This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Empty String Password
From OWASP
(Redirected from Empty Password in Configuration File)
This page contains draft content that has never been finished. Please help OWASP update this content! See FixME.
This is a Vulnerability. To view all vulnerabilities, please see the Vulnerability Category page.
Last revision (mm/dd/yy): 08/31/2015
Vulnerabilities Table of Contents
Description
Using an empty string as a password is insecure.
It is never appropriate to use an empty string as a password. It is too easy to guess. An empty string password makes the authentication as weak as the user names, which are normally public or guessable. This makes a brute-force attack against the login interface much easier.
Risk Factors
TBD
Examples
TBD
Related Attacks
- Brute force attack against application log in interface.
Related Vulnerabilities
Related Controls
Related Technical Impacts
References
TBD