Authentication and session weaknesses we probe
The mechanisms that log users in and keep them logged in are a prime target, so authentication and session weaknesses are firmly on the test list.
A tester examines areas such as:
- Whether login can be bypassed, brute-forced or otherwise subverted.
- How sessions are issued and managed, and whether a session can be stolen or reused.
- Whether logging out, session expiry and related controls actually work.
- Weaknesses in password handling and account-recovery flows.
If an attacker can defeat authentication or hijack a session, every other protection on the site becomes irrelevant — they are simply in. Because these flaws often depend on the specific logic of your site, they are exactly the kind of thing manual testing is best placed to find. The report explains any weaknesses and how to strengthen them.

0 comments
Sign in with your TDesk account to comment.