User Enumeration

Public preview

Want everyone on your software team to learn this? Free 14-day trial.

Train my team
Code vulnerable to a timing attack
JavaScript
app.post('/login', async (request, response) => {
  const user = getUser(request.body.username);

  // The function returns early if the username is incorrect.
  if (!user) {
    response.sendStatus(401);
    return;
  }

  // This code path will only get executed if the username is
  // correct, allowing an attacker to infer the existence of a
  // username by timing how long the HTTP response takes.
  const matched = await bcrypt.compare(request.body.password, user.hashedPassword);

  if (matched) {
    request.session.username = request.body.username;
    response.redirect('/');
  } else {
    response.sendStatus(401);
  }
});