DEV Community

Discussion on: Non-atomic increments in NodeJS or how I found a vulnerability in express-brute package.

Collapse
 
animir profile image
Roman Voloboev

I was preparing for a conference recently and did some test attacks with different options. I was able to make 216 wrong password tries with 1000 requests per 1ms rate. This is not acceptable.