CS / ITS PREPCOURSE · EXERCISE 01

One account. 10,000 possible PINs.

Guess the festival account's four-digit PIN, then experiment with a temporary lockout.

Offline simulation · fictional account · no requests leave this page

Your experiment

  1. Try a few PINs, then reset and run the guess generator without a defence.
  2. Save the result. Enable lockout after five failures, reset, and repeat.
  3. Reset again. Enter five wrong PINs, then immediately try the correct one you found.
  4. Change the settings and compare attack time with the inconvenience to the account owner.

Keep the same secret for comparisons. Every submitted request costs one simulated second; you can skip lockout time instantly.

1 / Login

Account: festival-volunteer

Ready for your first attempt.

2 / Defence

Reset clears time, counters and lockouts, but preserves the secret PIN. Editing controls alone does not apply them.

3 / Guess generator

Tries 0000, 0001, … in order. A blocked guess is retried after the lockout.

Uses the selected client. Without automatic skipping, it pauses when a request is blocked. Manual attempts do not advance the generator.

4 / Observe & compare

Comparison rows survive resets, but disappear when this page is reloaded. Export them before closing.

Start with a new secret PIN

This changes the challenge and resets the current experiment.

Comparison notebook

DefenceRequestsCheckedBlockedTime (s)Outcome / note

Recent requests

Most recent first; only the last 12 are displayed.

Start time (s)ClientPINResult

Hints & bonus

Hint 1 · How many possibilities?

Four digits give 10 × 10 × 10 × 10 = 10,000 possible strings. Keep leading zeros: 0042 is a valid PIN.

Hint 2 · Make a fair comparison

Save a baseline run from a fresh reset. Apply the defence and run again with the same PIN and starting guess.

Hint 3 · Test the account owner's experience

After finding the PIN, reset. Submit a different PIN five times. Immediately submit the correct PIN; then skip the lockout and retry.

Bonus: switch to per-client counters. Lock client A, then try the correct PIN with B. Repeat with per-account counters. Use the starter code in bonus/ to implement your own defence and tests.

Further reading: OWASP Authentication Cheat Sheet