Timing Attack Checker Timing Attack Checker / tool / free

http://pentestmonkey.net/tools/timing-attack-ch...

A sweet little PERL script for pentesting timing attacks on logins to brute force guess lists of existing usernames.
0 favorites
submitted over 3 years ago, by pineapple
Timing Attack Checker popular tool

2 Comments

pineapple

Cool script, here's a sample of something I just tried it on:

perl ./timing-attack-checker.pl -n 200 \
    'curl --data "username=z&password=nothing" http://localhost:3000/login' \
    'curl --data "username=zaphod&password=nothing" http://localhost:3000/login' \
    'curl --data "username=doesntexist&password=nothing" http://localhost:3000/login'

Sample output before attempting to counter a timing attack

=================================================
Results for: curl --data "username=zaphod&password=nothing" http://localhost:3000/login
Average time: 0.069618335
Minimum time: 0.051241
Maximum time: 0.194459
Standard deviation: 0.0264472536189067 (i.e. 68% of times within 1 sd, 95% within 2 sd)
Was fastest on 0 out of 200 occassions (0% of the time)
Was slowest on 160 out of 200 occassions (80% of the time)
=================================================
Results for: curl --data "username=doesntexist&password=nothing" http://localhost:3000/login
Average time: 0.02706211
Minimum time: 0.019439
Maximum time: 0.099455
Standard deviation: 0.0170977406386897 (i.e. 68% of times within 1 sd, 95% within 2 sd)
Was fastest on 159 out of 200 occassions (79.5% of the time)
Was slowest on 18 out of 200 occassions (9% of the time)
=================================================
Results for: curl --data "username=z&password=nothing" http://localhost:3000/login
Average time: 0.033158755
Minimum time: 0.019987
Maximum time: 0.089747
Standard deviation: 0.0162291339527091 (i.e. 68% of times within 1 sd, 95% within 2 sd)
Was fastest on 41 out of 200 occassions (20.5% of the time)
Was slowest on 22 out of 200 occassions (11% of the time)
=================================================

pineapple, over 3 years ago

xiaojun

20170512 junda
http://www.louisvuittonoutletclearance.us.com
http://www.oakleysunglasseswholesalechina.us.com
http://www.burberry-outletstore.in.net
http://www.coachoutletonlineshopping.us.com
http://www.poloralphlaurenoutlet-online.us.com
http://www.ralphlauren-outletuk.co.uk
http://www.rolexwatchesforsale.me.uk
http://www.christianlouboutinshoesoutlet.us.com
http://www.cheapfootballshirts.me.uk
http://www.christianlouboutin-shoes.org.uk
http://www.hollisterclothing.co.uk
http://www.oakleysunglassescheapoutlet.us.com
http://www.coachfactoryoutletcoachoutletonline.us.com
http://www.oakley-sunglasseswholesale.us.com
http://www.ferragamooutletstore.net
http://www.hollisterclothingstore.in.net
http://www.truereligionoutlet-store.us.com
http://www.herveleger.us.com
http://www.airhuarache-nike.co.uk
http://www.hollistersaleuk.co.uk
http://www.coachoutlet-clearance.us.com
http://www.michaelkorshandbagsclearanceoutlet.us.com
http://www.true-religion.org.uk
http://www.nikefree5.us
http://www.rolex-watches.it
http://www.coachoutletonlinecoachfactoryoutlet.com
http://www.rolexwatchesrolexoutlet.us.com
http://www.michaelkorsoutlet-onlineclearance.us.com
http://www.oakleysunglassesofficial.us.com
http://www.michaelkorshandbags-onsale.us.com
http://www.coachfactoryoutletstore.com.co
http://www.ray-bansunglassesofficial.us.com
http://www.nikeairmax90.me.uk
http://www.nikeoutletstore.us
http://www.hollisterclothing-store.us.com
http://www.cheapoakleysunglassesformen.us.com
http://www.ralphlaurenpoloshirts.org.uk
http://www.pandorajewelryoutlet.us.com
http://www.longchamp-handbags.co.uk
http://www.rolex-outlet.us.com
http://www.raybansunglassessale.com.co
http://www.nikeairmax-90.co.uk
http://www.oakleysunglassescheapwholesale.us.com
http://www.truereligion-jeans.org.uk
http://www.burberryoutletstore.in.net
http://www.valentinooutlet.us.com
http://www.michaelkorsoutlet-uk.me.uk
http://www.michaelkors-outletclearance.us.org
http://www.yeezyboostoutlet.us.com
http://www.polooutletstores.us.com

xiaojun, 2 months ago


Login or to comment.

Tutorials are any resources you learn from.

Examples: an intro to html5 screencast, a pdf about git, photoshop effects tutorials, meta-programming in ruby, lambda calculus, higher-order fixed-point combinators.

Tools are websites, apps or services used -on- your project (indirectly), to aid the process.

Examples: A color scheme generator, email marketing software, usability heat maps, css3 code generators, a downloadable png compressor.

Assets are downloadable files used -in- your projects, usually as code, textures, or images.

Examples: a jquery sticky menu, photoshop brushes, background textures, mvc frameworks, twitter bootstrap, 960 grid system.