3 ms·
It's certainly not good to leak this information, but wouldn't most of the providers mentioned have an automatic lockout for repeated login attempts? How could
by pbnjay 9y ago
It's certainly not good to leak this information, but wouldn't most of the providers mentioned have an automatic lockout for repeated login attempts? How could an attacker actually exploit this in any non-trivial system?
This is much more dangerous if combined with a database dump containing password hashes. (but that's a different problem)
It's cool as an undergraduate student project, but until it's got a CVE assigned and/or better vetting I don't think it's very helpful to be sharing a FUD site like this.