• Business
  • National
  • Politics
  • Sports
  • Tech
  • World
Saturday, December 14, 2019
No Result
View All Result
VTN News Networks
  • Home
  • NationalBreaking News
    ‘I am homesick’: She asked for photos of Yukon, and social media delivered

    ‘I am homesick’: She asked for photos of Yukon, and social media delivered

    Johnson keeps focus on election win and Brexit, not on regions opposed to leaving EU

    Johnson keeps focus on election win and Brexit, not on regions opposed to leaving EU

    From fourth place, Singh says he’d rather push Liberals than work with Tories

    From fourth place, Singh says he’d rather push Liberals than work with Tories

    Triumphant Boris Johnson heads to working class heartland to celebrate election win

    Triumphant Boris Johnson heads to working class heartland to celebrate election win

    Tragically Hip tribute band from Moose Factory translates lyrics into Cree

    Tragically Hip tribute band from Moose Factory translates lyrics into Cree

    Family of pilot killed in Gabriola Island crash says it is ‘absolutely devastated’

    Family of pilot killed in Gabriola Island crash says it is ‘absolutely devastated’

    Trending Tags

    • Donald Trump
    • United Stated
    • White House
    • News/Canada
    • News/Canada/Toronto
    • News/Canada/Montreal
    • News/World
    • News
  • World
    • All
    • Africa
    • Asia
    • England
    • Europe
    • Latin America
    • Middle East
    Matteo Salvini: ‘Sardines’ pack in for Rome protest

    Matteo Salvini: ‘Sardines’ pack in for Rome protest

    Heineken Champions Cup: Connacht score two late tries to snatch dramatic 27-24 win over Gloucester

    Heineken Champions Cup: Connacht score two late tries to snatch dramatic 27-24 win over Gloucester

    Sun-allergy man’s joy at window revamp

    Sun-allergy man’s joy at window revamp

    Somerset ‘strawberries and cream’ tree granted temporary protection

    Somerset ‘strawberries and cream’ tree granted temporary protection

    Car crashes into Tesco cafe in Sutton Coldfield

    Car crashes into Tesco cafe in Sutton Coldfield

    Hayling Island: Search for person in water after woman rescued

    Hayling Island: Search for person in water after woman rescued

    Trending Tags

    • News/World
  • Politics
    ‘Entirely appropriate’ for feds to weigh climate impacts of oilsands project: minister

    ‘Entirely appropriate’ for feds to weigh climate impacts of oilsands project: minister

    Cabinet’s mandate, if fulfilled, could offer a lot for northerners

    Cabinet’s mandate, if fulfilled, could offer a lot for northerners

    Alberta and Quebec have difference arguments for separation, says Bloc MP

    Alberta and Quebec have difference arguments for separation, says Bloc MP

    Conservatives focused on unity, says Candice Bergen

    Conservatives focused on unity, says Candice Bergen

    Jason Kenney has ‘no interest’ in leading federal Conservative party, supports Scheer

    Jason Kenney has ‘no interest’ in leading federal Conservative party, supports Scheer

    Don’t blame Trump: New study explores Canada’s surge in asylum-seekers

    Don’t blame Trump: New study explores Canada’s surge in asylum-seekers

    Trending Tags

    • Donald Trump
    • Election Results
    • United Stated
    • White House
    • Climate Change
    • News/Canada
    • News/Canada/Toronto
    • News/Politics
    • News/Canada/Ottawa
  • Business
    Switching broadband provider ‘could save £120’

    Switching broadband provider ‘could save £120’

    Desmarais brothers to retire as Power Corp. co-CEOs as company restructures

    Desmarais brothers to retire as Power Corp. co-CEOs as company restructures

    Volkswagen to plead guilty to Canadian environment charges, but case held up

    Volkswagen to plead guilty to Canadian environment charges, but case held up

    Check your train time – new timetables begin

    Check your train time – new timetables begin

    What the Conservatives’ win means for your money

    What the Conservatives’ win means for your money

    CN Rail workers being transferred across Canada twice in 1 year

    CN Rail workers being transferred across Canada twice in 1 year

    Trending Tags

    • News/Business
  • Science
    Climate change: UN talks in Madrid hit rough waters

