Broken Authentication Testing

当对 Web 应用做认证/会话安全测试(已获书面授权)时使用;按 10 阶段方法对密码策略、用户名枚举、暴破/撞库、会话令牌与固定、超时、MFA、口令重置逐项检测并产出漏洞评估报告与修复建议;不适用于无授权测试、用真实泄露凭据登录他人账号、或第三方 SSO 越界;触发词:broken authentication、会话固定、JWT none、OTP 暴破、撞库

findscripter fa1402c 5.4 KB Updated

File contents

findscripter/everything-skills/tree/main/08-security/broken-authentication-testing commit fa1402c15e

Frequently asked questions

npx skillmds@latest add findscripter/broken-authentication-testing