Skip to content

Do bcrypt hash on invalid username #9

@nullterminated

Description

@nullterminated

ERTwoFactorAuthenticationProcessor doesn't hash on invalid user name opening the possibility of enumeration attacks. Interesting article on the subject.

https://paragonie.com/blog/2016/01/on-design-and-implementation-stealth-backdoor-for-web-applications

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions