Authentication failures
TL;DR
Authentication failures are about proving who you are — and sessions are about staying proven. Weak passwords, no rate limiting, guessable resets and sloppy session handling all live here. The fixes are well known: strong auth, MFA, proper session management.
Only test accounts and apps you’re authorised to test.
What it is
If an attacker can become another user — by guessing, resetting, or stealing their session — nothing else matters. This category covers the login, the password reset, and how sessions are issued and ended.
How it works
Common weak spots:
- Credential attacks — brute force or, more realistically, password spraying (one common password against many accounts) where there’s no rate limiting or lockout.
- Broken reset flows — guessable tokens, resets that leak whether an account exists, or that don’t expire.
- Session flaws — session ids that don’t change after login, don’t expire, or ride in insecure cookies.
How to test for it
- Check for rate limiting and lockout on login and reset.
- See whether error messages reveal which accounts exist (username enumeration).
- Inspect the session cookie: does it change on login and logout? Is it
HttpOnlyandSecure?
How to fix it
- Support and encourage multi-factor authentication.
- Rate-limit and monitor authentication; use generic error messages.
- Issue a fresh session on login, expire it properly, and set secure cookie flags.
Reference: OWASP A07 and the Authentication cheat sheet.