in JD.COM.

This method can handle almost any website login system. Users use the same user name and password when logging in different websites, which is equivalent to giving themselves a "master key". Once lost, the consequences can be imagined. Therefore, it is a protracted war to prevent library collision, which requires the participation of users.

The user information of 20 14 12.25 and 12306 websites went viral online. In this regard, 12306 official website said that the leaked user information on the Internet flowed out through other websites or channels. It is reported that the leaked user data is not less than 13 1 653. This batch of data is basically confirmed to be obtained by hackers through "library collision attacks". ?

On June 5, 2065438+08, it was reported that not long ago, Yuhang District People's Procuratorate of Hangzhou, Zhejiang Province prosecuted Tan Moumou, Ye Moumou and Zhang Moumou for providing data to invade the computer information system for the crime of illegally obtaining computer information data.

On May 2, 2065438, the Yuhang District People's Court made a judgment on this case. The defendant Tan Moumou was sentenced to three years in prison, suspended for four years, and fined RMB 40,000. Defendant Ye Moumou committed the crime of providing programs to invade computer information systems, and was sentenced to three years in prison, suspended for four years, and fined RMB 40,000.

The defendant Zhang Moumou was sentenced to three years' imprisonment, suspended for three years, and fined RMB 30,000. It is reported that this is the first case of library collision and coding in China. The court fully adopted the prosecution opinions of the procuratorate.

Baidu encyclopedia-library collision attack