BREAK IT / CTF
Break It: web authentication, and the five ways it goes wrong
This session has finished.
What we did
Warm-up A deliberately vulnerable login form, and fifteen minutes to find out what it trusts that it should not.
In pairs Session fixation, missing ownership checks, and a password reset that tells you slightly too much. Everything runs against the lab we provide — no other target, ever.
Walk-through We compare how each pair found each issue. The interesting part is rarely the bug; it is which question led to it.
What did you take away?
Notes, questions you are still turning over, things you tried afterwards — this is the place for them.
Register or sign in to add yours.Loading…