Hi,
This is just a suggestion from our pen-testers, but they noted this:
In SimpleSAML2, sending POST requests to /idp/module.php/core/loginuserpassorg.php returns a 200 response with valid:false keys for authentication failure.
Because these are not 4xx or 5xx responses (and therefore triggering rate limiting), it may be possible to
brute-force this endpoint using known-good usernames.
The suggested solution is that a failure response returns a different code, such as a 403, so you can have an IPS look for that code for defensive purposes (e.g. rate limiting).
This isn't a major issue, just an opportunity for improvement from a security point of view. 🙂
Thanks,
Greg
Hi,
This is just a suggestion from our pen-testers, but they noted this:
The suggested solution is that a failure response returns a different code, such as a 403, so you can have an IPS look for that code for defensive purposes (e.g. rate limiting).
This isn't a major issue, just an opportunity for improvement from a security point of view. 🙂
Thanks,
Greg