Skip to content

Latest commit

 

History

History
15 lines (9 loc) · 476 Bytes

credential-stuffing-and-password-spraying.md

File metadata and controls

15 lines (9 loc) · 476 Bytes

Credential Stuffing and Password Spraying

Credential Stuffing

  • Injecting breached account credentials in hopes of account takeover
    • Stolen credentials from a previous breach

{% embed url="https://academy.tcm-sec.com/courses/1152300/lectures/24769650" %}

  • Utilize the "pitchfork" attack type in Burp

Password Spraying

  • Passwords are randomly chosen and sent at the target in an attempt to authenticate
  • Utilize the