A security analyst is reviewing web server access logs. They notice a large number of HTTP GET requests to '/admin/login.php' from a single IP address, with each request containing a different, short string in the 'username' parameter (e.g., 'admin', 'test', 'root'). The HTTP response status codes are consistently 200 OK for most attempts, but a few return 401 Unauthorized. What type of attack is most likely occurring?
- ASQL Injection
- BUsername Enumeration
- CPath Traversal
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Username Enumeration
The scenario describes an attacker systematically trying different usernames to a login page, indicated by varying 'username' parameters and consistent '200 OK' responses (meaning the page loaded successfully, but the login itself may have failed silently or shown a generic error) versus '401 Unauthorized' (which for some systems might explicitly indicate a known user with wrong password, while 200 means user not found). This is a classic username enumeration attempt.
Why the other options are wrong
- A. SQL injection targets database queries, not typically just iterating through usernames on a login page.
- C. Path traversal attempts to access files outside the web root, not to enumerate usernames.
- D. XSS injects client-side scripts, not for enumerating usernames on a login form.
Username Enumeration
Username enumeration is an attack where an attacker attempts to discover valid usernames on a system by observing differences in application responses (e.g., error messages, HTTP status codes, response times) when valid versus invalid usernames are submitted.
- Often a precursor to brute-force or credential stuffing attacks.
- Relies on subtle differences in error messages or response codes.
- Can be mitigated by generic error messages, rate limiting, and CAPTCHAs.
- Detected by monitoring repetitive login attempts with varying usernames.
Memory trick: Web log patterns are like reading a story of who's knocking on your web door, and why.