|
|
|
|
|
by tetha
871 days ago
|
|
Offline vs online brute forcing, as I like to call it. As others have said, if you have the hashes, you can brute force them offline and there won't be any limits on how fast it can go besides your algorithms and compute resources. But even online, attackers can be pretty smart. For example, something we detected was an attacker rotating both through a bunch of accounts and a bunch of IP addresses. That way you never saw many incorrect login tries per account and IP in a timeframe. It's not millions/billions of tries, but it can get around naive limits per IP or per account and you need some SIEM tooling to detect that. |
|
Saying "there's no limit besides your resources" is basically saying "there's no limit besides the very real and insurmountable limit there is".