TechKnowSurge
CompTIA Security+ 2.4 CompTIA A+ Core 2 2.4 CompTIA Tech+ 6.5
InteractiveSecurityFree

Password Attack Identifier

Sort realistic password attack scenarios into Brute Force, Password Spraying, Dictionary Attack, Credential Stuffing, Rainbow Table, or Mask Attack.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Six names for password attacks sound like six unrelated tricks. They are really answers to two questions: where did the guesses come from, and what stayed fixed while they were tried? Start with the lesson's first split. A password is either known or guessed, and every bin here except one is some form of guessing. Brute force is guessing with no shortcut at all — every combination, in order, against one account. It always succeeds eventually, which is why the lesson keeps coming back to length. Password spraying turns brute force around. Instead of many passwords against one username, it tries one password against many usernames, often a default like a new-hire password nobody changed. That is where most wrong answers land, because both are "lots of failed logins". Ask which part stayed the same. If the account is fixed and the password changes, it is brute force or a dictionary attack; if the password is fixed and the account changes, it is spraying. A dictionary attack is brute force with a list: real words, word pairs, or the most common passwords, all aimed at one account. The list is the shortcut — it skips the billions of random strings nobody chooses. Credential stuffing and mask attacks both start from a password that has already leaked, which makes them easy to confuse. Credential stuffing takes the exact username-and-password pair from one breach and tries it, unchanged, on other sites. It works only because people reuse passwords. A mask attack does not reuse the old password; it studies its shape — a word plus a year, a prefix plus the site's name, a capital then lowercase then digits — and guesses the next step. Tigers2023! tried at the bank is stuffing; Tigers2026! tried at work is a mask. The rainbow table is the odd one out, because it happens nowhere near a login page. When a stolen database holds hashes rather than plain passwords, the attacker cannot run the hash backwards, so they use a table of passwords hashed in advance and simply look the stolen hashes up. It cracks short, common passwords instantly and finds nothing for a long passphrase nobody thought to precompute. One honest caveat: the lesson calls spraying a type of brute force, and a dictionary attack is one too. Brute force is the family name. This activity asks for the most specific name that fits, so when a scenario has a list, a fixed password, a leaked pair or a pattern, that detail decides the bin.

What you'll learn

Aligned to

CompTIA Security+
2.4 Given a scenario, analyze indicators of malicious activity.
CompTIA A+ Core 2
2.4 Explain common social-engineering attacks, threats, and vulnerabilities.
CompTIA Tech+
6.5 Explain password best practices.

Key terms

Brute Force Attack
An attack method that systematically tries all possible combinations of passwords or keys until the correct one is found.
Password Spraying
An attack that attempts a single commonly used password against many different user accounts before moving to the next password, deliberately staying below account lockout thresholds to avoid detection.
Dictionary Attack
A type of brute force attack that uses a predefined list of common words and phrases to guess passwords.
Credential Stuffing
An automated attack in which stolen username and password pairs from one breached service are systematically tested against other services to gain unauthorized access. It exploits users who reuse passwords across multiple accounts.
Rainbow Table
A precomputed lookup table used to reverse cryptographic hash functions, allowing attackers to recover plaintext passwords from stolen hashed credentials. Rainbow table attacks are defeated by adding a unique salt to each password before hashing.
Mask Attack
A password cracking technique that exploits known patterns in passwords — such as a capital letter followed by lowercase letters and ending in numbers — to dramatically narrow the search space compared to a full brute-force attempt.
Password Reuse
The poor security practice of using the same password across multiple accounts, increasing exposure if one account is compromised.
Default Password
A generic, preset password assigned to a device or account during setup that has not been changed by the user, representing a significant security vulnerability.
Data Breach
An incident in which protected or sensitive data is accessed, stolen, or disclosed without authorization, typically triggering legal notification requirements.
Hash Function
A mathematical algorithm that converts input data of any size into a fixed-size output value used to verify data integrity.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →