Detecting Password Spraying with Security Event Auditing
May 28 20 2024-5-29 00:17:58 Author: adsecurity.org(查看原文) 阅读量:3 收藏

May 28 2024

A common method attackers leverage as well as many penetration testers and Red Teamers is called “password spraying”. Password spraying is interesting because it’s automated password guessing. This automated password guessing against all users typically avoids account lockout since the logon attempts with a specific password are performed against against every user and not one specific one which is what account lockout was designed to defeat. The attacker starts with a list list of passwords they’re going to try which starts with the most likely passwords (“Fall2017”, “Winter2018”, etc).

Continue reading…

(Visited 97 times, 1 visits today)


文章来源: https://adsecurity.org/?p=4428
如有侵权请联系:admin#unsafe.sh