Identification and Authentication Failures (OWASP A07)
Weaknesses in authentication mechanisms and session management.
Skills
- JWT Attacks - JSON Web Token exploitation
- OAuth Attacks - OAuth flow manipulation
- Session Attacks - Session fixation and hijacking
- 2FA Bypass - Two-factor authentication bypass
- Password Reset - Reset flow exploitation
Quick Reference
| Attack | Target | Technique |
|---|---|---|
| JWT | Token auth | Algorithm confusion, weak secret |
| OAuth | SSO/social login | Redirect manipulation |
| Session | Cookies | Fixation, hijacking |
| 2FA | MFA | Direct access, brute force |