2. of Denial of Service I
An attacker can make your authentication system unusable or unavailable.
Threat |
|
Your system locks users out after a number of failed login attempts, an attacker could enumerate users by deliberately sending invalid passwords to lock out all the users. |
|
CAPEC |
CAPEC-2 – Inducing account lockout |
ASVS |
2.2.1 – Verify the effectiveness of the authentication controls |
CWE |
CWE-307 – Improper restriction of excessive authentication attempts |
Mitigations |
|
|