Question: What Can I Learn from Password Spraying a 2FA Microsoft Web App Portal?
ID: c53ce139-5f20-5539-9555-20245adfe8d6
STIX ID: report--c53ce139-5f20-5539-9555-20245adfe8d6
Feed Name: Black Hills Infosec Blog
Threat Score
This report demonstrates a penetration test against Outlook Web App with Microsoft MFA where attackers can perform password spraying to (1) enumerate valid usernames via response timing differences and (2) detect when a guessed password is correct because the server returns a distinguishable response despite MFA. The findings highlight an implementation weakness that enables credential validation and account discovery, which can be leveraged for follow-on attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
