to change your password to various weak values.
N OT E
If password quality rules are enforced only through client-side controls,
this is not itself a security issue because ordinary users will still be protected. It
is not normally a threat to an application’s security that a crafty attacker can
assign themselves a weak password.
Brute-Forcible Login
Login functionality presents an open invitation for an attacker to try and guess
usernames and passwords, and so gain unauthorized access to the application.
If the application allows an attacker to make repeated login attempts with dif-
ferent passwords until the correct one is guessed, then it is highly vulnerable
Do'stlaringiz bilan baham: |