    Climate change: UN talks in Madrid hit rough waters

    New Brunswick to move youth mental health centre to Moncton from Campbellton

    New Brunswick to move youth mental health centre to Moncton from Campbellton

    Why smaller may be better when it comes to harnessing Bay of Fundy tides

    Why smaller may be better when it comes to harnessing Bay of Fundy tides

    60 cubic-metre bags of trash collected from Great Pacific Garbage Patch arrives in Vancouver

    60 cubic-metre bags of trash collected from Great Pacific Garbage Patch arrives in Vancouver

    3rd B.C. seniors home owned by Chinese company fails standard of care, placed under health authority control

    3rd B.C. seniors home owned by Chinese company fails standard of care, placed under health authority control

    ‘No one should be embarrassed to call 988 for a mental health emergency,’ U.S. advocate says

    ‘No one should be embarrassed to call 988 for a mental health emergency,’ U.S. advocate says

    Trending Tags

    • Tech
      3 successful data analytics use cases

      3 successful data analytics use cases

      Top 5 ways Apple failed businesses in the 2010s

      Top 5 ways Apple failed businesses in the 2010s

      Going to the dark side: Should you consider becoming a consultant?

      Going to the dark side: Should you consider becoming a consultant?

      How to change an Excel conditional format on the fly

      How to change an Excel conditional format on the fly

      AWS outperforms rivals in test of cloud capabilities

      AWS outperforms rivals in test of cloud capabilities

      AR headset maker Magic Leap shifts to enterprise focus

      AR headset maker Magic Leap shifts to enterprise focus

      Trending Tags

      • Entertainment
        Chris Brown Shares New Photos of His Mini-Me Baby Son Aeko

        Chris Brown Shares New Photos of His Mini-Me Baby Son Aeko

        Chris Pratt and His Pigs Pay Tribute to Katherine Schwarzenegger on Her 30th Birthday

        Chris Pratt and His Pigs Pay Tribute to Katherine Schwarzenegger on Her 30th Birthday

        Curl up with 3 Indigenous book recommendations from author Richard Van Camp

        Curl up with 3 Indigenous book recommendations from author Richard Van Camp

        Parenting Her Way: Kourtney Kardashian’s Most Unforgettable Mom Moments

        Parenting Her Way: Kourtney Kardashian’s Most Unforgettable Mom Moments

        Kristin Cavallari’s Genius Spin on Elf on the Shelf Will Blow Your Mind

        Kristin Cavallari’s Genius Spin on Elf on the Shelf Will Blow Your Mind

        Evaluating the Solo Careers of One Direction After the Split

        Evaluating the Solo Careers of One Direction After the Split

        Trending Tags

        • Golden Globes
      • Sports
        • All
        • MLB Headlines
        • NBA Headlines
        • NFL Headlines
        Teal Harle takes home big air silver at World Cup

        Teal Harle takes home big air silver at World Cup

        Mikaë​​​​​​​l Kingsbury takes World Cup silver in Thaiwoo moguls

        Mikaë​​​​​​​l Kingsbury takes World Cup silver in Thaiwoo moguls

        Canada’s Max Parrot wins big air gold over Swede Sven Thorgren

        Canada’s Max Parrot wins big air gold over Swede Sven Thorgren

        Canadian women advance to quarter-finals at Cape Town 7s

        Canadian women advance to quarter-finals at Cape Town 7s

        Watch Grand Slam of Curling: Jennifer Jones vs. Eve Muirhead at The National

        Watch Grand Slam of Curling: Jennifer Jones vs. Eve Muirhead at The National

        Mikael Kingsbury takes World Cup silver in Thaiwoo moguls

        Mikael Kingsbury takes World Cup silver in Thaiwoo moguls

        Trending Tags

        • MotoGP 2017
        • Sports/Baseball/MLB
        • Sports/Hockey/NHL
        • Sports/Podcasts/Player's Own Voice
        • Sports/Football/NFL
        • Sports/Basketball/NBA
        • Sports/Rugby
        • Sports/Soccer/MLS
      • Home
      • NationalBreaking News
        ‘I am homesick’: She asked for photos of Yukon, and social media delivered

