đ Buy MoT Professional Membership, get MoTaCon free! đ
Learn
Events
Insights
Certs
Observatory
Moments
Join
Search
*
Sign In
Joerg Sievers
Joerg Sievers
Test Service Specialist
Follow
Award Star
Passionately testing for ~30 years
đ MoTaBirthday | April 13, 2017
3
stars
9
badges
0
certs
2
followers
1
following
Glossary Terms
(1)
Broken Authentication
Broken Authentication means that a web applicationâs login system or session management is flawed, letting attackers bypass authentication and gain unauthorized access to sensitive accountsâsometimes even administrative ones. Attackers exploit these issues through methods like stolen or weak credentials, brute-force attacks, or hijacking session identifiers. [1][2] Problem Areas Credential Management: Weak or default passwords, poor password storage (no hashing/salting), or flaws in password recovery make it easier for attackers to steal or guess passwords. Session Management: Vulnerabilities in how sessions are created, tracked, or terminated can lead to session hijackingâwhere attackers impersonate users by stealing session IDs, often through poorly protected browser cookies or unexpired sessions. [3] Tips for Testers Test for Common Weaknesses Try default and weak passwords (âpasswordâ, âadminâ, â123456â, etc.) and check the applicationâs password policies. Attempt brute-force and credential stuffing attacks (within allowed scope) to verify protections. Check Session Management Confirm that session tokens are not leaked in URLs and are changed after login. Validate session termination: users should be logged out everywhere after logging out or timing out. Explore Forgot-Password and Recovery Flows Test for predictable, non-expiring, or re-usable reset tokens. Check for error messages or flow differences that might leak whether an account exists. What New Security Testers Should Know Broken authentication is one of the most impactful vulnerabilities, often leading to data breaches or account takeoversâeven on major platforms. Sources (Thanks to Perplexety AI for supporting the search [4]): Port Swigger (Home of BurpSuite, well know security tool) Bright Security OWASP API2:2023 Broken Authentication Prompt
đĄWhat's next? View ways to contribute
Badges
(9)
Stars
(3)
âď¸ Earn more stars âď¸
Events
(2)
Not registered for any upcoming events
Activity
(16)
Est 2017
This badge is awarded to those that joined the MoTaverse in 2017.
Badge Award
11 days ago
Visited an Observatory link
2025 - The Year in Review
Community Star
8 months ago
Started a conversation on The Club
39c3 - Chaos Communication Congress Hamburg, Germany - Are you there?
Community Star
10 months ago
Picture Perfect
This badge is awarded to members who update their profile with a new photo.
Badge Award
12 months ago
99 and Counting
This badge is awarded to members who visit the Ministry of Testing site 99 times
Badge Award
12 months ago
Contributions
(1)
Glossary Term (1)
đĄWhat's next? View ways to contribute
Subscribe to our newsletter
Subscribe