Authentication Vulnerabilities

Video Walkthrough :

Writeups :

Lab NameVisit
2FA simple bypassView
Password reset broken logicView
Username enumeration via different responsesView
2FA broken logicView
Brute-forcing a stay-logged-in cookieView
Offline password crackingView
Password brute-force via password changeView
Password reset poisoning via middlewareView
Username enumeration via account lockView
Username enumeration via response timingView
Username enumeration via subtly different responsesView
Broken brute-force protection, IP blockView
Broken brute-force protection, multiple credentials per requestView