Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
A security analyst is investigating a series of anomalies on a web server. The server logs show numerous HTTP POST requests to a login page with varying usernames and passwords, originating from a single IP address over a short period. Many of these attempts are failing due to incorrect credentials. Which common attack vector is most likely being observed?
- ADenial of Service (DoS)
- BSQL Injection
- CCross-Site Scripting (XSS)
- DCredential Stuffing
Show answer & explanationAnswer & explanation
Correct answer: D. Credential Stuffing
Credential stuffing involves using compromised username/password pairs obtained from a data breach on one service to attempt to gain unauthorized access to accounts on other, unrelated services. The scenario describes repeated login attempts with varying credentials, which aligns with this attack vector.
Why the other options are wrong
- A. Denial of Service (DoS) attacks aim to make a service unavailable to legitimate users by overwhelming it with traffic, not to compromise user accounts through login attempts.
- B. SQL injection targets vulnerabilities in web application databases, not credential attempts.
- C. Cross-Site Scripting (XSS) involves injecting malicious scripts into web pages viewed by other users, not repeated login attempts.
Credential Stuffing
An attack where an attacker takes a list of compromised username-password pairs, often obtained from a data breach on one service, and attempts to use them to log into a large number of other, unrelated online services.
- Relies on users reusing passwords across multiple sites.
- Automated using bots.
- Often follows a large data breach.
Memory trick: Remember, 'stuffing' implies filling many login forms with stolen credentials.