Account enumeration

A very common first move for attackers looking to compromise your user accounts is to test email/passwords leaked from databases found on the Internet.

Highlighting such attempts is often done at the expense of parsing the application logs, which can end up being quite cumbersome and very time consuming.

Sqreen can highlight such attacks without any effort on your end and provide you with the compromised accounts, should the attacker succeed to successfully login to one of the enumerated accounts.

Sqreen SDK enables you to track all login activities happening in your app.

Every minute Sqreen computes the signals and look for unusual failed login tentatives distributed over a large number of accounts. In case the attack is targeting a very limited number of accounts, the attack is considered as a brute force.

Should an attacker fail to log into an account multiple time and finally succeed, this plugin will report the compromised accounts, enabling you to take actions (suspend account, reset the password) and inform the owners about the attack ASAP.

The signals computation happens on Sqreen’s backend based on the signals collected on all the instances of your applications. This collection happens asynchronously and is not slowing down your application performance.

  • Ruby
  • Node.js
  • PHP
  • Python
  • Java

Authentication (Sqreen SDK)

  • Authentications (Sqreen SDK)
  • IPs

