📋 What Is It?
Broken Authentication - Application functions related to authentication and session management are often implemented incorrectly, allowing attackers to compromise passwords, keys, or session tokens.
#2
OWASP Rank 2017
3%
Apps Tested
123K
Occurrences
⚠️ Common Exploits
- Credential Stuffing: Use lists of known passwords
- Session Fixation: Force known session ID on victim
- Brute Force: Automated password guessing
- Session Hijacking: Steal or predict session tokens
- Weak Password Recovery: Exploit password reset flaws
🔴 Attack Flow
1. Attacker discovers weak authentication
↓
2. Attempts credential stuffing or brute force
↓
3. Application lacks rate limiting
↓
4. Credentials compromised or session stolen
↓
5. BREACH: Account takeover achieved!
↓
2. Attempts credential stuffing or brute force
↓
3. Application lacks rate limiting
↓
4. Credentials compromised or session stolen
↓
5. BREACH: Account takeover achieved!
✓ Prevention Checklist
- Implement multi-factor authentication (MFA)
- Use strong session management
- Implement rate limiting and account lockout
- Use secure password hashing (bcrypt, Argon2)
- Prevent credential stuffing with CAPTCHA
📌 Quick Reference
Risk Level: HIGH RISK
Year: OWASP Top 10 2017
Category: WEB
Ranking: #2 in 2017