TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Finding: Weak Password Policy

BHIS · 2018-05-24 · Read original ↗

ATT&CK techniques detected

3 predictions
T1110.003Password Spraying
55%
"! - password1! this isn ’ t nearly exhaustive because we often find company names, slogans, and other region specific root words exhibiting the same pattern. users select these passwords because they are easy to remember, easy to create, and conforms with the policy. the followin…"
T1110.002Password Cracking
40%
"! - password1! this isn ’ t nearly exhaustive because we often find company names, slogans, and other region specific root words exhibiting the same pattern. users select these passwords because they are easy to remember, easy to create, and conforms with the policy. the followin…"
T1201Password Policy Discovery
36%
"finding : weak password policy finding : weak password policy the weak password policy finding is typically an indicator of one of two conditions during a test : - a password could be easily guessed using standard authentication mechanisms. - a password could be easily recovered …"

Summary

David Fletcher// The weak password policy finding is typically an indicator of one of two conditions during a test: A password could be easily guessed using standard authentication mechanisms. A […]

The post Finding: Weak Password Policy appeared first on Black Hills Information Security, Inc..