Preventing User Enumeration on Registration Page

Preventing User Enumeration on Registration Page

Since the username is the public part, it isn't the end of the world if it can be enumerated, however if you really do want to avoid this, the easiest thing is to have them use e-mail address as the username.

Then you simply say that you sent a link to the e-mail no matter if they have an account already or not.

 

作者:Chuck Lu    GitHub    
posted @   ChuckLu  阅读(8)  评论(0编辑  收藏  举报
编辑推荐:
· 记一次.NET内存居高不下排查解决与启示
· 探究高空视频全景AR技术的实现原理
· 理解Rust引用及其生命周期标识(上)
· 浏览器原生「磁吸」效果!Anchor Positioning 锚点定位神器解析
· 没有源码,如何修改代码逻辑?
阅读排行:
· 全程不用写代码,我用AI程序员写了一个飞机大战
· DeepSeek 开源周回顾「GitHub 热点速览」
· MongoDB 8.0这个新功能碉堡了,比商业数据库还牛
· 记一次.NET内存居高不下排查解决与启示
· 白话解读 Dapr 1.15:你的「微服务管家」又秀新绝活了
历史上的今天:
2017-11-23 webpart containers in kentico 7
2017-11-23 Common webpart properties in kentico
2017-11-23 Find Blank Cell in Excel
2017-11-23 Document properties
2017-11-23 inheritance in kentico
2017-11-23 网络正常,但是网络图标上有黄色的三角图标
2017-11-23 Process Explorer
点击右上角即可分享
微信分享提示