Kuboid
Open Luck·Kuboid.in
Security BSides2025
Open in YouTube ↗

Faces in the Fog: Identifying Users through Unconventional Means

BSidesSLC80 views47:2810 months ago

This talk demonstrates how to identify and enumerate users in web applications by analyzing unconventional indicators such as error messages, response timing, and application-specific logic. It explores how developers often inadvertently leak sensitive user information through insecure API endpoints, password reset flows, and account management features. The speaker provides a practical methodology for using LLMs to automate the analysis of HTTP traffic to identify these enumeration vulnerabilities. A custom Python script is demonstrated to automate the extraction of user data from application responses.

Talk Type
talk
Difficulty
intermediate
Category
web security
Has Demo Has Code Tool Released


BSidesSLC 2025

24 talks · 2025
Browse conference →
Premium Security Audit

We break your app before they do.

Professional penetration testing and vulnerability assessments by the Kuboid Secure Layer team. Securing your infrastructure at every layer.

Get in Touch
Official Security Partner
kuboid.in