
17 Dec
2003
17 Dec
'03
11:17 p.m.
I have had some success using timing against UNIX to find out what usernames are valid on systems with finger &c disabled. If a username does not exist, it returns the "Login incorrect" a lot faster than it would if the username existed but the password was incorrect. I wonder how many other systems are vulnerable to this sort of attack.
7884
Age (days ago)
7884
Last active (days ago)
0 comments
1 participants
participants (1)
-
SINCLAIR DOUGLAS N