Many webapps don't perform authentication in constant-time operations which can result in a timing difference for authentication between valid and invalid user accounts. This can be used to enumerate valid and invalid usernames. This script tests the authentication pages for such issues.
-
Notifications
You must be signed in to change notification settings - Fork 0
A simple python utility for enummerating user accounts using a timing attack
License
tr4nc3/AuthTimer
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
A simple python utility for enummerating user accounts using a timing attack
Resources
License
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published