A2: Broken Authentication ❗️ — Top 10 OWASP 2017

What is authentication and session management?

What is broken authentication?

Attack scenarios

  • Man in the middle attacks
  • Credential stuffing / Bruteforce
  • No session timeouts


How can I prevent broken authentication

  • Strict password policy
  • Encryption
  • No excessive information

Preventive measures



