Credential stuffing is an attack in which stolen username and password pairs are tried automatically against a website’s login form to take over accounts.
It works because people reuse passwords. A list leaked from one site is replayed against many others, usually by scripts or headless browsers, and spread across many IP addresses through proxies so that per-IP rate limits do not trigger. Even a small success rate on a large list means many taken-over accounts.
How do you defend against credential stuffing?
Defences work best in layers:
- Bot detection on the login route, verified on your server.
- Network reputation: datacenter, proxy, VPN and Tor addresses, and addresses on attack blocklists.
- Rate limits per account and per network, not only per IP address.
- Multi-factor authentication, and refusing passwords known to be breached.
How Hextner uses it
On a login route, verify a DetectBT token on your server and treat the route as sensitive: refuse a bot verdict or a forged token, refuse an expired token, and a missing one unless DetectBT's own health check shows it is down, and accept each token once by recording its jti. From the same handler, call VerifIP's /v1/check for the address's verdict, its proxy, VPN, Tor and datacenter flags, and its attack-feed listings. The DetectBT decision table lists every case.
Related reading
Browse every definition in the glossary.