        ‘I am homesick’: She asked for photos of Yukon, and social media delivered

        Johnson keeps focus on election win and Brexit, not on regions opposed to leaving EU

        Johnson keeps focus on election win and Brexit, not on regions opposed to leaving EU

        From fourth place, Singh says he’d rather push Liberals than work with Tories

        From fourth place, Singh says he’d rather push Liberals than work with Tories

        Triumphant Boris Johnson heads to working class heartland to celebrate election win

        Triumphant Boris Johnson heads to working class heartland to celebrate election win

        Tragically Hip tribute band from Moose Factory translates lyrics into Cree

        Tragically Hip tribute band from Moose Factory translates lyrics into Cree

        Family of pilot killed in Gabriola Island crash says it is ‘absolutely devastated’

        Family of pilot killed in Gabriola Island crash says it is ‘absolutely devastated’

        Trending Tags

        • Donald Trump
        • United Stated
        • White House
        • News/Canada
        • News/Canada/Toronto
        • News/Canada/Montreal
        • News/World
        • News
      • World
        • All
        • Africa
        • Asia
        • England
        • Europe
        • Latin America
        • Middle East
        Matteo Salvini: ‘Sardines’ pack in for Rome protest

        Matteo Salvini: ‘Sardines’ pack in for Rome protest

        Heineken Champions Cup: Connacht score two late tries to snatch dramatic 27-24 win over Gloucester

        Heineken Champions Cup: Connacht score two late tries to snatch dramatic 27-24 win over Gloucester

        Sun-allergy man’s joy at window revamp

        Sun-allergy man’s joy at window revamp

        Somerset ‘strawberries and cream’ tree granted temporary protection

        Somerset ‘strawberries and cream’ tree granted temporary protection

        Car crashes into Tesco cafe in Sutton Coldfield

        Car crashes into Tesco cafe in Sutton Coldfield

        Hayling Island: Search for person in water after woman rescued

        Hayling Island: Search for person in water after woman rescued

        Trending Tags

        • News/World
      • Politics
        ‘Entirely appropriate’ for feds to weigh climate impacts of oilsands project: minister

        ‘Entirely appropriate’ for feds to weigh climate impacts of oilsands project: minister

        Cabinet’s mandate, if fulfilled, could offer a lot for northerners

        Cabinet’s mandate, if fulfilled, could offer a lot for northerners

        Alberta and Quebec have difference arguments for separation, says Bloc MP

        Alberta and Quebec have difference arguments for separation, says Bloc MP

        Conservatives focused on unity, says Candice Bergen

        Conservatives focused on unity, says Candice Bergen

        Jason Kenney has ‘no interest’ in leading federal Conservative party, supports Scheer

        Jason Kenney has ‘no interest’ in leading federal Conservative party, supports Scheer

        Don’t blame Trump: New study explores Canada’s surge in asylum-seekers

        Don’t blame Trump: New study explores Canada’s surge in asylum-seekers

        Trending Tags

        • Donald Trump
        • Election Results
        • United Stated
        • White House
        • Climate Change
        • News/Canada
        • News/Canada/Toronto
        • News/Politics
        • News/Canada/Ottawa
      • Business
        Switching broadband provider ‘could save £120’

        Switching broadband provider ‘could save £120’

        Desmarais brothers to retire as Power Corp. co-CEOs as company restructures

        Desmarais brothers to retire as Power Corp. co-CEOs as company restructures

        Volkswagen to plead guilty to Canadian environment charges, but case held up

        Volkswagen to plead guilty to Canadian environment charges, but case held up

        Check your train time – new timetables begin

        Check your train time – new timetables begin

        What the Conservatives’ win means for your money

        What the Conservatives’ win means for your money

        CN Rail workers being transferred across Canada twice in 1 year

        CN Rail workers being transferred across Canada twice in 1 year

        Trending Tags

        • News/Business
      • Science
        Climate change: UN talks in Madrid hit rough waters

