• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
How to Avoid Cyber Threats by Disgruntled Employees
July 19, 2019
Rewterz Threat Alert – Amex Cardholders Targeted via Phishing Scheme
July 22, 2019

Rewterz Threat Alert – Protecting Your Organization from Password Spraying

July 22, 2019

Severity

Medium

Analysis Summary

Password spraying attacks often goes unnoticed in the radar because of their low and slow approach. It is mostly because of not targeting a single account with multiple password guesses but multiple accounts to avoid lock outs and disabling the account. Attackers obtain lists of common passwords previously leaked and try them on multiple accounts.

Password spraying attacks have high success rate because of users using the common passwords. Research showed a significant amount of similarity between account passwords commonly used by people in organisations which touch a massive 75% and 87% passwords featured in the top 10,000 most commonly used passwords which makes it easier for the attackers to target users. These stats are clear signs of worry that reminds that common passwords are still a serious threat to data security today.

Citrix Breach

In 2019, Citrix confirmed the breach of their internal network which was most likely to be a password spraying attack. The attack went completely went unnoticed for five months and it most likely exploited weak passwords to gain access and downloaded business documents, which indicates that any organization even a tech savvy one can fall prey to weak password policy.

Impact

Credential theft

Remediation

  • Implement an effective password policy that balances usability and security.
  • It is strongly suggested to enable multi factor authentication to ensure safety of your account.
  • Educate users about the safety of their accounts by security training that helps prevents the common threats such as password spraying.
  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.