Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



 665

Possible DoS Issue

by Duncan Idaho - 15 February, 2020 - 08:02 AM
This post is by a banned member (Duncan Idaho) - Unhide
589
Posts
148
Threads
5 Years of service
#1
Bcrypt uses a ton of resources. UCP > Password doesn't have a captcha setup at all. You could potentially just spam password request changes with random strings as the password and the server would check every request. Enough requests = oh shit. Not to mention the fact it only takes like 6 lines of code in JS to make a tool for it.
[Image: Stylin-on-You.gif]

[Image: Leave-A-Like-Signature.png]
This post is by a banned member (Pentester708) - Unhide
652
Posts
482
Threads
5 Years of service
#2
(15 February, 2020 - 08:02 AM)Duncan Idaho Wrote: Show More
Bcrypt uses a ton of resources. UCP > Password doesn't have a captcha setup at all. You could potentially just spam password request changes with random strings as the password and the server would check every request. Enough requests = oh shit. Not to mention the fact it only takes like 6 lines of code in JS to make a tool for it.

nice finding
[Image: Udpc9Lb.gif]
Telegram: https://t.me/candycainlobbies
Ad by brocain
This post is by a banned member (snow1337) - Unhide
This post is by a banned member (Duncan Idaho) - Unhide
589
Posts
148
Threads
5 Years of service
#4
(15 February, 2020 - 10:03 AM)snow1337 Wrote: Show More
(15 February, 2020 - 08:24 AM)Pentester708 Wrote: Show More
(15 February, 2020 - 08:02 AM)Duncan Idaho Wrote: Show More
Bcrypt uses a ton of resources. UCP > Password doesn't have a captcha setup at all. You could potentially just spam password request changes with random strings as the password and the server would check every request. Enough requests = oh shit. Not to mention the fact it only takes like 6 lines of code in JS to make a tool for it.

nice finding

nice cicada 3301 pic :)  pepeokay

 http://973-eht-namuh-973.com/ Your recruitment is waiting brother.
[Image: Stylin-on-You.gif]

[Image: Leave-A-Like-Signature.png]
This post is by a banned member (Barry) - Unhide
Barry  
Staff
17.547
Posts
8
Threads
Staff Team
5 Years of service
#5
Your suggestion has been denied.
 1st spot available
[Image: 9Oq6tka.gif]
PRIVATEALPS.NET - Offshore Cloud Services - Dedicated Servers - TOR Friendly - DMCA Ignored 

Instant Deploy

Telegram : @PrivateAlps

Paid Advts Above----> I don't own above linked services, contact respective ownesr of the services for queries and issues

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 2 Guest(s)