Skip to content

Pen-test suggestion - loginuserpassorg.php returns a 200 response #2578

Description

@gregharvey

Hi,

This is just a suggestion from our pen-testers, but they noted this:

In SimpleSAML2, sending POST requests to /idp/module.php/core/loginuserpassorg.php returns a 200 response with valid:false keys for authentication failure.

Because these are not 4xx or 5xx responses (and therefore triggering rate limiting), it may be possible to
brute-force this endpoint using known-good usernames.

The suggested solution is that a failure response returns a different code, such as a 403, so you can have an IPS look for that code for defensive purposes (e.g. rate limiting).

This isn't a major issue, just an opportunity for improvement from a security point of view. 🙂

Thanks,

Greg

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions