User Enumeration

Public preview

Want everyone on your software team to learn this? Free 14-day trial.

Train my team
Code not vulnerable to a timing attack
JavaScript
app.post('/login', async (request, response) => {
  const user = getUser(request.body.username);

  // Calculate the password hash regardless of whether the username exists,
  // so the attacker cannot use timing attacks to detect which users exist
  // in the database.
  const passwordHash = user ? user.hashedPassword : DUMMY_PASSWORD_HASH;

  const matched = await bcrypt.compare(request.body.password, passwordHash);

  if (user && matched) {
    request.session.username = request.body.username;
    response.redirect('/');
  } else {
    response.sendStatus(401);
  }
});