CAPEC 16 Dictionary-based Password Attack

Draft Detailed Medium Risk
Severity High

Description

{'xhtml:p': ['An attacker tries each of the words in a dictionary as passwords to gain access to the system via some user's account. If the password chosen by the user was a word within the dictionary, this attack will be successful (in the absence of other mitigations). This is a specific instance of the password brute forcing attack pattern.', 'Dictionary Attacks differ from similar attacks such as Password Spraying (CAPEC-565) and Credential Stuffing (CAPEC-600), since they leverage unknown username/password combinations and don't care about inducing account lockouts.']}

Attack Execution Flow

4

Mitigations

3

Consequences

Indicators

1

Relationships

Resources Required

1