4.4 Authentication Testing

Evidence:

​

You can use Burp's Cluster Bomb attack

Evidence:

​

Evidence:

​

Try to break the authentication process in order to obtain a valid session ID.

Try to bypass the authentication mechanisms in any section of the web pages which requires some sort of authentication with the following techinques:

Evidence:

​

Evidence:

​

Cache-Control: no-cache, no-store
Expires: 0
Pragma: no-cache

Evidence:

​

Evidence

​

Evidence:

​

Evidence:

​

Evidence:

​

Last updated