Password Spraying 101

  • one password, multiple usernames/emails
  • use delay between login attempts to reduce the risk of lockouts.
  • find a domains password policy and design your password spray according to this
    • lowers the lockout risk
  • If you don’t know the password policy, wait a few hours between attempts, which should be long enough for the account lockout threshold to reset.
  • It is best to obtain the password policy before attempting the attack during an internal assessment, but this is not always possible.
  • Password spray is a "hail Mary/Jai gajanan" option if all other options for a foothold or furthering access have been exhausted