Terme informatique

Credential stuffing

An attack that tests on a stolen identifier service during other data leaks.

View my favorites

Simple definition

An attack that tests on a stolen identifier service during other data leaks.

Technical definition

The credential stuffing exploits the reuse of passwords rather than guessing each combination.

What is it used for ?

Detect and reduce the impact of reuse of compromised identifiers.

Practical example

An email address and password from a leak can be automatically tested on a portal Microsoft 365.

Common issues

  • Reuse of passwords
  • MFA absent
  • Limited detection of automated connections

MFA · Attaque by gross force · Entra ID

Key takeaway: This entry explains the general operation of the term. Exact settings may vary depending on software, vendors and environments.

♡ 0