I keep seeing tables of how easy it is to brute force a password depending on length and complexity, but how does the brute force attack get past the account lockout feature?

650 views

Every system I’ve ever maintained has an account lockout after a few attempts.

In: 2

18 Answers

Anonymous 0 Comments

Brute force password hacks are usually piggybacking off of a database hack. Somehow, the database of password hashes got leaked, and is now available to run on another machine. That other machine has no account lock timers on it, so you can try as many passwords as you want. Either that, or there is some vulnerability that prevents the locks from happening, like the one on iPhone 5 and earlier.

You are viewing 1 out of 18 answers, click here to view all answers.