Search

Username Enumeration

  • O365 and OWA username valid/not valid
  • but other portals too
  • Forgot password
  • Calendar feature (funky errors)

Remediation:

Synchronize error messages for both valid and invalid users/emails. For example:

  • If the email/user you provided exists, a password reset link will be sent to your email.