        Climate change: UN talks in Madrid hit rough waters

        New Brunswick to move youth mental health centre to Moncton from Campbellton

        New Brunswick to move youth mental health centre to Moncton from Campbellton

        Why smaller may be better when it comes to harnessing Bay of Fundy tides

        Why smaller may be better when it comes to harnessing Bay of Fundy tides

        60 cubic-metre bags of trash collected from Great Pacific Garbage Patch arrives in Vancouver

        60 cubic-metre bags of trash collected from Great Pacific Garbage Patch arrives in Vancouver

        3rd B.C. seniors home owned by Chinese company fails standard of care, placed under health authority control

        3rd B.C. seniors home owned by Chinese company fails standard of care, placed under health authority control

        ‘No one should be embarrassed to call 988 for a mental health emergency,’ U.S. advocate says

        ‘No one should be embarrassed to call 988 for a mental health emergency,’ U.S. advocate says

        Trending Tags

        • Tech
          3 successful data analytics use cases

          3 successful data analytics use cases

          Top 5 ways Apple failed businesses in the 2010s

          Top 5 ways Apple failed businesses in the 2010s

          Going to the dark side: Should you consider becoming a consultant?

          Going to the dark side: Should you consider becoming a consultant?

          How to change an Excel conditional format on the fly

          How to change an Excel conditional format on the fly

          AWS outperforms rivals in test of cloud capabilities

          AWS outperforms rivals in test of cloud capabilities

          AR headset maker Magic Leap shifts to enterprise focus

          AR headset maker Magic Leap shifts to enterprise focus

          Trending Tags

          • Entertainment
            Chris Brown Shares New Photos of His Mini-Me Baby Son Aeko

            Chris Brown Shares New Photos of His Mini-Me Baby Son Aeko

            Chris Pratt and His Pigs Pay Tribute to Katherine Schwarzenegger on Her 30th Birthday

            Chris Pratt and His Pigs Pay Tribute to Katherine Schwarzenegger on Her 30th Birthday

            Curl up with 3 Indigenous book recommendations from author Richard Van Camp

            Curl up with 3 Indigenous book recommendations from author Richard Van Camp

            Parenting Her Way: Kourtney Kardashian’s Most Unforgettable Mom Moments

            Parenting Her Way: Kourtney Kardashian’s Most Unforgettable Mom Moments

            Kristin Cavallari’s Genius Spin on Elf on the Shelf Will Blow Your Mind

            Kristin Cavallari’s Genius Spin on Elf on the Shelf Will Blow Your Mind

            Evaluating the Solo Careers of One Direction After the Split

            Evaluating the Solo Careers of One Direction After the Split

            Trending Tags

            • Golden Globes
          • Sports
            • All
            • MLB Headlines
            • NBA Headlines
            • NFL Headlines
            Teal Harle takes home big air silver at World Cup

            Teal Harle takes home big air silver at World Cup

            Mikaë​​​​​​​l Kingsbury takes World Cup silver in Thaiwoo moguls

            Mikaë​​​​​​​l Kingsbury takes World Cup silver in Thaiwoo moguls

            Canada’s Max Parrot wins big air gold over Swede Sven Thorgren

            Canada’s Max Parrot wins big air gold over Swede Sven Thorgren

            Canadian women advance to quarter-finals at Cape Town 7s

            Canadian women advance to quarter-finals at Cape Town 7s

            Watch Grand Slam of Curling: Jennifer Jones vs. Eve Muirhead at The National

            Watch Grand Slam of Curling: Jennifer Jones vs. Eve Muirhead at The National

            Mikael Kingsbury takes World Cup silver in Thaiwoo moguls

            Mikael Kingsbury takes World Cup silver in Thaiwoo moguls

            Trending Tags

            • MotoGP 2017
            • Sports/Baseball/MLB
            • Sports/Hockey/NHL
            • Sports/Podcasts/Player's Own Voice
            • Sports/Football/NFL
            • Sports/Basketball/NBA
            • Sports/Rugby
            • Sports/Soccer/MLS
          No Result
          View All Result
          VTN News Networks
          No Result
          View All Result
          Home Tech

          How credential stuffing attacks work, and how to prevent them

          by VTN News Network
          November 29, 2019
          in Tech
          0
          How credential stuffing attacks work, and how to prevent them
          773
          SHARES
          12.9k
          VIEWS
          Share on FacebookShare on Twitter

          Credential stuffing attacks pose a significant risk to consumers and businesses. Learn how they work and what you can do about them.

