From the course: CompTIA Security (SY0-701) Cert Prep: 2 Threats, Vulnerabilities, and Mitigations

Unlock the full course today

Join today to access over 23,200 courses taught by industry experts.

Password spraying and credential stuffing

Password spraying and credential stuffing

- [Narrator] There are two other types of password attack that can occur when users poorly manage their passwords. These are password spraying and credential stuffing. In a password spraying attack, the attacker takes a list of commonly used passwords and then uses them to try to attack many different accounts at the same time. For example, here's a list stored on GitHub of 10 million commonly used passwords. An attacker could take this list and use it to attempt to log into as many accounts as possible. If a target system does not prevent the use of commonly used passwords, chances are that the attack will eventually be successful against at least one account. The best defense against password spraying attacks is to incorporate lists of commonly used passwords into access control systems and prevent users from selecting a password that appears on the list. Credential stuffing attacks are made possible when users…

Contents