CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester obtains a list of 500,000 username/password pairs leaked from an unrelated third-party website breach and uses an automated tool to try each exact pair against a corporate web portal's login page, succeeding on accounts where employees reused the same password. Which attack technique is this?
- ABrute-force attack
- BDictionary attack
- CPassword spraying
- DCredential stuffing
Show answer & explanationAnswer & explanation
Correct answer: D. Credential stuffing
Credential stuffing uses known valid username/password pairs from prior breaches and tries them as exact matches against a different service, exploiting password reuse across sites — unlike password spraying, which tries a small set of common passwords against many different usernames.
Why the other options are wrong
- A. Brute force systematically tries all possible character combinations, not pre-known valid pairs.
- B. A dictionary attack tries a wordlist of likely passwords against one account, not paired credentials from a breach.
- C. Password spraying tries a few common passwords across many accounts, not exact leaked username/password pairs.
Credential Stuffing
An attack that automates login attempts using username/password pairs obtained from previous data breaches, exploiting users who reuse the same credentials across multiple services.
- Relies on real, previously breached credential pairs, not guessed passwords
- Effective due to widespread password reuse
- Mitigated by MFA, breach-password blocklists, and rate limiting
Memory trick: Stuffing = stuffing stolen keys into every door hoping one fits