          Hacking and phishing concept

          Image: peshkov, Getty Images/iStockphoto

          There’s no shortage of threats on the internet, which puts end users at risk and keeps cybersecurity and IT professionals busy. Credential stuffing is a such risk that can pose a great danger to consumers and business employees.

          SEE: Checklist: Security Risk Assessment (TechRepublic Premium download)

          More about cybersecurity

          I spoke with Sumit Agarwal, co-founder and COO of Shape Security, a cybersecurity organization about the concept. Agarwal served as deputy assistant secretary of defense under President Obama. 
           
          Scott Matteson: You came up with the term “credential stuffing” in 2011 when you were at the Pentagon. What is credential stuffing?

          Sumit Agarwal: That’s right. While serving as Deputy Assistant Secretary of Defense, I observed very complicated cyberattacks affecting publicly facing military websites. I realized it was only a matter of time before those attacks affected the average person’s online accounts. I termed these malicious attacks “credential stuffing.” 

          Credential stuffing is the weaponization of stolen credentials (usernames and passwords) against websites and mobile applications. Lists of credentials stolen from one website are tested against other websites’ login pages to gain unauthorized access to accounts, in order to commit fraud. 

          The most remarkable aspect of credential stuffing is that a given business does not have to be breached itself to suffer from credential stuffing. The vulnerability is simply having a login form and having users.

          There are more than 15 billion stolen credential pairs in the hands of cybercriminals. Criminals can either steal credentials themselves or, more likely, purchase them on the Dark Web. 

          Scott Matteson: How does it work?

          Sumit Agarwal: Most consumers reuse usernames and passwords across different web and mobile applications. This is capitalized upon for credential stuffing purposes.
           
          First, let’s discuss the root cause of the problem: Consumers are drowning in security complexity. After many, many years of advice around password complexity (uppercase, lowercase, numbers, special characters, etc.) consumers have responded by selecting just a few passwords that meet all those complexity requirements, and then re-using those passwords across many websites. 
           
          Although this practice is terrible from a security perspective, it’s understandable. When large businesses ask too much of consumers, they react by finding ways to simplify their lives. So this is the backdrop for credential stuffing—lots of password complexity, lots of consumers who are surviving by crafting a few conforming passwords and then reusing them across more than 30 accounts on average.

          Next, it’s important to understand that credential stuffing and other automation attacks against web and mobile applications are an economic pursuit for cybercriminals. They operate like businesses, striving for specific profit margins, and there’s an entire underworld industrial complex that has been developed to support their criminal attacks. 

          Credential stuffing is a volumetric attack: The attackers know they will enjoy success rates of upwards of 1 in 100 (which may sound low to the average person, but if you multiply by 10M attempted credentials, yields 10,000 successful account takeovers, which are worth easily $100 to $1,000 each). 

          To serve the economic objectives of the criminal attackers, the criminal industrial complex has developed three elements that power their attacks:

          • Inexpensive credentials, typically stolen through large-scale data breaches, and then sold to criminals on the Dark Web. In January 2019, billions of stolen credentials were posted on the Dark Web for free download in a cache called Collections 1 through 5.

          • Purpose-built attacker tools, or repurposed QA tools that automate the process of machine-gunning login credentials at web and mobile applications. Sample credential-stuffing toolkits include Sentry MBA, Wget, cURL, PhantomJS, Selenium and Sikuli. Most attack toolkits are free or very low cost, and also offer pre-built configuration files that tailor attacks for specific popular sites and apps for as little as $50 per site. 

