Lesson:
User Enumeration
Public previewWant everyone on your software team to learn this? Get completion tracking and compliance reporting with Hacksplaining for Teams. Free 14-day trial.
Train my teamCode not vulnerable to a timing attackapp.post('/login', async (request, response) => {
const user = getUser(request.body.username);
// Calculate the password hash regardless of whether the username exists,
// so the attacker cannot use timing attacks to detect which users exist
// in the database.
const passwordHash = user ? user.hashedPassword : DUMMY_PASSWORD_HASH;
const matched = await bcrypt.compare(request.body.password, passwordHash);
if (user && matched) {
request.session.username = request.body.username;
response.redirect('/');
} else {
response.sendStatus(401);
}
});