SBN

The Reality of Compromised Credentials

Cracked Wide Open

Over the past decade, the number of data breaches in almost all industries has skyrocketed. From healthcare to finance, user credentials have become both the tool of cyberattack and one of its primary targets. The 2021 Verizon DBIR report indicated that upwards of 61% of breaches involved leveraged credentials.

Communicating clearly about the problem

The Open Web Application Security Project (OWASP) is a nonprofit foundation that improves software security. OWASP recently produced an Automated Threat Handbook intended to provide a common language for developers, business executives, cybersecurity professionals to communicate and tackle the overarching issues.

Within their digital handbook, OWASP provides a list of umbrella terms describing types of threats and attack methods—from Spamming and Sniping to Ad Fraud and CAPTCHA Defeat. OWASP calls out ā€œCredential Crackingā€ as a top-level term related to credentials.

Credential cracking is the process of ā€œidentifying valid login credentials by trying different values for usernames and/or passwords.ā€ Underneath this umbrella category of credential cracking, there are several more specific terms. These variations include: ā€œBrute-force attacks against sign-inā€; ā€œBrute forcing login credentialsā€; ā€œBrute-force password crackingā€; ā€œCracking login credentialsā€; ā€œPassword brute-forcingā€; ā€œPassword crackingā€; ā€œReverse brute force attackā€; and ā€œUsername cracking; Username enumeration.ā€ All these techniques involve cybercriminals interacting with a User Identity Authorization Process to identify valid credentials.

OWASP also calls out ā€œCredential Stuffingā€ as another top-level category due to how frequently it occurs. Credential stuffing is fundamentally a form of credential cracking but explicitly involves the large-scale use of username/password pairs to verify which credentials are valid.

With any of these techniques, once the hacker has found valid login credentials, the real problems begin. Not only can credentials be used to infect a system with malware or disrupt an entire network, but they can be bought and sold as a commodity. For example, bad actors might sell high-value credentials individually or trade them on the dark web.

Taking next steps to protect your organization

The issue of compromised credentials seems daunting, but fortunately, there are some solutions out there. There are several countermeasures that organizations can take:

One of the most streamlined and effective ways to combat the credential crisis is to screen passwords against those leaked on the dark web. Simply preventing users from re-using passwords found on these unsafe password lists goes a long way to limit cybercriminals cracking efforts.   

The post The Reality of Compromised Credentials appeared first on Enzoic.

*** This is a Security Bloggers Network syndicated blog from Enzoic authored by Enzoic. Read the original post at: https://www.enzoic.com/compromised-credentials/