Contact

What is Brute-Force Attack?

Definition

A brute-force attack tries to discover a password, PIN or cryptographic key by systematically trying possible values until one works. The family includes automated guessing against a login form, replaying username and password pairs leaked from other sites (credential stuffing) and cracking stolen password hashes offline. The main defences are multi-factor authentication, rate limiting, and long, unique passwords stored with a slow hashing algorithm.

Also known as: brute force, brute-force, password guessing attack, exhaustive key search, dictionary attack

Gauge of failed login attempts against thresholds, with rate limiting, lockout, MFA and challenges stopping brute-force guessing

One idea, several variants

  • Classic brute force: trying candidate passwords one after another against a single account.
  • Dictionary attack: starting from common passwords and word lists rather than random combinations.
  • Password spraying: trying a handful of popular passwords across many accounts. With only a few attempts per account, it stays under lockout thresholds.
  • Credential stuffing: replaying username and password pairs leaked in another site's breach. Because people reuse passwords, this is the most productive variant by far.

Then there is offline cracking: once a database has leaked, the attacker no longer needs your login form and can test guesses against the stolen hashes on their own hardware. The only thing standing in the way is storing passwords with a deliberately slow algorithm such as bcrypt or Argon2, as explained under password hashing.

Why length beats complexity

The search space is the size of the character pool raised to the power of the length. An 8-character password of lowercase letters has about 2.1 × 10¹¹ possibilities. Using all 95 printable ASCII characters, 8 characters give roughly 6.6 × 10¹⁵; yet 12 lowercase letters already reach about 9.5 × 10¹⁶. Every extra character multiplies the space by the pool size. In practice: long passphrases for the few passwords you must memorise, a password manager and random passwords for everything else. The Strong Password Generator creates random ones locally in the browser.

Against credential stuffing, though, strength alone changes nothing: a strong password that leaked elsewhere is still a known password. Unique passwords per site and a second factor are what break that attack.

Layers of defence

  1. Multi-factor authentication: the most effective control, because a correct password is no longer enough.
  2. Rate limiting: cap attempts per account, IP and device; responding with 429 Too Many Requests is the standard signal.
  3. Careful lockout: growing delays after each failure often work better than a fixed lockout. Since lockout can be turned into a denial-of-service tool against real users, the password reset path should stay usable for locked accounts.
  4. Identical error messages: “user not found” and “wrong password” should look the same, or attackers can enumerate valid accounts.
  5. Bot friction: a CAPTCHA or bot protection challenge after a few failures slows automation down; it is a layer, not a fix.
  6. Breached-password screening: reject passwords found in known breach corpora at sign-up and on password change.
# Nginx: 5 requests per minute per IP on the login endpoint
limit_req_zone $binary_remote_addr zone=login:10m rate=5r/m;

location = /api/login {
    limit_req zone=login burst=5 nodelay;
    limit_req_status 429;
    proxy_pass http://app;
}

Per-IP limits alone cannot stop a distributed attack from thousands of addresses; pair them with per-account counters inside the application.

Reading the signs in your logs

Well-kept authentication logs show the signature clearly: one IP trying many different accounts (spraying), many IPs hammering one account, a single success after hundreds of failures, or a session from a country the user has never logged in from. Alerting on these patterns means noticing an attack while it is happening rather than weeks later. The OWASP Authentication Cheat Sheet collects the detailed recommendations.

Related terms

← Back to the glossary