Chapter 04 of 05 · Web Application Security
Broken Authentication
A session token is only as strong as the check that verifies it. When the verifier accepts a token that declares its own signature unnecessary, anyone can write themselves a token that says whatever they like.
FreeMedium
3 lessons8 quiz questionsabout 7 minup to 60 XP
Loop in progress
Start this chapterWhat A Token Trusts- Attack
- Telemetry
- Fix
- Detection