Password Brute force - Attempting to login using the same password for all user profiles.
We have just been audited by an external company. One of their security intrusion tests involved using the same password to log in to every user profile.
One particular password was able to log in to 7 different accounts.
Are there any methods being used to prevent this type of brute force attack?
0