Six Years of Service
Posts: 2,973
Threads: 246
RE: HACKER LEXICON: WHAT IS CREDENTIAL STUFFING? 02-17-2019, 06:44 PM
#2
wow, I will sure take a look at the link.
My IT skills that I know perfect is SQL, HTML ,css ,wordpress, PHP.
coding skills that I know is Java, JavaScript and C#
•
Eight Years of Service
Posts: 48
Threads: 7
RE: HACKER LEXICON: WHAT IS CREDENTIAL STUFFING? 02-18-2019, 05:07 AM
#4
(02-18-2019, 04:53 AM)mothered Wrote: Quote:Attackers take a massive trove of usernames and passwords (often from a corporate megabreach) and try to "stuff" those credentials into the login page of other digital services
Because people often reuse the same username and password across multiple sites, attackers can often use one piece of credential info to unlock multiple accounts.
What's the big deal about this? I've been doing It for over two decades.
It's common sense, really.
You're right, it is. But things don't really get brought up because people use the hell out of it because it becomes popular. It's just like an exploit. I have a folder with private and public exploits. I don't share my private exploits because I don't want it to be fixed. People are now going to try and make website logins more secure by using different methods such as 2 factor authentication everywhere or something more friendlier as this method of compromise becomes more used or popular. What i'm really trying to get to is, this method is just now becoming more recognized because of it's trend.
(This post was last modified: 02-18-2019, 05:11 AM by SickPsycko.)
“Lord, protect me from my friends; I can take care of my enemies.” - Volitaire
•
Six Years of Service
Posts: 2,973
Threads: 246
RE: HACKER LEXICON: WHAT IS CREDENTIAL STUFFING? 02-18-2019, 12:54 PM
#6
(02-18-2019, 05:07 AM)SickPsycko Wrote: (02-18-2019, 04:53 AM)mothered Wrote: Quote:Attackers take a massive trove of usernames and passwords (often from a corporate megabreach) and try to "stuff" those credentials into the login page of other digital services
Because people often reuse the same username and password across multiple sites, attackers can often use one piece of credential info to unlock multiple accounts.
What's the big deal about this? I've been doing It for over two decades.
It's common sense, really.
You're right, it is. But things don't really get brought up because people use the hell out of it because it becomes popular. It's just like an exploit. I have a folder with private and public exploits. I don't share my private exploits because I don't want it to be fixed. People are now going to try and make website logins more secure by using different methods such as 2 factor authentication everywhere or something more friendlier as this method of compromise becomes more used or popular. What i'm really trying to get to is, this method is just now becoming more recognized because of it's trend.
that good you do not share your private exploits.
My IT skills that I know perfect is SQL, HTML ,css ,wordpress, PHP.
coding skills that I know is Java, JavaScript and C#
•