Broken Authentication - Username Enumeration via Account Lock

  Рет қаралды 447

z3nsh3ll

z3nsh3ll

Күн бұрын

Support This Channel
======================
Please like and subscribe, it means a lot!
Please buy me a coffee so I can continue to make content.
buymeacoffee.c...
My cybersec and webdev training site
www.zenshell.n...
Join our Discord
/ discord
This lab will lock accounts after too many failed login attempts. Although login is prevented, the app still provides different responses depending on whether the username is valid and whether the password is correct. This allows for both username enumeration and brute forcing of the password despite the account in question technically being locked for logins.

Пікірлер: 3
@alex-v7e6v
@alex-v7e6v 8 ай бұрын
probably the best educational channel I've ever seen. Hard to explain with words how cool this is. Thank you very very much
@GilligansTravels
@GilligansTravels 6 ай бұрын
do you have the script for that handy for share?
To Brawl AND BEYOND!
00:51
Brawl Stars
Рет қаралды 17 МЛН
Sigma Kid Mistake #funny #sigma
00:17
CRAZY GREAPA
Рет қаралды 30 МЛН
How do hackers hide themselves? - staying anonymous online
11:55
Grant Collins
Рет қаралды 1,5 МЛН
Hackers Bypass Google Two-Factor Authentication (2FA) SMS
12:47
John Hammond
Рет қаралды 1,1 МЛН
But what is a neural network? | Deep learning chapter 1
18:40
3Blue1Brown
Рет қаралды 18 МЛН
SHODAN Explained! (It's Scary Easy to do) | Let's Hack
7:58
Let's Hack
Рет қаралды 528 М.
10 Signs Your Software Project Is Heading For FAILURE
17:59
Continuous Delivery
Рет қаралды 46 М.
To Brawl AND BEYOND!
00:51
Brawl Stars
Рет қаралды 17 МЛН