Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

What enumeration attacks are and how to prevent them

Altszn.com by Altszn.com
December 20, 2022
in Dark Web
0
What enumeration attacks are and how to prevent them
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter

[ad_1]


Ravi Das

By

Ransomware and other malware-based attacks continue to make headlines, but that doesn’t mean they deserve all the attention. Another threat security teams need to be aware of is user enumeration attacks.

What is an enumeration attack?

Enumeration attacks happen when malicious actors brute-force access to web applications. Attackers often use credentials exposed in previous breaches or social engineering scams to attempt access to other websites and applications where users may have used the same login information.

If successful, attackers may gain access to personally identifiable information (PII) of customers and employees. They can then sell the PII on the dark web or use it to attack their victims, for example, by draining their bank accounts or making charges on their credit cards.

How does an enumeration attack work?

The majority of enumeration attacks target the databases of web-based applications. Such attacks most often occur on the app’s main login page.

Incorrect password

When conducting an enumeration attack on a login page, attackers observe how the web application reacts to a brute-force entry attempt:

  • If the reaction is a “username not found” message, attackers know the username isn’t in that particular database.
  • If the reaction is a “password is incorrect” message, attackers know the username exists within the database and that they can continue to brute-force attack that application.
  • If the reaction is a “username and/or password not found” message, attackers are unsure which credential is correct, if either.

Enumeration attacks can also be conducted against “forgot password” and “forgot username” forms in applications.

How to prevent enumeration attacks

While it’s not possible to 100% prevent user enumeration attacks, organizations should take the following steps to make them more difficult:

  1. Employ cryptic wording. Well-developed login pages should display a “username and/or password not valid” message. This makes it difficult for attackers to know if the username, password or both are incorrect.
  2. Use a next-generation firewall (NGFW). While all firewalls block traffic based on established rules, NGFWs in particular can limit the number of failed login attempts from multiple IP addresses.
    Graphic of a text-based CAPTCHA example
    Use CAPTCHA to prevent bots from logging in to user accounts.
  3. Use a web application firewall (WAF). WAFs filter HTTP traffic for malicious or rogue traffic incoming from the internet.
  4. Use CAPTCHA. CAPTCHA not only limits the number of times a person can attempt to log in to an app, but also helps slow down attacks and eliminate bots. CAPTCHA can also block automated enumeration attacks.
  5. Implement multifactor authentication (MFA). MFA, which requires additional credentials to successfully log in to an account, blocks cyber attackers from exploiting server responses used to launch enumeration attacks because they are unable to log in without the additional credential(s).
  6. Secure source code. The best way to mitigate the risk of an enumeration attack comes down to securing the source code of the web application. Make sure any source code — open source or otherwise — is updated and tested through DevSecOps methods before being implemented in production environments.

This was last published in December 2022

Related Resources

Dig Deeper on Threats and vulnerabilities




[ad_2]

Read More: news.google.com

Tags: Attacksdark webDarknetenumerationprevent
ADVERTISEMENT

Recent

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

June 15, 2025
Is it the future of finance?

Is it the future of finance?

June 15, 2025
U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

June 10, 2025

Categories

  • Bitcoin (4,227)
  • Blockchain (10,191)
  • Crypto (8,116)
  • Dark Web (343)
  • DeFi (7,822)
  • Ethereum (4,237)
  • Metaverse (6,158)
  • Monero (194)
  • NFT (762)
  • Solana (4,800)
  • Web3 (18,989)
  • Zcash (431)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

    VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

    June 15, 2025
    Is it the future of finance?

    Is it the future of finance?

