<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Creds Harvesting through invalid user error in Suggest an Idea</title>
    <link>https://community.qlik.com/t5/Suggest-an-Idea/Creds-Harvesting-through-invalid-user-error/idi-p/1927748</link>
    <description>&lt;P&gt;Description:&lt;BR /&gt;Using differences in responses from the application, it is possible to determine accounts that exist within the application and accounts that do not. These differences in responses can be used by an attacker to identify existing or active accounts, and the information gathered can be used to aid in additional attack scenarios&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anagarju_0-1652074488218.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/78906i848239D2158A8636/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anagarju_0-1652074488218.png" alt="anagarju_0-1652074488218.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mitigation Recommendations:&lt;BR /&gt;Avoid providing specific reasons for failure and use generic responses instead when possible. This will help ensure that attackers cannot obtain more information about accounts than necessary.&lt;BR /&gt;Examples for possible remediation:&lt;BR /&gt;Login&lt;BR /&gt;• Make sure to return a generic “Username or password is incorrect” message when a login failure occurs.&lt;BR /&gt;• Make sure the HTTP response, and the time taken to respond are no different when a username does not exist, and an incorrect password is entered.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jul 2022 14:37:00 GMT</pubDate>
    <dc:creator>anagarju</dc:creator>
    <dc:date>2022-07-04T14:37:00Z</dc:date>
    <item>
      <title>Re: Creds Harvesting through invalid user error</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Creds-Harvesting-through-invalid-user-error/idc-p/1927749#M9453</link>
      <description>&lt;P&gt;Reference support ticket:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/crmsupport/casepage/issue-id/00034362/issue-guid/5003z00002V50IqAAJ/issue-provider/salesforce" target="_blank"&gt;https://community.qlik.com/t5/crmsupport/casepage/issue-id/00034362/issue-guid/5003z00002V50IqAAJ/issue-provider/salesforce&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 05:36:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Creds-Harvesting-through-invalid-user-error/idc-p/1927749#M9453</guid>
      <dc:creator>anagarju</dc:creator>
      <dc:date>2022-05-09T05:36:55Z</dc:date>
    </item>
    <item>
      <title>From now on, please track this idea from the Ideation por...</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Creds-Harvesting-through-invalid-user-error/idc-p/2100119#M13387</link>
      <description>&lt;P&gt;From now on, please track this idea from the Ideation portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A title="Link to new idea" href="https://ideation.qlik.com/app/#/case/281481" target="_blank" rel="noopener"&gt;Link to new idea&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Meghann&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;EM&gt;NOTE: Upon clicking this link 2 tabs may open - please feel free to close the one with a login page. If you &lt;STRONG&gt;only&lt;/STRONG&gt; see 1 tab with the login page, please try clicking this link first: &lt;STRONG&gt;&lt;A title="Authenticate me!" href="#" target="_blank" rel="noopener"&gt;Authenticate me!&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;t&lt;/EM&gt;&lt;EM&gt;hen try the link above again. Ensure pop-up blocker is off.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 15:16:25 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Creds-Harvesting-through-invalid-user-error/idc-p/2100119#M13387</guid>
      <dc:creator>Meghann_MacDonald</dc:creator>
      <dc:date>2023-08-02T15:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Creds Harvesting through invalid user error - Status changed to: Closed - Archived</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Creds-Harvesting-through-invalid-user-error/idc-p/2100120#M13388</link>
      <description />
      <pubDate>Wed, 02 Aug 2023 15:16:27 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Creds-Harvesting-through-invalid-user-error/idc-p/2100120#M13388</guid>
      <dc:creator>Ideation</dc:creator>
      <dc:date>2023-08-02T15:16:27Z</dc:date>
    </item>
  </channel>
</rss>

