Application-layer denial of service and other activities that adversely affect the application's users. Includes:
Account lockout. Spamming. Excessive resource consumption. Scalping. Sniping. Must involve the ecommerce application in the attack and thus excludes HTTP DoS (e.g. flood attacks, slow attacks).
Gareth can utilize the application to deny service to some or all of its users
Owasp ASVS (4.0): 2.2.1 ,11.1.3 ,11.1.4
Owasp SCP: 41,55
Owasp Appsensor: UT1-4,STE3
Safecode: 1
ASVS V2.2 - General Authenticator Requirements
ASVS V11.1 - Business Logic Security Requirements
Password Guessing/Brute Force Attacks
Loading comments 0%