    June 15, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 106,654.00
    • ethereumEthereum (ETH) $ 2,614.16
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.25
    • bnbBNB (BNB) $ 655.33
    • solanaSolana (SOL) $ 155.49
    • usd-coinUSDC (USDC) $ 0.999809
    • tronTRON (TRX) $ 0.280901
    • dogecoinDogecoin (DOGE) $ 0.176843
    • staked-etherLido Staked Ether (STETH) $ 2,614.71
    • cardanoCardano (ADA) $ 0.644275
    • hyperliquidHyperliquid (HYPE) $ 44.55
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,618.00
    • wrapped-stethWrapped stETH (WSTETH) $ 3,150.07
    • suiSui (SUI) $ 3.10
    • bitcoin-cashBitcoin Cash (BCH) $ 465.58
    • chainlinkChainlink (LINK) $ 13.68
    • leo-tokenLEO Token (LEO) $ 9.25
    • avalanche-2Avalanche (AVAX) $ 19.54
    • stellarStellar (XLM) $ 0.263607
    • whitebitWhiteBIT Coin (WBT) $ 51.46
    • the-open-networkToncoin (TON) $ 2.99
    • shiba-inuShiba Inu (SHIB) $ 0.000012
    • usdsUSDS (USDS) $ 0.999852
    • wethWETH (WETH) $ 2,615.24
    • wrapped-eethWrapped eETH (WEETH) $ 2,798.39
    • hedera-hashgraphHedera (HBAR) $ 0.160335
    • litecoinLitecoin (LTC) $ 87.57
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • polkadotPolkadot (DOT) $ 3.91
    • moneroMonero (XMR) $ 320.12
    • ethena-usdeEthena USDe (USDE) $ 0.999775
    • bitget-tokenBitget Token (BGB) $ 4.57
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 106,605.00
    • pepePepe (PEPE) $ 0.000011
    • uniswapUniswap (UNI) $ 7.83
    • pi-networkPi Network (PI) $ 0.597574
    • aaveAave (AAVE) $ 288.77
    • daiDai (DAI) $ 0.999552
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • bittensorBittensor (TAO) $ 382.06
    • okbOKB (OKB) $ 51.70
    • internet-computerInternet Computer (ICP) $ 5.64
    • aptosAptos (APT) $ 4.67
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.33
    • crypto-com-chainCronos (CRO) $ 0.092424
    • jito-staked-solJito Staked SOL (JITOSOL) $ 188.20
    • ethereum-classicEthereum Classic (ETC) $ 17.11
    • ondo-financeOndo (ONDO) $ 0.821803
    • bitcoinBitcoin (BTC) $ 106,654.00
    • ethereumEthereum (ETH) $ 2,614.16
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.25
    • bnbBNB (BNB) $ 655.33
    • solanaSolana (SOL) $ 155.49
    • usd-coinUSDC (USDC) $ 0.999809
    • tronTRON (TRX) $ 0.280901
    • dogecoinDogecoin (DOGE) $ 0.176843
    • staked-etherLido Staked Ether (STETH) $ 2,614.71
    • cardanoCardano (ADA) $ 0.644275
    • hyperliquidHyperliquid (HYPE) $ 44.55
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,618.00
    • wrapped-stethWrapped stETH (WSTETH) $ 3,150.07
    • suiSui (SUI) $ 3.10
    • bitcoin-cashBitcoin Cash (BCH) $ 465.58
    • chainlinkChainlink (LINK) $ 13.68
    • leo-tokenLEO Token (LEO) $ 9.25
    • avalanche-2Avalanche (AVAX) $ 19.54
    • stellarStellar (XLM) $ 0.263607
    • whitebitWhiteBIT Coin (WBT) $ 51.46
    • the-open-networkToncoin (TON) $ 2.99
    • shiba-inuShiba Inu (SHIB) $ 0.000012
    • usdsUSDS (USDS) $ 0.999852
    • wethWETH (WETH) $ 2,615.24
    • wrapped-eethWrapped eETH (WEETH) $ 2,798.39
    • hedera-hashgraphHedera (HBAR) $ 0.160335
    • litecoinLitecoin (LTC) $ 87.57
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • polkadotPolkadot (DOT) $ 3.91
    • moneroMonero (XMR) $ 320.12
    • ethena-usdeEthena USDe (USDE) $ 0.999775
    • bitget-tokenBitget Token (BGB) $ 4.57
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 106,605.00
    • pepePepe (PEPE) $ 0.000011
    • uniswapUniswap (UNI) $ 7.83
    • pi-networkPi Network (PI) $ 0.597574
    • aaveAave (AAVE) $ 288.77
    • daiDai (DAI) $ 0.999552
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • bittensorBittensor (TAO) $ 382.06
    • okbOKB (OKB) $ 51.70
    • internet-computerInternet Computer (ICP) $ 5.64
    • aptosAptos (APT) $ 4.67
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.33
    • crypto-com-chainCronos (CRO) $ 0.092424
    • jito-staked-solJito Staked SOL (JITOSOL) $ 188.20
    • ethereum-classicEthereum Classic (ETC) $ 17.11
    • ondo-financeOndo (ONDO) $ 0.821803