FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    User Enumeration

    Scheduled Pinned Locked Moved
    General Discussion
    2
    2
    334
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      john.mooney
      last edited by

      Hello, I was wondering if FusionAuth will mitigate User Enumeration attacks by apply some random response delay or any other method?

      1 Reply Last reply Reply Quote 0
      • danD
        dan
        last edited by

        Hiya,

        Do you have a script or set of scripts which illustrates a valid user enumeration attack against FusionAuth?

        I did a test of three kinds of user login:

        • existing user, valid password
        • existing user, invalid password
        • user who didn't exist

        And they all returned in roughly the same amount of time.

        --
        FusionAuth - Auth for devs, built by devs.
        https://fusionauth.io

        1 Reply Last reply Reply Quote 0
        • First post
          Last post