Skip to content

Authentication flaws

Authentication verifies that someone is who they claim to be. Its flaws let an attacker impersonate another user: by guessing credentials, skipping steps in the flow, or abusing recovery and session management. This is the OWASP Top 10 Identification and Authentication Failures category, and the entry point for most modern intrusions.

Account takeover (ATO) of users and admins, persistent access, and pivoting to critical data and functions. The cost of a single failure (one admin account without MFA, a predictable reset) is usually full compromise.

Three intertwined mechanisms: authentication (login, MFA), session management (how identity persists after login) and recovery (password reset). A flaw in any breaks the identity guarantee. Golden rule: the server decides identity at every step; the client is never trusted.

  • Weak credentials: no policy, no limit → brute force, credential stuffing (breach reuse) and password spraying.
  • User enumeration: different messages, status codes or timing for “user doesn’t exist” vs “wrong password”.
  • Broken MFA: bypassed by jumping to the post-MFA step, codes without attempt limits, weak backup codes, tamperable “remember device”, race conditions.
  • Recovery: predictable/non-expiring tokens, token leak in the Referer, host header poisoning to redirect the link, failure to invalidate sessions.
  • Session management: predictable IDs, no rotation after login (fixation), no expiry, surviving logout.
  • Compare valid/invalid login responses (text, status code, timing) → spot enumeration.
  • Check attempt limits (rate limiting) and lockout; review the MFA and reset flows step by step.
Ventana de terminal
# Enumeration by response/size difference
ffuf -w users.txt -X POST -d 'user=FUZZ&pass=x' \
-u https://app.tld/login -mr "does not exist" -of csv
# Password spraying (one common password against many users)
ffuf -w users.txt -X POST -d 'user=FUZZ&pass=Spring2026!' \
-u https://app.tld/login -fc 401
# (hydra/patator are alternatives; ALWAYS respect scope limits)
  • MFA: after user+password, try going straight to the post-login resource skipping the code step; replay/repeat codes to check for limits; try 0000000-9999999 if there’s no lockout (brute-force window).
  • Reset: analyze token entropy and expiry; try changing the Host/header so the link points to your domain (you capture the token).

Credential stuffing (breach lists + proxies), spraying (avoids per-user lockout), MFA bypass (step skip, code brute force, JSON response tampering mfa:false→skip), session fixation, and “remember me” abuse with persistent tokens.

Burp Intruder, ffuf, hydra, patator; SecLists wordlists; JWT analysis with jwt_tool (see also the JWT page).

Mass ATO, admin access, persistence via long-lived sessions/tokens, and escalation to other apps through credential reuse.

  • Spikes of failed logins, spraying patterns (many users, one password) and stuffing (many IPs, same structure).
  • Impossible travel (same account from incompatible geographies), anomalous user-agents, unusual hours.
  • MFA anomalies: many code attempts, MFA fatigue (push bursts).

Authentication logs (success/failure with IP/UA), IdP/SSO, WAF/bot management, and MFA events.

  1. Phishing-resistant MFA: passkeys / WebAuthn (FIDO2) for sensitive accounts; avoid SMS where possible.
  2. Strong hashing: Argon2id (or bcrypt/scrypt) with a unique salt; never plain MD5/SHA.
  3. Modern policy (NIST 800-63B): minimum length, check against breached passwords (HIBP/k-anonymity), no forced rotations or absurd composition rules.
  4. Rate limiting and stuffing/spraying detection; generic errors and constant timing against enumeration.
  5. Sessions: random IDs, rotation after login, expiry, server-side invalidation on logout and password change.
  6. Reset: one-time token, high entropy, short expiry; do not build the link from the request Host.

Force reset and invalidate sessions of affected accounts, enable/enforce MFA, block IPs/patterns, and review post-compromise access.

  • 23andMe (2023) — credential stuffing (password reuse from other breaches) that ultimately exposed data of ~6.9 million people via the “relatives” graph.
  • Colonial Pipeline (2021) — initial access through a VPN account without MFA with a compromised password; led to a nationally impactful ransomware incident.
  • “MFA fatigue” waves — attacks spamming push notifications until the victim accepts (mitigated by number matching / passkeys).

This category is rarely a single CVE; look at incidents and, for specific components, NVD (https://nvd.nist.gov/vuln/search) and GitHub Advisories (https://github.com/advisories).

  • User enumeration (text/code/timing) checked.
  • Rate limiting/lockout on login and on the MFA code.
  • MFA bypass: step skip, code brute force, response tampering.
  • Reset: token entropy/expiry, host header, Referer leak.
  • Session: rotation after login, expiry, invalidation on logout/password change.
  • Tests only against your own / in-scope accounts.