• Attackers crack weak passwords by guessing, using default user credentials, tools and techniques

Weak Password Attack Prevention

  1. Mandate web application that accepts only increased length of user ID credentials, especially password
  2. Mandate passwords to be at least 6 characters long with a combination of uppercase and lowercase letters, digits, and special characters
  3. Impose a password aging policy
  4. Incorrect authentication failure messages should be avoided
  5. Implement account lockout policy
  6. Highly critical applications need multi-factor authentication