skip to content

Spraying and Stuffing

Brute force, spraying, stuffing and corpus replay differ by what the operator already knows, not by how fast they go. Interviewers ask because the wrong model buys the wrong control every time.

on this pageshow

explore

questions

4

What separates credential stuffing from password spraying, and what does each operator already know?

level: juniorimportance: must knowfreq 78%

answer

  1. start from what the operator holds
  2. a corpus of real pairs, or nothing
  3. wide in sites versus wide in accounts
  4. reuse versus policy predictability
  5. one exact pair each, one guess each

basics

~10 s

Stuffing replays real username-and-password pairs stolen from other sites and bets on reuse. Spraying knows no password at all: it tries one likely guess, such as Autumn2026!, against every account in a directory.

solid answer

~50 s

Both end in a working sign-in that broke nothing, but they start from opposite kinds of knowledge. Credential stuffing starts from a corpus: real `address:password` pairs aggregated from other organisations' breaches, replayed against your login on the bet that people reuse. It is exact in credentials and wide in sites, hit rates are typically a fraction of a percent, and the operator profits by replaying millions of pairs. Password spraying starts from an address list only: the operator holds no password for anyone, so it picks one or two guesses a policy is likely to have produced, such as `Winter2026!` or the company name plus a digit, and tries each against every account once. It is wide in accounts and shallow in attempts per account. That difference decides which change bites: stuffing dies when the corpus stops matching your accounts, spraying dies when the single guess stops being likely.

go deeper

for a junior

Be ready to define both in one sentence each and say what the operator holds before the first request: real stolen pairs for stuffing, only an address list for spraying.

for a middle

Explain why the two need different countermeasures, and why a per-account attempt counter is aimed at neither. Expect to be pushed on hit rates and why a tiny one is still worth running.

for a senior

Show that you classify an observed pattern correctly before recommending anything, and that you can say which change actually removes each attack rather than taxing it.

for a principal

Own the framing that credential guessing is an economics problem, not a policy-checkbox problem, and that reuse imported from other organisations is a risk you inherit whatever your own history looks like.

## Two attacks that share an outcome and nothing else Credential stuffing and password spraying both end with an attacker holding a valid sign-in obtained without exploiting a single software flaw. That shared ending is why they get lumped together as "brute force", and why the lumping is the wrong-answer this question exists to catch. The two differ on the one axis that determines everything else: **what the operator already knows before the first request**. ## Credential stuffing: the operator knows real pairs A stuffing operator starts with a corpus — a list of `address:password` pairs recovered from other organisations' breaches, aggregated over years, deduplicated and sold or traded cheaply. Nothing in that corpus came from you. The operator replays those exact pairs against your login and profits from one human habit: password reuse across sites. Characteristics that follow directly: - **Each account is attempted with the credential that account's owner actually used somewhere.** There is no guessing, so complexity rules are irrelevant — the pair already satisfies whatever rule produced it. - **The hit rate is low and that is fine.** Typical published rates sit well under one percent. The run is economic because the input is near-free and the operator's unit of profit is a valid session, not a percentage. - **A site that has never been breached is fully exposed.** This is the single most common misconception. The corpus is other people's data plus your users' reuse; your own storage was never involved. ## Password spraying: the operator knows nobody's password A spraying operator starts with an address list — harvested from public directory structures, published email formats (`[email protected]`), or a leaked employee roster — and no password at all. It must therefore *guess*, and the guess is not random. It is drawn from the short list of strings a password policy predictably generates: a season or month plus the year plus one punctuation mark, the company name plus digits, the classic keyboard walks. Characteristics that follow: - **One or two attempts per account, then move on.** The attempt budget per account is deliberately kept below any lockout threshold, and successive rounds are spaced past the counter's reset window. - **The attack scales in accounts, not in guesses.** With one guess against ten thousand accounts, the operator needs only one person in ten thousand to have chosen it. - **Complexity rules help the operator.** They narrow the plausible space and push humans onto a template. A policy demanding an uppercase letter, a digit and a symbol makes `Autumn2026!` a better guess than it would otherwise be. ## Where classic brute force sits The third member of the family is the one people picture: many guesses against **one** account. Against a live login this is the weakest of the three, because a per-account attempt counter bounds it exactly. It becomes serious only offline, against stolen password hashes, where no counter exists and guessing is limited by compute alone — a different game with a different set of defences. ## The comparison in one table | | Brute force | Stuffing | Spraying | |---|---|---|---| | Operator holds | nothing | real pairs from other breaches | an address list | | Breadth | one account, many guesses | many accounts, one exact pair each | many accounts, one guess each | | Beaten by | per-account attempt counter | making your accounts absent from the corpus | making the guess unlikely (length, screening) | | Needs your site breached | no | no | no | ## Why interviewers ask this first Because the classification predicts the control. A candidate who says "both are brute force, and lockout handles brute force" has given the wrong answer twice: lockout bounds guesses per account, stuffing does not need more than one guess per account, and spraying deliberately stays under the threshold. Getting the taxonomy right is the precondition for pricing either attack correctly.

  • Where does classic brute force sit next to these two?
    Many guesses against one account. Against a live login it is the weakest of the three, because a per-account attempt counter bounds it precisely. It matters offline, against stolen password hashes, where no counter exists and only compute limits the guessing. Stuffing and spraying exist precisely because they route around that counter rather than fighting it.
  • Your organisation has never been breached. Does that reduce its exposure to stuffing?
    No. The corpus is assembled from other organisations' dumps, and the vulnerability is your users' reuse of a password they chose somewhere else. Your storage, your hashing and your breach history are all irrelevant to whether a replayed pair is accepted. The only thing that matters is whether the password now sitting on your account also appears in the corpus.
  • Why would an operator prefer spraying when it holds no passwords, rather than buying a corpus?
    Because a corpus of consumer pairs rarely covers a specific corporate directory, and matching addresses to employees is extra work. Spraying needs only the address format and one policy-shaped guess, both of which are effectively free, and it reaches every account in the estate including ones no consumer breach ever touched.

Stuffing is trying one stolen key in every door on the street. Spraying is trying the one key shape most doors in this building were cut to, once per door.

saying these in an interview costs you the question

  • Calls both attacks brute force and stops there
  • Thinks spraying means many guesses against one account
  • Assumes a stuffing hit requires the target itself to be breached
  • Believes a hit rate under one percent means the run failed
  • Says complexity rules make spraying harder

context

open as a page

Why doesn't a five-attempt account lockout stop a password spray across 8,000 accounts?

level: middleimportance: must knowfreq 72%

basics

~10 s

The counter is per account; the spray is per estate. One guess against each of 8,000 accounts leaves every counter at one, and the reset window clears it long before a second guess arrives.

open as a page

Why does 90-day rotation with complexity rules make passwords easier to guess, not harder?

level: middleimportance: should knowfreq 62%

basics

~10 s

A human forced to invent a compliant password four times a year converges on a template: a season, the year, one capital, one symbol. That template is a short candidate list to spray.

open as a page

A credential-stuffing run converts 0.2% of pairs into logins — why is that profitable, and what kills it?

level: seniorimportance: should knowfreq 45%

basics

~20 s

Because the corpus is nearly free and each valid session resells. Two thousand hits from a million pairs clears the proxy and challenge-solving bill. Only shrinking how many of your accounts appear in that corpus changes the arithmetic.

open as a page