About this interactive
Six names for password attacks sound like six unrelated tricks. They are really answers to two questions: where did the guesses come from, and what stayed fixed while they were tried? Start with the lesson's first split. A password is either known or guessed, and every bin here except one is some form of guessing. Brute force is guessing with no shortcut at all — every combination, in order, against one account. It always succeeds eventually, which is why the lesson keeps coming back to length. Password spraying turns brute force around. Instead of many passwords against one username, it tries one password against many usernames, often a default like a new-hire password nobody changed. That is where most wrong answers land, because both are "lots of failed logins". Ask which part stayed the same. If the account is fixed and the password changes, it is brute force or a dictionary attack; if the password is fixed and the account changes, it is spraying. A dictionary attack is brute force with a list: real words, word pairs, or the most common passwords, all aimed at one account. The list is the shortcut — it skips the billions of random strings nobody chooses. Credential stuffing and mask attacks both start from a password that has already leaked, which makes them easy to confuse. Credential stuffing takes the exact username-and-password pair from one breach and tries it, unchanged, on other sites. It works only because people reuse passwords. A mask attack does not reuse the old password; it studies its shape — a word plus a year, a prefix plus the site's name, a capital then lowercase then digits — and guesses the next step. Tigers2023! tried at the bank is stuffing; Tigers2026! tried at work is a mask. The rainbow table is the odd one out, because it happens nowhere near a login page. When a stolen database holds hashes rather than plain passwords, the attacker cannot run the hash backwards, so they use a table of passwords hashed in advance and simply look the stolen hashes up. It cracks short, common passwords instantly and finds nothing for a long passphrase nobody thought to precompute. One honest caveat: the lesson calls spraying a type of brute force, and a dictionary attack is one too. Brute force is the family name. This activity asks for the most specific name that fits, so when a scenario has a list, a fixed password, a leaked pair or a pattern, that detail decides the bin.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →