Rewterz Threat Alert – Protecting Your Organization from Password Spraying

Monday, July 22, 2019

Severity

Medium

Analysis Summary

Password spraying attacks often goes unnoticed in the radar because of their low and slow approach. It is mostly because of not targeting a single account with multiple password guesses but multiple accounts to avoid lock outs and disabling the account. Attackers obtain lists of common passwords previously leaked and try them on multiple accounts.

Password spraying attacks have high success rate because of users using the common passwords. Research showed a significant amount of similarity between account passwords commonly used by people in organisations which touch a massive 75% and 87% passwords featured in the top 10,000 most commonly used passwords which makes it easier for the attackers to target users. These stats are clear signs of worry that reminds that common passwords are still a serious threat to data security today.

Citrix Breach

In 2019, Citrix confirmed the breach of their internal network which was most likely to be a password spraying attack. The attack went completely went unnoticed for five months and it most likely exploited weak passwords to gain access and downloaded business documents, which indicates that any organization even a tech savvy one can fall prey to weak password policy.

Impact

Credential theft

Remediation

  • Implement an effective password policy that balances usability and security.
  • It is strongly suggested to enable multi factor authentication to ensure safety of your account.
  • Educate users about the safety of their accounts by security training that helps prevents the common threats such as password spraying.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 6, December 2019 Rewterz Threat Advisory – CVE-2019-14899 – New Linux Vulnerability Inferring and hijacking VPN-tunneled TCP connections
  • 6, December 2019 Rewterz Threat Advisory – CVE-2019-18232 – ICS: Thales DIS SafeNet Sentinel LDK License Manager Runtime Privilege Escalation Vulnerability
  • 5, December 2019 Rewterz Threat Alert – “ZeroCleare” Targets Energy Sector in the Middle East
  • 5, December 2019 Rewterz Threat Alert – CStealer Trojan Targeting Chrome Passwords

Copyright © Rewterz. All rights reserved.