CS / ITS PREPCOURSE · EXERCISE 01
One account. 10,000 possible PINs.
Guess the festival account's four-digit PIN, then experiment with a temporary lockout.
Offline simulation · fictional account · no requests leave this page
Your experiment
- Try a few PINs, then reset and run the guess generator without a defence.
- Save the result. Enable lockout after five failures, reset, and repeat.
- Reset again. Enter five wrong PINs, then immediately try the correct one you found.
- Change the settings and compare attack time with the inconvenience to the account owner.
Keep the same secret for comparisons. Every submitted request costs one simulated second; you can skip lockout time instantly.
1 / Login
Account: festival-volunteer
Ready for your first attempt.
2 / Defence
Reset clears time, counters and lockouts, but preserves the secret PIN. Editing controls alone does not apply them.
3 / Guess generator
Tries 0000, 0001, … in order. A blocked guess is retried after the lockout.
Uses the selected client. Without automatic skipping, it pauses when a request is blocked. Manual attempts do not advance the generator.
4 / Observe & compare
Comparison rows survive resets, but disappear when this page is reloaded. Export them before closing.
Start with a new secret PIN
This changes the challenge and resets the current experiment.
Comparison notebook
| Defence | Requests | Checked | Blocked | Time (s) | Outcome / note |
|---|
Recent requests
Most recent first; only the last 12 are displayed.
| Start time (s) | Client | PIN | Result |
|---|
Hints & bonus
Hint 1 · How many possibilities?
Four digits give 10 × 10 × 10 × 10 = 10,000 possible strings. Keep leading zeros: 0042 is a valid PIN.
Hint 2 · Make a fair comparison
Save a baseline run from a fresh reset. Apply the defence and run again with the same PIN and starting guess.
Hint 3 · Test the account owner's experience
After finding the PIN, reset. Submit a different PIN five times. Immediately submit the correct PIN; then skip the lockout and retry.
Bonus: switch to per-client counters. Lock client A, then try the correct PIN with B. Repeat with per-account counters. Use the starter code in bonus/ to implement your own defence and tests.