What Is a Brute Force Attack?
A brute force attack is a method used by attackers to gain unauthorised access to an account, system, or encrypted data by systematically trying every possible password or key until the correct one is found. The name comes from the blunt, forceful nature of the approach — no elegance, no subtlety, just computational power applied repeatedly until something works.
Modern brute force attacks are not done by hand. Automated tools like Hydra, Medusa, Burp Suite Intruder, and custom scripts can attempt thousands to millions of password combinations per minute, often running from multiple IP addresses simultaneously to avoid detection.
How a Brute Force Attack Works
**Pure brute force** — the simplest form. The attacker tries every possible character combination: a, b, c... aa, ab, ac... This becomes computationally impractical for long passwords but is effective against short or simple ones. An 8-character password using only lowercase letters has 208 billion combinations — a modern GPU can exhaust this in hours.
**Dictionary attack** — rather than trying every possible combination, the attacker uses a wordlist of common passwords, dictionary words, and known compromised passwords from previous breaches. Lists like RockYou (14 million passwords from a real breach), SecLists, and custom wordlists make dictionary attacks far faster than pure brute force. "password123", "qwerty", "letmein", and "admin" are tested within the first few seconds of any dictionary attack.
**Credential stuffing** — the attacker uses real username/password pairs from previously leaked data breaches. If you used the same password on two sites and one of them was breached, an attacker may try those credentials against every other site you are likely to use. This is not guessing — it is using your actual credentials from a different breach. Billions of credential pairs are available on dark web marketplaces and free breach databases.
**Password spraying** — instead of trying many passwords against one account (which triggers lockouts), the attacker tries one common password against thousands of different accounts. This avoids account lockout mechanisms while still compromising accounts with weak passwords.
**Reverse brute force** — the attacker starts with a known common password and tries it against multiple usernames, rather than the other way around.
What Attackers Target With Brute Force
**Login pages** — any login form that does not limit attempts is vulnerable. WordPress admin pages (/wp-admin), cPanel, Plesk, and custom login forms are constant targets.
**SSH and RDP** — servers with exposed SSH (port 22) or Remote Desktop Protocol (port 3389) are attacked continuously. Automated scanners probe the entire IPv4 address space looking for exposed services and immediately begin brute forcing them.
**Admin panels** — database admin tools (phpMyAdmin), CMS admin areas, router interfaces, and management portals with weak credentials are common targets.
**API endpoints** — authentication APIs that do not implement rate limiting can be brute forced to validate credential lists or discover valid usernames.
**Encrypted files and archives** — ZIP files, PDF documents, and encrypted drives can be subjected to offline brute force attacks where there is no lockout mechanism to slow the attacker down.
Why Brute Force Attacks Still Work
Despite being a decades-old technique, brute force attacks remain effective because:
**People use weak passwords** — "123456", "password", "qwerty", and "admin" are still among the most common passwords found in every breach dataset. If even a small percentage of a site's users have weak passwords, credential stuffing and dictionary attacks will find them.
**Sites do not implement rate limiting** — many websites, especially small business sites built on WordPress or custom frameworks, do not limit the number of login attempts per IP address or per account. Without rate limiting, an attacker can attempt thousands of passwords per minute with no consequence.
**Credentials are reused across sites** — the average person uses the same password across multiple accounts. One breach anywhere in the chain compromises everywhere else.
**Account lockouts are not universal** — even where lockouts exist, they are often only applied per-account, not per-IP. An attacker using password spraying — one password, many accounts — bypasses per-account lockouts entirely.
How to Detect a Brute Force Attack
Signs that a brute force attack may be underway:
- Sudden spike in failed login attempts in your server logs - Multiple failed logins from the same IP address or range of IPs - Failed logins for usernames that do not exist on your system (attacker is guessing usernames) - Slow site performance caused by the volume of requests to your login endpoint - Alerts from your security plugin (Wordfence, Solid Security) about blocked login attempts
How to Protect Your Website Against Brute Force Attacks
**Rate limiting** — limit login attempts to a maximum of five per minute per IP address, with exponential back-off after repeated failures. This alone eliminates most automated attacks.
**Account lockout** — after a defined number of failed attempts (typically five to ten), lock the account temporarily and require email verification or CAPTCHA to continue.
**CAPTCHA on login forms** — Google reCAPTCHA, hCaptcha, or Cloudflare Turnstile add a human-verification step that automated tools cannot complete without significant additional effort.
**Multi-factor authentication (MFA)** — even if an attacker guesses the correct password, MFA requires a second factor (a code from an app, an SMS, a hardware key) that the attacker does not have. Implementing MFA on admin accounts is one of the highest-impact security steps any website owner can take.
**Strong, unique passwords** — enforce a minimum password length of twelve characters. Use a password manager to generate unique credentials for every site and service.
**IP allowlisting for admin panels** — restrict access to /wp-admin, cPanel, or your application's admin interface to specific IP addresses or ranges. An attacker cannot brute force a login page they cannot reach.
**Fail2Ban or equivalent** — server-level tools like Fail2Ban automatically detect repeated failed authentication attempts and block the offending IP at the firewall level.
**Change default usernames** — the WordPress username "admin" and default database credentials are the first things automated tools try. Change them on all systems.
**Monitor and alert** — configure logging to alert you when there are unusual numbers of failed authentication attempts. The faster you detect an attack, the faster you can block it.
Yrzo AI and Brute Force Protection Testing
Yrzo AI's automated security scan includes rate limiting checks as part of its 44-check assessment. It tests whether your login endpoints respond differently to repeated rapid requests — a key indicator of whether brute force protection is in place.
If your site has no rate limiting on its login page, Yrzo AI will flag it, explain the risk in plain English, and tell you exactly what to do to fix it. A scan takes under 20 minutes and starts at £99.
Brute force attacks are unsophisticated but effective against unprepared targets. The defences — rate limiting, MFA, strong passwords — are straightforward to implement and dramatically reduce your exposure.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →