Lesson:
User Enumeration
Public previewWant everyone on your software team to learn this? Get completion tracking and compliance reporting with Hacksplaining for Teams. Free 14-day trial.
Train my teamCode vulnerable to a timing attackapp.post('/login', async (request, response) => {
const user = getUser(request.body.username);
// The function returns early if the username is incorrect.
if (!user) {
response.sendStatus(401);
return;
}
// This code path will only get executed if the username is
// correct, allowing an attacker to infer the existence of a
// username by timing how long the HTTP response takes.
const matched = await bcrypt.compare(request.body.password, user.hashedPassword);
if (matched) {
request.session.username = request.body.username;
response.redirect('/');
} else {
response.sendStatus(401);
}
});