15–25 min Updated

User Enumeration

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Leaking username information on your site makes things much easier for hackers.

Prevalence
Common
Exploitability
Easy
Impact
Worrying

What is user enumeration?

User enumeration is a reconnaissance attack in which an attacker probes an application to discover which usernames or email addresses have accounts. It works when login, signup or password reset pages respond differently for accounts that exist, in their messages or their timing. The harvested usernames are then used for password guessing and phishing.

What you'll learn

  • How login, signup and password reset pages reveal which accounts exist
  • Why response timing can leak a username even when the messages match
  • How to make responses identical for real and unknown accounts

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • User Enumeration lab

    See how a site tells attackers which usernames exist: login errors that differ, responses that take longer for real accounts, password reset and sign-up pages that confirm an address, and profile URLs that answer 403 instead of 404. Most leaks come with a safer design.

  • How to prevent User Enumeration

    The prevention guide covers four approaches:

    • Make Login Failures Indistinguishable
    • Don't Reveal Usernames During Password Resets
    • Don't Reveal Usernames During Registration
    • Hide Profile Pages from Anonymous Users
  • User Enumeration quiz

    Two questions. Passing marks the lesson complete.

  • Password Mismanagement

    Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.

  • Email Spoofing

    Email spoofing is the sending of email messages with a forged "from" address.

  • Privilege Escalation

    Privilege escalation occurs when an attacker exploits a vulnerability to impersonate another user or gain extra permissions.