General Information

Missing Account Lockout Abuse

Variants:
Direct 

Vector Type:
Attack

Relevance:
Generic

Layer:
Application-Level

Platforms:
Any

Target Type:
Application

Affected Mechanisms:
Account Lockout, Anti-Automation

Invented In:
01/01/1999

Added In:
19/12/2014


Vector Operation Method:
Attackers can abuse a missing account lockout mechanism to perform brute force and dictionary attacks aimed at enumerating user credentials and sensitive resources.


Direct Variant:

Missing Account Lockout Abuse

Variant Title:
Missing Account Lockout Abuse

Typical Severity:
Medium

Resources:

White Papers:

Learn More: