← Back to list
● General attack technique · leaked-password reuse (credential stuffing)

I reproduced credential stuffing exactly,
and I'm publishing the code that stops it

Credential stuffing — trying passwords leaked from other services against this login — exploits the basic weakness of a system where a matching password alone is enough. I reproduced it and verified, with the real open-source pentesting tool hydra, how MFA stops it.

See live demo → Jump to code

Who this is for

A learning resource for backend developers building login systems that assume a matching password alone is enough.

OWASP #7
Roughly where broken authentication (including credential stuffing) ranks on the OWASP API Security Top 10
hydra
Attack reproduced and verified with hydra, a real pentesting tool with 10k+ GitHub stars
$0
What this code costs right now — free

Code — password-only-login.js

A vulnerable login API that authenticates on a matching password alone.

password-only-login.js
// Vulnerable login API — a matching password is the whole check.
// A leaked-password list from another breach, tried here as-is,
// gets through (verified directly with hydra).
class PasswordOnlyLogin {
  constructor(userDb) {
    this.db = userDb; // { username: password }
  }

  login(username, password) {
    if (this.db[username] === password) {
      return { status: 'ok' };
    }
    return { status: 'invalid_credentials' };
  }
}

module.exports = { PasswordOnlyLogin };

Code — mfa-guard.js

The fix: a matching password alone is no longer enough without a valid second factor.

mfa-guard.js
// The fix: BOTH the password AND a second factor (TOTP-style) are
// required. Even a 100% correct leaked password is useless to an
// attacker who doesn't have the code that changes in real time.
class MfaGuardedLogin {
  constructor(userDb, totpProvider) {
    this.db = userDb;
    this.totp = totpProvider; // .currentCode(username)
  }

  login(username, password, totpCode) {
    if (this.db[username] !== password) {
      return { status: 'invalid_credentials' };
    }
    if (totpCode !== this.totp.currentCode(username)) {
      return { status: 'invalid_credentials' }; // never reveal which part was wrong
    }
    return { status: 'ok' };
  }
}

module.exports = { MfaGuardedLogin };

Price

Free (for now)
A deeper version (account lockout, anomaly detection) ships later — pay-what-you-want, starting at $0.
goalsgo7574@gmail.com
This isn’t a purchase — just email me "notify me about the paid version" and I’ll reach out when it ships.
Note: This is a scaled-down learning implementation. A real system also needs account lockout, rate limiting, and anomaly detection.

Leave feedback

Questions or feedback about this product? Leave your email if you'd like a reply (optional).