Password Spraying 101
- one password, multiple usernames/emails
- use delay between login attempts to reduce the risk of lockouts.
- find a domains password policy and design your password spray according to this
- If you don’t know the password policy, wait a few hours between attempts, which should be long enough for the account lockout threshold to reset.
- It is best to obtain the password policy before attempting the attack during an internal assessment, but this is not always possible.
- Password spray is a "hail Mary/Jai gajanan" option if all other options for a foothold or furthering access have been exhausted