EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A penetration tester is evaluating a web application's login form. They notice that repeated failed login attempts for a specific username do not result in any account lockout or delay mechanism. The tester then proceeds to use a tool to rapidly try thousands of common passwords against a single target username. Which type of attack is the tester performing?

  1. ABrute-Force Attack
  2. BCredential Stuffing
  3. CRainbow Table Attack
  4. DDictionary Attack
Show answer & explanation

Correct answer: D. Dictionary Attack

The tester is trying thousands of *common* passwords against a *single* target username. This fits the definition of a Dictionary Attack, which uses a list of common passwords, unlike a pure brute-force that tries all possible combinations.

Why the other options are wrong

  • A. Brute-force attacks try every possible character combination, which is broader than 'common passwords'.
  • B. Credential Stuffing uses breached username/password pairs obtained from other sites, not common passwords generated for a single account.
  • C. Rainbow table attacks are used to reverse password hashes, not directly against a login form with a specific username.

Dictionary Attack

A Dictionary Attack is a type of brute-force attack that attempts to gain unauthorized access to a computer system by systematically trying a list of common words, phrases, and passwords.

  • More efficient than pure brute-force for common passwords.
  • Relies on users choosing weak or easily guessable passwords.
  • Mitigated by strong password policies, account lockout, and multi-factor authentication.

Memory trick: Passwords Tested, Access Gained.

More Web Application Hacking questions