6. of Denial of Service I
An attacker can make a server unavailable or unusable without ever authenticating, but the problem goes away when the attacker stops (server, anonymous, temporary).
Threat |
|
You are temporarily locking users out of their accounts after three failed login attempts to protect against brute force attacks. An attacker is taking advantage of this security control and making deliberate repeated failed logins to cause account lockouts. |
|
CAPEC |
CAPEC-2 – Inducing account lockout |
ASVS |
N/A |
CWE |
CWE-645 – Overly restrictive account lockout mechanism |
Mitigations |
|
|