A security analyst is investigating a series of alerts from a web application firewall (WAF) indicating 'Excessive Login Failures' originating from a single external IP address. The pattern shows thousands of unique username attempts against the login page within a short period. Which attack technique is most accurately described by this activity?
- ADenial of Service
- BPassword Spraying
- CCredential Stuffing
- DBrute-Force Attack
Show answer & explanationAnswer & explanation
Correct answer: B. Password Spraying
Password spraying involves attempting a small number of common passwords against a large number of user accounts. The scenario describes 'thousands of unique username attempts' with implied common passwords, which aligns perfectly with password spraying. This differs from traditional brute-force (many passwords for one user) or credential stuffing (reused stolen credentials).
Why the other options are wrong
- A. Denial of service aims to make a service unavailable, not to gain unauthorized access through login attempts, although excessive login attempts could indirectly cause a DoS.
- C. Credential stuffing uses previously compromised username/password pairs, not attempts with 'thousands of unique usernames' and implied common guesses.
- D. A brute-force attack typically attempts many different passwords against a single username, not thousands of unique usernames.
Password Spraying
An attack technique where a threat actor attempts a small number of common passwords against a large list of user accounts to avoid account lockout policies, rather than repeatedly trying many passwords against a single account.
- Targets many usernames with a few common passwords.
- Designed to evade account lockout thresholds.
- Often uses common defaults like 'Password1!' or 'Summer2023'.
Memory trick: Spray paints many targets with one color, while brute force hammers one target with many tools.