Member-only story

Understanding Credentials Stuffing and Password Spraying

Gupta Bless
5 min readOct 23, 2021

--

Photo by Mika Baumeister on Unsplash

Introduction

We all are familiar with the importance of credentials as they are an essential part of our digital life. Every user and the organization wants to protect the credentials from being leaked to the attacker. Sometimes the organization might be dealing with some sensitive data. There are two most important terms that are “Credentials Stuffing” and “Password Spraying” . In this blog we are going to discuss those two terms, their exploitation scenarios and what steps can be taken to remediate them.

What is Password Spraying and credentials stuffing?

Source

Password Spraying:

Password spraying is a type of brute force attack that is commonly used in guessing the password of the users. In a typical brute force attack, attackers seek to acquire unauthorized access to a single account by guessing the password repeatedly over a short period of time, usually less than ten minutes. The…

--

--

Gupta Bless
Gupta Bless

Written by Gupta Bless

Security enthusiast working to secure web for others.

No responses yet