Training Overview
The "Broken Authentication" training is designed to enhance your cybersecurity skills. This comprehensive training details common vulnerabilities in authentication processes and explains how these vulnerabilities can be exploited. Additionally, it provides information on effective measures to prevent such vulnerabilities.
The training content covers various authentication methods, username enumeration, default credentials, protection deficiencies against brute force attacks, cookies, and more in detail.
What you will learn
- How to identify common broken authentication vulnerabilities.
- Techniques for username enumeration and exploiting default credentials.
- How to analyze and exploit weak cookie implementations.
- Methods for preventing and mitigating authentication flaws.
Tools you will use
- Burp Suite or similar web proxy
- Username and password wordlists
Prerequisites
- Basic understanding of web applications and HTTP.
- Familiarity with a web proxy like Burp Suite is recommended.
Who this is for
- Web Penetration Testers.
- Web Developers and Application Security Engineers.
- Bug Bounty Hunters.
Training sections
- 1Introduction
- 2Authentication Methods
- 3Gathering Information on Usernames
- 4Default Credentials
- 5Lack of Brute-Force Protection
- 6Weak Cookies
- 7Object Injection (Mass Assignment)
- 8Application
- 9Preventing Broken Authentication Vulnerabilities
- 10Exam
Continue learning
Practice the topic in a lab or continue with a related Hackviser guide.