Using Aegis to force open the gate

A cesspit with an open iron gate.

Image: A cesspit with an open iron gate.

Athena flaunts here shield, Aegis, and summon forth a violent windstorm that slams into the gate and force it open with brute force. You jump into the stinking cesspit, swim across it, carefully entering the gate and into the lower part of the caste dungeon.

Note:

There are a number of different types of automated attacks that attackers can use to try and compromise user accounts. The most common types are listed below:

  • Brute Force: Testing multiple passwords from a dictionary or other source against a single account.
  • Credential Stuffing: Testing username/password pairs obtained from the breach of another site.
  • Password Spraying: Testing a single weak password against a large number of different accounts.

Different protection mechanisms can be implemented to protect against these attacks. In many cases, these defenses do not provide complete protection, but when a number of them are implemented in a defense-in-depth approach, a reasonable level of protection can be achieved. See Authentication Cheat Sheet for more information on how to protect against automated attacks.

You may mistakingly assume that you don't need to protect against brute force attacks due to the fact that your login and locks are hidden, inaccessible or in this case, protected by a stinking cesspit, but a good hacker always find his way around these type of barriers.

Provided by Johan Sydseter

OWASP® Dungeons & Daemons

OWASP Dungeons & Daemons is originally created by Johan Sydseter. It is open source and can be downloaded free of charge from the OWASP website. It is is free to use. It is licensed under the Creative Commons Attribution-ShareAlike 4.0 International, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. OWASP does not endorse or recommend commercial products or services. OWASP Dungeons & Daemons is licensed under the Creative Commons Attribution-ShareAlike 4.0 International license and is © 2024 OWASP Foundation.