Resource icon

Password spraying: one guess against many accounts

Password spraying is an attack in which someone tries a small set of common passwords across many accounts. Spreading the guesses can avoid the lockout that a long sequence against one account might trigger. The attacker still needs a successful sign-in to take control.

A useful example​

An organization sees a single weak password tried against hundreds of staff addresses. Most attempts fail; one account using that password succeeds. The best response is not to reset only the loudest account. Investigators check for successful sign-ins, revoke affected sessions and make sure accounts use unique strong passwords and MFA.

What an individual can do​

Use a password manager to generate unique passwords, turn on MFA and report unexpected approvals to your security team. A failed-login notice does not mean your password was guessed. The OWASP explanation describes how spraying differs from repeated guessing against one user.

Practical distinction​

A failed attempt is a warning to review, not proof of entry. Successful sign-ins and new sessions determine which accounts need immediate containment.
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack