Authentication flaws
Authentication verifies that someone is who they claim to be. Its flaws let an attacker impersonate another user: by guessing credentials, skipping steps in the flow, or abusing recovery and session management. This is the OWASP Top 10 Identification and Authentication Failures category, and the entry point for most modern intrusions.
Threat model
Section titled “Threat model”Account takeover (ATO) of users and admins, persistent access, and pivoting to critical data and functions. The cost of a single failure (one admin account without MFA, a predictable reset) is usually full compromise.
Anatomy
Section titled “Anatomy”Three intertwined mechanisms: authentication (login, MFA), session management (how identity persists after login) and recovery (password reset). A flaw in any breaks the identity guarantee. Golden rule: the server decides identity at every step; the client is never trusted.
Attack surfaces and variants
Section titled “Attack surfaces and variants”- Weak credentials: no policy, no limit → brute force, credential stuffing (breach reuse) and password spraying.
- User enumeration: different messages, status codes or timing for “user doesn’t exist” vs “wrong password”.
- Broken MFA: bypassed by jumping to the post-MFA step, codes without attempt limits, weak backup codes, tamperable “remember device”, race conditions.
- Recovery: predictable/non-expiring tokens, token leak in the
Referer, host header poisoning to redirect the link, failure to invalidate sessions. - Session management: predictable IDs, no rotation after login (fixation), no expiry, surviving logout.
Red Team
Section titled “Red Team”Discovery
Section titled “Discovery”- Compare valid/invalid login responses (text, status code, timing) → spot enumeration.
- Check attempt limits (rate limiting) and lockout; review the MFA and reset flows step by step.
By hand
Section titled “By hand”# Enumeration by response/size differenceffuf -w users.txt -X POST -d 'user=FUZZ&pass=x' \ -u https://app.tld/login -mr "does not exist" -of csv
# Password spraying (one common password against many users)ffuf -w users.txt -X POST -d 'user=FUZZ&pass=Spring2026!' \ -u https://app.tld/login -fc 401# (hydra/patator are alternatives; ALWAYS respect scope limits)- MFA: after user+password, try going straight to the post-login resource
skipping the code step; replay/repeat codes to check for limits; try
0000000-9999999if there’s no lockout (brute-force window). - Reset: analyze token entropy and expiry; try changing the
Host/header so the link points to your domain (you capture the token).
Techniques
Section titled “Techniques”Credential stuffing (breach lists + proxies), spraying (avoids per-user lockout), MFA
bypass (step skip, code brute force, JSON response tampering mfa:false→skip),
session fixation, and “remember me” abuse with persistent tokens.
Tooling
Section titled “Tooling”Burp Intruder, ffuf, hydra, patator; SecLists wordlists; JWT analysis with
jwt_tool (see also the JWT page).
Impact and chaining
Section titled “Impact and chaining”Mass ATO, admin access, persistence via long-lived sessions/tokens, and escalation to other apps through credential reuse.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- Spikes of failed logins, spraying patterns (many users, one password) and stuffing (many IPs, same structure).
- Impossible travel (same account from incompatible geographies), anomalous user-agents, unusual hours.
- MFA anomalies: many code attempts, MFA fatigue (push bursts).
Telemetry and sources
Section titled “Telemetry and sources”Authentication logs (success/failure with IP/UA), IdP/SSO, WAF/bot management, and MFA events.
Hardening
Section titled “Hardening”- Phishing-resistant MFA: passkeys / WebAuthn (FIDO2) for sensitive accounts; avoid SMS where possible.
- Strong hashing: Argon2id (or bcrypt/scrypt) with a unique salt; never plain MD5/SHA.
- Modern policy (NIST 800-63B): minimum length, check against breached passwords (HIBP/k-anonymity), no forced rotations or absurd composition rules.
- Rate limiting and stuffing/spraying detection; generic errors and constant timing against enumeration.
- Sessions: random IDs, rotation after login, expiry, server-side invalidation on logout and password change.
- Reset: one-time token, high entropy, short expiry; do not build the link
from the request
Host.
Response
Section titled “Response”Force reset and invalidate sessions of affected accounts, enable/enforce MFA, block IPs/patterns, and review post-compromise access.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- 23andMe (2023) — credential stuffing (password reuse from other breaches) that ultimately exposed data of ~6.9 million people via the “relatives” graph.
- Colonial Pipeline (2021) — initial access through a VPN account without MFA with a compromised password; led to a nationally impactful ransomware incident.
- “MFA fatigue” waves — attacks spamming push notifications until the victim accepts (mitigated by number matching / passkeys).
This category is rarely a single CVE; look at incidents and, for specific components, NVD (https://nvd.nist.gov/vuln/search) and GitHub Advisories (https://github.com/advisories).
Testing checklist
Section titled “Testing checklist”- User enumeration (text/code/timing) checked.
- Rate limiting/lockout on login and on the MFA code.
- MFA bypass: step skip, code brute force, response tampering.
- Reset: token entropy/expiry, host header, Referer leak.
- Session: rotation after login, expiry, invalidation on logout/password change.
- Tests only against your own / in-scope accounts.