This Security Ninja test checks whether failed login messages reveal too much detail, such as confirming that a username exists while the password is wrong. That helps attackers during brute-force attempts.
Why it matters
Generic login errors are safer. Messages like “invalid username” versus “incorrect password” tell an attacker which half of the credentials to keep trying.
How to run the test
- Open Security Ninja and run the security tests.
- Find Check for display of unnecessary information on failed login attempts.
- Follow the guidance in the result if it fails.
On Pro, related login hardening is available under the firewall and Fixes features. See Firewall and Fixes.