Skip to content

A simple python utility for enummerating user accounts using a timing attack

License

Notifications You must be signed in to change notification settings

tr4nc3/AuthTimer

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 

Repository files navigation

AuthTimer

Description

Many webapps don't perform authentication in constant-time operations which can result in a timing difference for authentication between valid and invalid user accounts. This can be used to enumerate valid and invalid usernames. This script tests the authentication pages for such issues.

About

A simple python utility for enummerating user accounts using a timing attack

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages