Back to Cheat Sheets

🛡️ Broken AuthenticationOWASP 2017

OWASP WEB Top 10 2017 - #2

HIGH RISK

📋 What Is It?

Broken Authentication - Application functions related to authentication and session management are often implemented incorrectly, allowing attackers to compromise passwords, keys, or session tokens.

#2 OWASP Rank 2017
3% Apps Tested
123K Occurrences

⚠️ Common Exploits

  • Credential Stuffing: Use lists of known passwords
  • Session Fixation: Force known session ID on victim
  • Brute Force: Automated password guessing
  • Session Hijacking: Steal or predict session tokens
  • Weak Password Recovery: Exploit password reset flaws

🔴 Attack Flow

1. Attacker discovers weak authentication

2. Attempts credential stuffing or brute force

3. Application lacks rate limiting

4. Credentials compromised or session stolen

5. BREACH: Account takeover achieved!

✓ Prevention Checklist

  • Implement multi-factor authentication (MFA)
  • Use strong session management
  • Implement rate limiting and account lockout
  • Use secure password hashing (bcrypt, Argon2)
  • Prevent credential stuffing with CAPTCHA

📌 Quick Reference

Risk Level: HIGH RISK
Year: OWASP Top 10 2017
Category: WEB
Ranking: #2 in 2017