4 ms·
We see credential stuffing quite a lot, with attacks varying from the blatantly obvious (1000s of requests in a minute, to the login page, from the same IP, wit
by graystevens 9y ago
We see credential stuffing quite a lot, with attacks varying from the blatantly obvious (1000s of requests in a minute, to the login page, from the same IP, with a scripting UserAgent like python-requests) to highly distributed attacks across 100s of IPs with a random but current useragent.
While some malicious folk do this all manually and write their own scripts, tools like those mentioned in Troy's post are pretty common. One mentioned that I'd like to call out is SentryMBA - this tool is easily adapted to any business via a shareable config, written by anyway. Want to know if your service is probably affected or targeted? Google "Sentry MBA" + your businesses name. There are trading forums for these configs, and they range from banks and big businesses, to CRMs and utility services.
SentryMBA also has the ability to scare certain information on a successful login, helping to identify those key accounts that'll earn you more on the black market, such as recent successful orders on Amazon, or a high number of points on Starbucks accounts.
If you've got a business with an online login page, it's well worth checking the logs these types of attacks, to see if any of your users or even employees need to have their passwords reset after being successfully popped from a credential stuffing attack.
- sasas 9y ago> We see credential stuffing quite a lot Thanks for sharing. Super interested to know what line of work you are in?
- stedaniels 9y agoI don't know what his day job is, but is side project, Breach Canary, has just been bookmarked for use in my own side project! Edit: "Incredibly unique canaries personalised for your business. Should they ever be reached or discovered on the Internet, you will be the first to find out, allowing you to be proactive in protecting your real customers – the ones which matter."
- graystevens 9y agoI work in the UK for a large telecoms provider, who I'd like to think are pretty good when it comes to security and monitoring. Take a look through the Sentry MBA configs and I'm sure you'll see a tonne of names you recognise, including my employer. In regards to my side project, as mentioned below, it's something which should hopefully helps businesses spot when their user data has been leaked, so that they can be proactive in their investigations and alerting customers to take a look at their passwords. Hope to get a first draft out soon!
- deleted 9y ago[deleted]