associated with that question, and verify whether the login is still
successful.
■
If the application does not enable an attacker to submit an arbitrary
question and answer, perform a partial login several times with a single
account, proceeding each time as far as the varying question. If the ques-
tion changes on each occasion, then an attacker can still effectively
choose which question to answer.
160
Chapter 6
■
Attacking Authentication
70779c06.qxd:WileyRed 9/14/07 3:13 PM Page 160
N OT E
In some applications where one component of the login varies
randomly, the application collects all of a user’s credentials at a single stage.
Do'stlaringiz bilan baham: |