Skip to contentExploitQuest
LearnWeb Application SecurityBroken Authentication

Chapter 04 of 05 · Web Application Security

Broken Authentication

A session token is only as strong as the check that verifies it. When the verifier accepts a token that declares its own signature unnecessary, anyone can write themselves a token that says whatever they like.

FreeMedium
3 lessons8 quiz questionsabout 7 minup to 60 XP
Loop in progress
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
defensive beats coming
Start this chapterWhat A Token Trusts
  1. What A Token Trusts2 min
  2. Forge The Token3 min
  3. Verify What You Issued2 min
  4. Practice quiz8 questions
Broken Authentication — Web Application Security · ExploitQuest