<aside>
Password Spraying
</aside>
Overview
Password spraying is an effective technique for gaining initial access or expanding access during a penetration test. However, if used carelessly, it can lead to large-scale account lockouts, especially in production environments.
Password Spraying vs Brute Force
-
Brute Force:
Attempts many passwords against a single user account.
High risk of account lockout.
-
Password Spraying:
Attempts one common password across many user accounts.
Lower noise and reduced lockout risk when done correctly.
Attack Pattern
- Select a single common or weak password.
- Attempt authentication against all target usernames.
- Introduce a delay between attempts.
- Repeat the process with another common password if needed.
Lockout Risks
- Password spraying still carries a risk of account lockouts.
- Delays between attempts are critical to prevent triggering lockout policies.
- Internal password spraying follows the same lockout considerations.