Slides 9–13 · Five attack patterns, each grounded in reality
Slide 9 · Five Patterns
Authentication breaks in five distinct ways.
Same vulnerability class, very different attack mechanics.
📋
1. Credential Stuffing
Automated testing of username/password pairs leaked from other breaches. Works because people reuse passwords. No guessing needed — the list comes from someone else's breach.
🔑
2. Brute Force Without Lockout
Trying millions of password guesses on a login endpoint that has no rate limit, no lockout, and no CAPTCHA. APIs make this trivially scriptable.
🆔
3. Broken Token Validation
JWT tokens accepted without verifying the signature, or accepting {"alg":"none"}, or tokens that never expire. An attacker can craft or modify a token and the API won't catch it.
🔗
4. Token Exposure in URLs
Auth tokens passed as URL query parameters leak into server logs, browser history, proxy caches, and referrer headers. Once logged, they persist far longer than the intended session.
📧
5. Missing Re-authentication
Sensitive operations — changing email, disabling MFA, updating payment info — don't require the current password. A stolen session token is enough to take full control.