User Enumeration
-
Hello, I was wondering if FusionAuth will mitigate User Enumeration attacks by apply some random response delay or any other method?
-
Hiya,
Do you have a script or set of scripts which illustrates a valid user enumeration attack against FusionAuth?
I did a test of three kinds of user login:
- existing user, valid password
- existing user, invalid password
- user who didn't exist
And they all returned in roughly the same amount of time.