Open cardosec

Case 8D264A · Web AppSec · L2 Practitioner

Login Spike from 4,000 IPs

Practise as: Incident drill · Interview

Live alertAt 22:05 the login API jumps from 200 to 18,000 requests per minute across 4,000 residential IPs, with a 1.5% success rate on distinct usernames.

Interview questionHow do you tell credential stuffing from a brute-force attack, and how do you respond?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Many usernames, few attempts each, low but non-zero success rate = credential stuffing with breached password lists
  2. Immediate: bot management or rate limits keyed on device fingerprint and ASN, not just IP; step-up CAPTCHA/MFA
  3. Identify successful logins in the window and force password reset plus session revocation for those accounts
  4. Watch post-login abuse: changed emails, added payment methods, gift card redemption, API token creation
  5. Long term: MFA/passkeys, breached-password checks at login and signup, and anomaly-based login risk scoring

If the interviewer pushes back

  • Residential proxy traffic defeats IP reputation. What signals would you use instead?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.