From Error to Entry: Cracking the Code of Password-Spraying Tools
ID: c4f54192-0d20-5b54-9b66-0de90408f7fc
STIX ID: report--c4f54192-0d20-5b54-9b66-0de90408f7fc
Feed Name: TrustedSec blog
This blog post describes how the author discovered during an engagement that the AADSTS50079 error returned by Microsoft Entra (Azure AD) indicates a user must complete MFA enrollment, not merely that MFA is enabled; attackers (or testers) can exploit this behavior during password-spraying to onboard MFA and gain access. The post compares how popular Office 365 password-spraying tools handle AADSTS error codes, demonstrates the security impact of misinterpreting AADSTS50079, and lists pull requests submitted to tooling to correct the handling of these error codes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
