CompTIA Security+ (SY0-701)Security OperationsMedium
A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts on the corporate VPN. Many of these attempts are failing. What type of attack is MOST likely occurring?
- AMan-in-the-Middle (MitM)
- BSQL injection
- CDistributed Denial of Service (DDoS)
- DCredential stuffing
Show answer & explanationAnswer & explanation
Correct answer: D. Credential stuffing
Credential stuffing involves an attacker using a list of compromised usernames and passwords (often from a breach on a different service) to attempt to gain unauthorized access to multiple accounts on a new service. The 'spike in login attempts from a single IP to multiple user accounts' and 'many failing' are key indicators.
Why the other options are wrong
- A. MitM attacks involve intercepting communication between two parties and wouldn't directly cause a spike in login attempts from a single IP.
- B. SQL injection targets databases via input fields and doesn't manifest as a spike in login attempts to multiple user accounts.
- C. DDoS attacks aim to overwhelm a service with traffic, not specifically to log into multiple user accounts.
Credential Stuffing
An attack where adversaries use lists of compromised username/password pairs (obtained from data breaches) to try and gain unauthorized access to user accounts on different services.
- Relies on password reuse by users.
- Often uses automated tools.
- Results in many failed login attempts across multiple accounts.
Memory trick: An attacker 'stuffs' credentials into many accounts, hoping one 'fits'.