          • Botnets and other simulated network infrastructure, so that attack traffic appears to originate organically from real users across a “normal” geographic area (say, the Western United States), instead of all from one IP address in the Ukraine or the Philippines.

          The automation provided by these components is key to the criminal economic model for credential stuffing.

          Shape defeats the economics for cybercriminals, making credential stuffing and other automation attacks prohibitively expensive for criminals to sustain on protected websites and mobile applications.

          Scott Matteson: What are the goals and motivations behind it?

          Sumit Agarwal: Economic gain through theft, fraud, and deception. One study estimates that cybercrime revenues hit $1.5 trillion in 2018. This is an entire shadow economy larger than many legitimate nation-states.

          Scott Matteson: Where is this threat most prevalent?

          Sumit Agarwal: As an economic endeavor, cybercriminals attack where the money is. The threats are most prevalent in large B2C verticals, including financial services, retail and ecommerce, travel and hospitality, telecommunications, media, government, social media, and entertainment.

          Scott Matteson: Who is behind the threat?

          Sumit Agarwal: Cybercriminals are behind the threat. Typically these criminals operate outside of the United States, with prevalence in the developing world.

          Scott Matteson: How should companies protect themselves from it?

          Sumit Agarwal:  Here are four things companies can do immediately to protect themselves:

          1. Realize that you likely are at risk—or already under attack—if your web or mobile applications provide an opportunity to buy or exchange anything of value. 

          2. Monitor your business metrics for signs that you may already be experiencing credential stuffing or other automation attacks, including poor or declining login success rates, high password reset rates, or low traffic-to-success conversion rates. 

          3. Analyze the hourly pattern of traffic to your login and other attackable URLs for traffic spikes or volume outside of normal human operating hours for your markets: Real users sleep, automated attacks do not.

          4. Get infosecurity, fraud, and digital teams in a room to discuss the possibility of automation attacks, current fraud trends, and digital metrics. 

          Cybersecurity Insider Newsletter

          Strengthen your organization’s IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered Tuesdays and Thursdays

          Sign up today

          Also see

          VTN News Network

          VTN News Network

          Next Post
          A BOOTquet of questions with alpine skier Erik Read

          A BOOTquet of questions with alpine skier Erik Read

          Latest News

          ‘I am homesick’: She asked for photos of Yukon, and social media delivered

          ‘I am homesick’: She asked for photos of Yukon, and social media delivered

          1 hour ago
          Climate change: UN talks in Madrid hit rough waters

          Climate change: UN talks in Madrid hit rough waters

          2 hours ago

          Top News

          • Patrick Reed’s caddie says he shoved fan at Presidents Cup

            Patrick Reed’s caddie says he shoved fan at Presidents Cup

            774 shares
            Share 310 Tweet 194
          • Key takeaways from Day 3 of the Trump impeachment testimony

            773 shares
            Share 309 Tweet 193
          • Vancouver police discriminated against Indigenous mother, B.C. rights tribunal rules

            773 shares
            Share 309 Tweet 193
          • Survey: Employees with more tech skills needed by 80% of companies

            774 shares
            Share 310 Tweet 194
          • Brexit: What happens now?

            774 shares
            Share 310 Tweet 194

          Latest News

          • Business
          • Entertainment
          • National
          • Politics
          • Science
          • Sports
            • MLB Headlines
            • NBA Headlines
            • NFL Headlines
          • Tech
          • World
            • Africa
            • Asia
            • England
            • Europe
            • Latin America
            • Middle East

          About Us

          VTN News Networks is the world leader in online news and information and seeks to inform, engage and empower the world. Staffed 24 hours, seven days a week by a dedicated team

          • Business
          • National
          • Politics
          • Sports
          • Tech
          • World

          © 2014 | 3.1 Version | VTN News Network International | By M9 Engineering Group Inc.

          No Result
          View All Result
          • Home
          • National
          • World
          • Politics
          • Business
          • Science
          • Tech
          • Entertainment
          • Sports

          © 2014 | 3.1 Version | VTN News Network International | By M9 Engineering Group Inc.