Threat, Vulnerabilities and Mitigations: Indicators of Password Attacks Flashcards

1
Q

What are indications of Password Attacks?

A

Unusual amount of failed log in attempts
Unusual Login Activity
Account Lockouts
Unexpected Password Change Notifications
Unauthorized Account Access
Security Alerts
Slow System Performance
IP Address Blocking
Unexpected Two-Factor Authentication (2FA) Requests
Social Engineering Attempts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a dictionary attack?

A

A dictionary attack is a method used to break into a password-protected system or account by systematically entering every word in a predefined list (dictionary) of possible passwords. This list typically contains common passwords, words found in dictionaries, and variations of those words.

This can also use added characters at the front or end of a possible password eg 23Dog23!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a brute force attack?

A

Pure brute force, which often is indicated by unexpected failures:

Windows Server:

https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx

Event Viewer > Windows Logs > Security

Linux SSH Server

Look for abnormally amount of Failed Log in attempts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is spraying?

A

Spraying – Take commonly used password and try to log into Computers in greater numbers of the chance logging into a computer

https://attack.mitre.org/techniques/T1110/003/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is credential stuffing?

A

Credential stuffing – Take known data breaches and re-use those password to gain access

https://attack.mitre.org/techniques/T1110/004/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly