Article
|
September 19, 2023
|
No items found.

Strengthening Cybersecurity: Part 2 - Credential stuffing: Unveiling the overlapping password problem

No items found.

In our previous article, we explored the dangers of clear text credential discovery. Today, we're delving into another cybersecurity concern that has been making waves in recent years - credential stuffing, or as it's more accurately understood, "credential overlap." At Elliott Davis, our penetration testers have encountered and exploited this issue in numerous tests, shedding light on its significance in today's threat landscape.

Credential Stuffing vs. Credential Overlap

Before we proceed, it's essential to clarify the terminology. While the term "credential stuffing" is commonly used, it can be somewhat misleading. The issue is better understood as "credential overlap." This occurs when individuals reuse passwords across multiple accounts. When one of these accounts is compromised, malicious actors can exploit the overlap by attempting to use the stolen username and password combinations on other accounts, successfully gaining unauthorized access and potentially elevating access.

Elliott Davis Penetration Test Insights

During our penetration tests for our customers, we've seen firsthand how dangerous credential overlap can be. Numerous times we have discovered password shared between accounts of different levels, including third party managed accounts with privileged access. Here are some key insights:

The Massachusetts Institute of Technology Research and Engineering Adversarial Tactics Techniques, and Common Knowledge (MITRE ATT&CK®) framework classifies this threat under T1110 - "Brute Force." Tactics, Techniques and Procedures (TTP) T1110 encompasses a range of brute force methods used by adversaries to gain unauthorized access.

Mitigation Strategies: People, Process, and Technology

To combat the threat of credential overlap effectively, organizations should adopt a multi-faceted approach involving people, processes, and technology:

Conclusion

Credential overlap, or credential stuffing as it's commonly called, poses a significant threat to organizations. It exploits individuals’ unfortunate habit of password reuse. By following a comprehensive strategy of educating users, implementing stringent policies, and leveraging technology, organizations can significantly reduce the risk of falling victim to this malicious tactic. At Elliott Davis, we're committed to helping our clients stay ahead of these threats through proactive testing and security guidance. Please reach out if you have questions. Stay vigilant, stay secure!

The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.

“Elliott Davis" is the brand name under which Elliott Davis, LLC (doing business in North Carolina and D.C. as Elliott Davis, PLLC) and Elliott Davis Advisory, LLC and its subsidiary entities provide professional services. Elliott Davis, LLC and Elliott Davis Advisory, LLC and its subsidiary entities practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations and professional standards. Elliott Davis, LLC is a licensed independent CPA firm that provides attest services to its customers. Elliott Davis Advisory, LLC and its subsidiary entities provide tax and business consulting services to their customers. Elliott Davis Advisory, LLC and its subsidiary entities are not licensed CPA firms. The entities falling under the Elliott Davis brand are each individual firms that are separate legal and independently owned entities and are not responsible or liable for the services and/or products provided by any other entity providing services and/or products under the Elliott Davis brand. Our use of the terms “our firm” and “we” and “us” and terms of similar import, denote the alternative practice structure conducted by Elliott Davis, LLC and Elliott Davis Advisory, LLC.

links and downloads.

Ready to find your business’ potential?

get in touch

download the white paper

contact our team

contact our team.

contact our team.

meet the author

meet the team

meet the authors

No items found.