1. Executive Summary & Scope
Credential stuffing is the automated injection of breached username/password pairs into website login forms. Attackers capitalize on user password reuse across services to hijack accounts. Without intelligent adaptive lockouts and bot detection, attackers achieve substantial takeover rates.
2. Threat Model & Attack Vectors
Botnets test millions of breached credentials across public login endpoints, locking out legitimate users through naive account lockout or successfully compromising unmonitored accounts.
3. Code Analysis & Remediation Playbook
Vulnerable Implementation Pattern
Hardened Defense-in-Depth Implementation
4. Audit Verification Checklist & Pass Criteria
| Verification Phase | Audit Test Description | Mandatory Passing Criteria |
|---|---|---|
| Automated Dictionary Fuzzing | Send 20 incorrect password attempts against a target account within 30 seconds. | System locks account after 5 failed attempts and triggers security notification email. |
| Distributed IP Attack Simulation | Simulate login attempts against single account across 10 distinct IP addresses. | Account-level lockout triggers regardless of IP rotation. |
| Timing Uniformity Check | Measure response latency for non-existent users versus valid users with wrong password. | Timing difference is below 20ms, preventing username enumeration. |
WebOTG Application Security Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.