EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy
A penetration tester is evaluating a web application's login form. They notice that repeated failed login attempts for a specific username do not result in any account lockout or delay mechanism. The tester then proceeds to use a tool to rapidly try thousands of common passwords against a single target username. Which type of attack is the tester performing?
- ABrute-Force Attack
- BCredential Stuffing
- CRainbow Table Attack
- DDictionary Attack
Show answer & explanationAnswer & explanation
Correct answer: D. Dictionary Attack
The tester is trying thousands of *common* passwords against a *single* target username. This fits the definition of a Dictionary Attack, which uses a list of common passwords, unlike a pure brute-force that tries all possible combinations.
Why the other options are wrong
- A. Brute-force attacks try every possible character combination, which is broader than 'common passwords'.
- B. Credential Stuffing uses breached username/password pairs obtained from other sites, not common passwords generated for a single account.
- C. Rainbow table attacks are used to reverse password hashes, not directly against a login form with a specific username.
Dictionary Attack
A Dictionary Attack is a type of brute-force attack that attempts to gain unauthorized access to a computer system by systematically trying a list of common words, phrases, and passwords.
- More efficient than pure brute-force for common passwords.
- Relies on users choosing weak or easily guessable passwords.
- Mitigated by strong password policies, account lockout, and multi-factor authentication.
Memory trick: Passwords Tested, Access Gained.