#bruteforce

3 posts · Last used 23d

Back to Timeline
Blue Ghost @blueghost@mastodon.online · Jul 21, 2026
Hive Systems published their 2026 password table. The table illustrates the maximum time required to brute force a password based on various lengths and complexities. Brute force: https://wikipedia.org/wiki/Brute-force_attack Website: https://www.hivesystems.com/password-table Blog: https://www.hivesystems.com/blog/are-your-passwords-in-the-green #HiveSystems #Password #InfoSec #BruteForce #PasswordTable #Security #Data #DataProtection #CyberSecurity #PasswordManager #Cracking #Privacy #Passphrase #OpSec #Passwords
4
0
4
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange · Jun 30, 2026
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches. The attack bypasses MFA and SSO because it uses deprecated but still functional OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. https://www.huntress.com/blog/lshiy-password-spray-attack #M365 #bruteforce #passwordspray #compromise #weakpasswords
11
0
6
Erik van Straten @ErikvanStraten@todon.nl · Jun 03, 2026
Replying to on infosec.exchange
@sophieschmieg@infosec.exchange : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance. Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance. I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass I remembered that attack, but Pouyan (@i@toot.pouyan.net) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that. W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier. And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers. Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters). @dangoodin@infosec.exchange @cibyr@omg.wtf.sh #TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
0
0
0

You've seen all posts