5. of Denial of Service II
An attacker can make a client unavailable or unusable without ever authenticating, but the problem goes away when the attacker stops (client, anonymous, temporary).
Threat |
|
You rate limit users of your system, so an attacker has stolen a user’s credentials and is exceeding usage limits on your service, causing rate limiting to take place that is affecting the legitimate user. |
|
CAPEC |
CAPEC-2 – Inducing account lockout |
ASVS |
N/A |
CWE |
CWE-399 – Resource management errors |
Mitigations |
|
|