AUTHENTICATION (AT4)

Sebastien can easily identify user names or can enumerate them

AUTHENTICATION
4

Sebastien can easily identify user names or can enumerate them

OWASP SCP

33,53

OWASP ASVS

2.2.1,4.1.5

OWASP AppSensor

AE1

CAPEC

-

SAFECODE

28

How to play?

This attack is often the result of one or more of the following:

User names (IDs, account names) may be guessable, published elsewhere, or are simply email addresses Authentication and related mechanisms may indicate whether a username is valid or not (registration, password reset/recovery, username recovery, change password, change email address) Missing authentication failure detection Missing monitoring to identify attacks against multiple user accounts, utilizing the same password Additionally another web or non-web application (e.g. mobile app, telephone service) that utilises the same credentials has one or more of the above problems.

NB: This card relates to user names. See AT 7 for the similar password cracking (brute forcing, dictionary attacks, guessing, credential stuffing, credential cracking).

Mappings

OWASP ASVS (4.0): 2.2.1 ,4.1.5

Capec: 383

OWASP SCP: 33,53

OWASP Appsensor: AE1

Safecode: 28

ASVS (4.0) Cheatsheetseries Index

ASVS V2.2 - General Authenticator Requirements

ASVS V4.1 - General Access Control Design

No suitable mappings were found.

Attacks

Password Guessing/Brute Force Attacks

Social engineering attack

Session Hijacking (Man-in-the-Middle)

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.