This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Empty String Password
From OWASP
Revision as of 17:39, 9 June 2006 by Weilin Zhong (talk | contribs)
This is a Vulnerability. To view all vulnerabilities, please see the Vulnerability Category page.
Description
Empty string password allows attackers that obtain the cooresponding user name, which is normally public or easily guessable, to log in to the application. This also makes a brute-force attack much easier, in which an attacker only needs to guess the right user name in order to get in.
Examples
Related Threats
Attackers try to obtain a log in account of the application.
Related Attacks
- Brute-force Attack against application log in interface.
Related Vulnerabilities
Related Countermeasures
Category:Authentication Strong Password Policy
Categories
This article is a stub. You can help OWASP by expanding it or discussing it on its Talk page.