Authentication failures

beginnerWeb

TL;DR

Authentication failures are about proving who you are — and sessions are about staying proven. Weak passwords, no rate limiting, guessable resets and sloppy session handling all live here. The fixes are well known: strong auth, MFA, proper session management.

Only test accounts and apps you’re authorised to test.

What it is

If an attacker can become another user — by guessing, resetting, or stealing their session — nothing else matters. This category covers the login, the password reset, and how sessions are issued and ended.

How it works

Common weak spots:

How to test for it

How to fix it

Reference: OWASP A07 and the Authentication cheat sheet.

← Back to Web