Watch out for Password Spraying Attacks…

by

August 13, 2019

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to Network Administrators regarding an increase in Password Spraying attacks.

What is a Password Spraying Attack?

Pretty much exactly what it sounds like. It’s a brute-force style attack where a would-be attacker literally sprays passwords at a user accounts until one sticks.

By using one password at a time across multiple accounts the attacker is usually able to remain undetected.

Typical Targets

Attackers go after a wide array of targets including, but not limited to:

  • Webmail
  • Remote Desktop Software
  • Active Directory Federated Services
  • Cloud Services (i.e. Office365)

What to Look For

  • A high number of authentication attempts within a set period of time
  • Large numbers of bad usernames
  • High number of account lockouts within a set period of time

How to Stop a Password Spraying Attack

  • Implement multifactor authentication
  • Use complex passwords
  • Implement a strong password reset policy
  • Increase alerting and monitoring

Like our blog? Subscribe using the CTA in the upper right hand corner of this page. Feel like sharing your thoughts with us? Use the comment section below.

Don’t forget to follow us on LinkedIn and Twitter

Carl Keyser is the Content Manager at Integris.

Keep reading

What Are Best Practices for Managing IT Projects?

What Are Best Practices for Managing IT Projects?

What Are Best Practices for Managing IT Projects? The Quick Take Managing IT projects effectively is crucial for ensuring success and maximizing ROI. Here are the best practices to follow: Define Clear Objectives and Scope: Set specific, measurable, achievable,...

What Is The Future of Managed IT Services?

What Is The Future of Managed IT Services?

What Is the Future of Managed IT Services? The Quick Take: The future of managed IT services for small and medium-sized businesses is bright, with the market expected to grow from $1.735 trillion to $2.173 trillion by 2028. Key trends driving this growth include:...

The Regulatory Outlook for 2025 and What That Means for Banking IT

The Regulatory Outlook for 2025 and What That Means for Banking IT

With a new administration coming in, 2025 promises to be a year of change. But will it significantly impact banking regulation and your bank’s cybersecurity? No one has a crystal ball, of course, but recent global outlooks for the banking industry seem to point to two...