Dictionary Attack with Transformed Russian Words using QWERTY Keyboard Layout

Lea Müller, Aušrius Juozapavičius, Volodymyr Okhrimchuk, Stefan Sütterlin · 2024

Despite the vulnerability of passwords to various types of attacks, the combination of username and password remains the most commonly used authentication method worldwide. Although the necessity for complex passwords that cannot be easily guessed is widely acknowledged, a considerable number of users opt for simple passwords that can be easily recalled, such as a word or a combination of a word and numbers. Dictionary attacks exploit this vulnerability by attempting to guess a password using a dictionary or wordlist. This paper presents a novel approach to dictionary attacks targeting Russian-speaking users. This approach is predicated on the assumption that Russian-speaking users may have their keyboard configuration set to the QWERTY layout, yet still type their passwords according to the Russian keyboard layout. Thus, typing a Russian word in accordance with this approach would result in a seemingly random sequence of characters. To test this assumption, a dictionary comprising transformed Russian words was compared with a set of one million unique Russian passwords. The results demonstrated that approximately 1% of these passwords exhibited the assumed transformation, while a further 6% of the passwords were at least partially composed of a transformed Russian word.

Read the paper · More papers on PaperTik