User Enumeration
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Leaking username information on your site makes things much easier for hackers.
- Prevalence
- Common
- Exploitability
- Easy
- Impact
- Worrying
What is user enumeration?
User enumeration is a reconnaissance attack in which an attacker probes an application to discover which usernames or email addresses have accounts. It works when login, signup or password reset pages respond differently for accounts that exist, in their messages or their timing. The harvested usernames are then used for password guessing and phishing.
What you'll learn
- How login, signup and password reset pages reveal which accounts exist
- Why response timing can leak a username even when the messages match
- How to make responses identical for real and unknown accounts
Where this lesson counts
OWASP Top 10
Weak passwords, guessable sessions and leaky login flows let attackers assume other identities.
Learn more about A07PCI DSS 4.0
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Learn more about 6.2.4This lesson includes
-
User Enumeration lab
See how a site tells attackers which usernames exist: login errors that differ, responses that take longer for real accounts, password reset and sign-up pages that confirm an address, and profile URLs that answer 403 instead of 404. Most leaks come with a safer design.
-
How to prevent User Enumeration
The prevention guide covers four approaches:
- Make Login Failures Indistinguishable
- Don't Reveal Usernames During Password Resets
- Don't Reveal Usernames During Registration
- Hide Profile Pages from Anonymous Users
-
User Enumeration quiz
Two questions. Passing marks the lesson complete.
Related lessons
Browse all 45 lessons
Password Mismanagement
Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.
Information Leakage
Revealing system information helps an attacker learn about your tech stack.
Email Spoofing
Email spoofing is the sending of email messages with a forged "from" address.
Privilege Escalation
Privilege escalation occurs when an attacker exploits a vulnerability to impersonate another user or gain extra permissions.