Authentication
Test authentication mechanisms including login security, token handling, 2FA, CAPTCHA, and bot detection.
Techniques
| Type |
Key Vectors |
| Auth Bypass |
Default credentials, logic flaws, response manipulation |
| JWT |
Algorithm confusion, key injection, claim tampering, token forging |
| OAuth |
Redirect manipulation, CSRF, token leakage, scope abuse |
| Password |
Brute force, credential stuffing, password policy bypass |
| 2FA Bypass |
Response manipulation, direct endpoint access, code reuse, race conditions |
| CAPTCHA Bypass |
Missing server validation, token reuse, OCR, parameter manipulation |
| Bot Detection |
Behavioral biometrics simulation, fingerprint randomization, stealth mode |
Tools
PasswordGenerator (tools/password_generator.py):
from tools.password_generator import generate_password
password = generate_password(hint_text="8-16 chars, uppercase, numbers")
CredentialManager (tools/credential_manager.py):
from tools.credential_manager import CredentialManager
mgr = CredentialManager()
mgr.store_credential(target="example.com", username="test", password="pass")
Workflow
- Analyze auth implementation (forms, tokens, 2FA, CAPTCHA)
- Test bypass vectors per technique type
- Use Playwright MCP with human-like behavior (typing 80-200ms, random pauses)
- Capture evidence (screenshots, network logs, tokens)
- Document findings with PoC scripts
Reference
reference/authentication*.md - Auth bypass techniques, payloads, and resources
reference/jwt*.md - JWT attack techniques and cheat sheets
reference/oauth*.md - OAuth vulnerability testing
reference/password-attacks.md - Password attack vectors
reference/2FA_BYPASS.md - 10 2FA bypass methods
reference/CAPTCHA_BYPASS.md - 11 CAPTCHA bypass techniques
reference/BOT_DETECTION.md - Bot detection evasion strategies
reference/PASSWORD_CREDENTIAL_MANAGEMENT.md - Tool usage guide
1---2name: authentication3description: Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.4---56# Authentication78Test authentication mechanisms including login security, token handling, 2FA, CAPTCHA, and bot detection.910## Techniques1112| Type | Key Vectors |13|------|-------------|14| **Auth Bypass** | Default credentials, logic flaws, response manipulation |15| **JWT** | Algorithm confusion, key injection, claim tampering, token forging |16| **OAuth** | Redirect manipulation, CSRF, token leakage, scope abuse |17| **Password** | Brute force, credential stuffing, password policy bypass |18| **2FA Bypass** | Response manipulation, direct endpoint access, code reuse, race conditions |19| **CAPTCHA Bypass** | Missing server validation, token reuse, OCR, parameter manipulation |20| **Bot Detection** | Behavioral biometrics simulation, fingerprint randomization, stealth mode |2122## Tools2324**PasswordGenerator** (`tools/password_generator.py`):25```python26from tools.password_generator import generate_password27password = generate_password(hint_text="8-16 chars, uppercase, numbers")28```2930**CredentialManager** (`tools/credential_manager.py`):31```python32from tools.credential_manager import CredentialManager33mgr = CredentialManager()34mgr.store_credential(target="example.com", username="test", password="pass")35```3637## Workflow38391. Analyze auth implementation (forms, tokens, 2FA, CAPTCHA)402. Test bypass vectors per technique type413. Use Playwright MCP with human-like behavior (typing 80-200ms, random pauses)424. Capture evidence (screenshots, network logs, tokens)435. Document findings with PoC scripts4445## Reference4647- `reference/authentication*.md` - Auth bypass techniques, payloads, and resources48- `reference/jwt*.md` - JWT attack techniques and cheat sheets49- `reference/oauth*.md` - OAuth vulnerability testing50- `reference/password-attacks.md` - Password attack vectors51- `reference/2FA_BYPASS.md` - 10 2FA bypass methods52- `reference/CAPTCHA_BYPASS.md` - 11 CAPTCHA bypass techniques53- `reference/BOT_DETECTION.md` - Bot detection evasion strategies54- `reference/PASSWORD_CREDENTIAL_MANAGEMENT.md` - Tool usage guide