CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester obtains a list of 500,000 username/password pairs leaked from an unrelated third-party website breach and uses an automated tool to try each exact pair against a corporate web portal's login page, succeeding on accounts where employees reused the same password. Which attack technique is this?

  1. ABrute-force attack
  2. BDictionary attack
  3. CPassword spraying
  4. DCredential stuffing
Show answer & explanation

Correct answer: D. Credential stuffing

Credential stuffing uses known valid username/password pairs from prior breaches and tries them as exact matches against a different service, exploiting password reuse across sites — unlike password spraying, which tries a small set of common passwords against many different usernames.

Why the other options are wrong

  • A. Brute force systematically tries all possible character combinations, not pre-known valid pairs.
  • B. A dictionary attack tries a wordlist of likely passwords against one account, not paired credentials from a breach.
  • C. Password spraying tries a few common passwords across many accounts, not exact leaked username/password pairs.

Credential Stuffing

An attack that automates login attempts using username/password pairs obtained from previous data breaches, exploiting users who reuse the same credentials across multiple services.

  • Relies on real, previously breached credential pairs, not guessed passwords
  • Effective due to widespread password reuse
  • Mitigated by MFA, breach-password blocklists, and rate limiting

Memory trick: Stuffing = stuffing stolen keys into every door hoping one fits

More Attacks and Exploits questions