Cracking & Brute Force
How passwords actually fall — offline against a stolen hash at a hundred billion guesses a second, online against a live login at four. Which hashes crack instantly and which never do, why the difference is the algorithm rather than the password, and what genuinely stops each attack.
Not yet reviewed
Before you start
- Linux Fundamentalsabout 6h
This course expects those first. Nothing is locked — sign in and it will say where you stand.
Offline cracking against a stolen hash, and why the algorithm decides everything.
- Attack
- Telemetry
- Fix
- Detection
1 lesson · 1 hands-on · 2 min
When a tiny list built from the account beats a million generic words.
- Attack
- Telemetry
- Fix
- Detection
1 lesson · 1 hands-on · 2 min
Online brute force, and why it is mostly a way to get rate-limited.
- Attack
- Telemetry
- Fix
- Detection
1 lesson · 1 hands-on · 2 min
A memory-hard hash, rate limiting on both axes, and a constant-time comparison.
One-sided — This module is the defence for the three attacks above. It teaches from the platform's own implementations rather than staging a fresh attack, which the earlier modules already did.
1 lesson · 3 min
Exam
Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.