Dictionary attack

A password-guessing attack that tries entries from a prepared list of likely passwords, such as common choices, words and leaked values, instead of every possible combination.

A dictionary attack guesses passwords by working through a list of candidates chosen because people are likely to use them: common passwords, words, names and values leaked in earlier breaches. A brute-force attack tries every combination and, given enough time, finds any password; a dictionary attack tries far fewer guesses and finds only passwords on or near its list, which is where many weak passwords are.

The controls depend on the setting. Online, against a live login, it is slowed by rate limiting, account lockout and a clipping level that flags repeated failures. Offline, against a stolen file of password hashes, the storage method is the main defence. NIST SP 800-63B-4 section 3.1.1.2 requires stored passwords to be salted and hashed with a password hashing scheme that has a cost factor, which makes each guess expensive and precomputed tables of little use. The same section requires new passwords to be checked against a blocklist that may include dictionary words, removing the easiest targets before they are chosen.

Exam relevance: a scenario is likely to describe guesses drawn from a word list, or a stolen hash file, and ask for the attack or the control. Candidates are expected to separate it from brute force, password spraying and credential stuffing, and to match salting and slow hashing to the offline case.