Authentication
Test authentication mechanisms including login security, token handling, 2FA, CAPTCHA, and bot detection.
Techniques
| Type |
Key Vectors |
| Auth Bypass |
Default credentials, logic flaws, response manipulation |
| ADFS/SAML |
Golden SAML, token signing cert theft, assertion manipulation, SAML wrapping |
| JWT |
Algorithm confusion, key injection, claim tampering, token forging |
| OAuth |
Redirect manipulation, CSRF, token leakage, scope abuse |
| Password |
Brute force, credential stuffing, password policy bypass |
| 2FA Bypass |
Response manipulation, direct endpoint access, code reuse, race conditions |
| CAPTCHA Bypass |
Missing server validation, token reuse, OCR, parameter manipulation |
| Bot Detection |
Behavioral biometrics simulation, fingerprint randomization, stealth mode |
Tools
PasswordGenerator (tools/password_generator.py):
from tools.password_generator import generate_password
password = generate_password(hint_text="8-16 chars, uppercase, numbers")
CredentialManager (tools/credential_manager.py):
from tools.credential_manager import CredentialManager
mgr = CredentialManager()
mgr.store_credential(target="example.com", username="test", password="pass")
Workflow
- Analyze auth implementation (forms, tokens, 2FA, CAPTCHA)
- Test bypass vectors per technique type
- Use Playwright MCP with human-like behavior (typing 80-200ms, random pauses)
- Capture evidence (screenshots, network logs, tokens)
- Document findings with PoC scripts
Reference
reference/authentication*.md - Auth bypass techniques, payloads, and resources
reference/jwt*.md - JWT attack techniques and cheat sheets
reference/oauth*.md - OAuth vulnerability testing
reference/scenarios/password-attacks/*.md - Password attack vectors (spray, stuffing, cracking, PtH)
reference/adfs-exploitation.md - ADFS, Golden SAML, federation attacks
reference/scenarios/2fa/*.md - 2FA bypass methods
reference/CAPTCHA_BYPASS.md - 11 CAPTCHA bypass techniques
reference/BOT_DETECTION.md - Bot detection evasion strategies
reference/PASSWORD_CREDENTIAL_MANAGEMENT.md - Tool usage guide
1---2name: authentication3description: Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.4---5
6# Authentication
7
8Test authentication mechanisms including login security, token handling, 2FA, CAPTCHA, and bot detection.
9
10## Techniques
11
12| Type | Key Vectors |
13|------|-------------|
14| **Auth Bypass** | Default credentials, logic flaws, response manipulation |
15| **ADFS/SAML** | Golden SAML, token signing cert theft, assertion manipulation, SAML wrapping |
16| **JWT** | Algorithm confusion, key injection, claim tampering, token forging |
17| **OAuth** | Redirect manipulation, CSRF, token leakage, scope abuse |
18| **Password** | Brute force, credential stuffing, password policy bypass |
19| **2FA Bypass** | Response manipulation, direct endpoint access, code reuse, race conditions |
20| **CAPTCHA Bypass** | Missing server validation, token reuse, OCR, parameter manipulation |
21| **Bot Detection** | Behavioral biometrics simulation, fingerprint randomization, stealth mode |
22
23## Tools
24
25**PasswordGenerator** (`tools/password_generator.py`):
26```python
27from tools.password_generator import generate_password
28password = generate_password(hint_text="8-16 chars, uppercase, numbers")
29```
30
31**CredentialManager** (`tools/credential_manager.py`):
32```python
33from tools.credential_manager import CredentialManager
34mgr = CredentialManager()
35mgr.store_credential(target="example.com", username="test", password="pass")
36```
37
38## Workflow
39
401. Analyze auth implementation (forms, tokens, 2FA, CAPTCHA)
412. Test bypass vectors per technique type
423. Use Playwright MCP with human-like behavior (typing 80-200ms, random pauses)
434. Capture evidence (screenshots, network logs, tokens)
445. Document findings with PoC scripts
45
46## Reference
47
48- `reference/authentication*.md` - Auth bypass techniques, payloads, and resources
49- `reference/jwt*.md` - JWT attack techniques and cheat sheets
50- `reference/oauth*.md` - OAuth vulnerability testing
51- `reference/scenarios/password-attacks/*.md` - Password attack vectors (spray, stuffing, cracking, PtH)
52- `reference/adfs-exploitation.md` - ADFS, Golden SAML, federation attacks
53- `reference/scenarios/2fa/*.md` - 2FA bypass methods
54- `reference/CAPTCHA_BYPASS.md` - 11 CAPTCHA bypass techniques
55- `reference/BOT_DETECTION.md` - Bot detection evasion strategies
56- `reference/PASSWORD_CREDENTIAL_MANAGEMENT.md` - Tool usage guide